In October 2025, a ransomware crew called Akira found its way into more than 70 organizations through SonicWall SSL VPN devices, moving from initial login to full ransomware deployment in under four hours, The incident wasn’t unusual for its sophistication rather it followed a pattern seen across 2025: attackers targeting the seam between networking and security, where a VPN gateway sits at the network edge but isn’t governed by the same policies as everything behind it.
That seam is what Secure Access Service Edge (SASE) is designed to close. Here’s what SASE actually changes about enterprise architecture, and what a realistic path to adopting it looks like.
Understanding the Convergence of Networking and Security
For most enterprises, networking and security are run as two different disciplines, different teams, different budgets, different tools, reporting up different chains of command. That divide worked when everyone worked from an office, and every application lived in one data center. It works less well now that users, applications, and data are spread across a distributed, multi-cloud environment. The tools built for the old model- VPN concentrators, standalone firewalls, branch routers- were never designed to share a policy engine, which is exactly why they don’t.
Convergence means governing networking and security through one policy instead of two systems that occasionally compare notes. The data below shows why this matters: Coalition’s 2025 Cyber Threat Index found that 58% of ransomware claims started with a compromised perimeter appliance, and Zscaler’s 2025 VPN Risk Report found 92% of organizations are concerned about ransomware tied to VPN vulnerabilities.
That pattern shows up in federal data too. In September 2025, CISA issued an emergency directive ordering agencies to identify and mitigate a vulnerability in Cisco’s ASA and Firepower firewalls, the kind of edge device long treated as networking infrastructure, even though it now functions as a security control. CISA’s Known Exploited Vulnerabilities catalog grew by 245 entries in 2025, and network edge devices like firewalls, VPN gateways, and remote-access appliances were the dominant category.
Few of the incidents behind those numbers were patching failures; most of the affected companies patched eventually. The gap was operational: a network team owns uptime, a security team owns detection, and neither owns the moment a device connects from an unmanaged network and requests access to a sensitive application. That seam is where several of the incidents below started.
It’s also worth noting who actually got hurt in these incidents. Ingram Micro is a large distributor, but the disruption reached thousands of much smaller resellers and managed service providers who depended on its systems for daily operations. Mid-market companies rarely make the headlines, but they’re frequently the ones absorbing the downstream impact of a vendor’s or partner’s perimeter failure, which is its own argument for not assuming this is only a large-enterprise problem.
None of this is a new theoretical framework, either. NIST SP 800-207 laid out the foundational principles of zero trust architecture years ago, and CISA’s own Zero Trust Maturity Model builds on it with five pillars covering identity, devices, networks, applications, and data. SASE is best understood as the practical, cloud-delivered way most organizations actually implement those principles across a distributed environment rather than a competing standard.

Source: Created by Authors using AI Tools based on Data Gathered from Multiple Sources
The Limitations of Legacy IT Infrastructure Models
Legacy architecture runs on an assumption that stopped being true years ago: traffic from inside the network is trusted, and everything else gets flagged at the perimeter. Several incidents from 2025 illustrate what that assumption costs:
- Perimeter-based design, exploited: In January 2025, Ivanti disclosed a critical authentication bypass in its Connect Secure VPN appliance that was already being exploited in the wild, serious enough that CISA ordered federal agencies to disconnect the product outright rather than simply patch it a sign of how little confidence remained in the appliance once it had been compromised once.
- Siloed management, weaponized: When the SafePay ransomware group breached Ingram Micro in July 2025 through a flaw in its SSL VPN platform, the damage didn’t stop at Ingram Micro itself. Online ordering systems went dark for days, and the disruption rippled out to thousands of resellers and MSPs across the Netherlands and Belgium who depended on that one vendor relationship for daily operations.
- Weak segmentation, exposed: Yale New Haven Health System discovered in March 2025 that an intrusion tied to insufficient network segmentation had exposed records for roughly 5.5 million patients’ names, Social Security numbers, and medical record numbers, all reachable because the network wasn’t built to contain a breach once one started.
- Performance bottlenecks, tolerated as normal: Inspecting encrypted traffic means decrypting, checking, and re-encrypting it a process that doesn’t scale well as traffic grows. IT teams often exempt some traffic from inspection just to keep applications fast, which quietly reopens the gap the appliance was meant to close.
These aren’t isolated failures. IBM’s Institute for Business Value found that the average organization runs 83 security tools from 29 vendors, and names complexity, not budget, as the top obstacle to better security. Legacy stacks also tend to accumulate undocumented rules over time: a firewall exception added for an integration that was retired years ago, a VPN configuration nobody wants to touch because nobody’s sure what breaks if they do. Each one is a door that convergence work eventually has to find and close, and most of those doors were never intentionally opened; they were left that way by attrition.
What Makes Secure Access Service Edge (SASE) Different?
SASE doesn’t add another appliance to the stack; it changes where policy gets enforced. Instead of backhauling traffic to a data center for inspection, SASE enforces one policy for both networking and security close to the user, at a point of presence near wherever that user actually is, rather than routing everything back through a central location first.
That shift addresses the gap behind the incidents above: a stolen credential no longer grants broad network access by default, and a single vulnerable appliance isn’t the only thing standing between an attacker and the rest of the environment. It also removes a common trade-off, since inspection close to the user doesn’t add the latency that often makes teams hesitant to enforce stricter policy.
This isn’t just a vendor argument, either. In July 2025, CISA published guidance specifically encouraging federal agencies to move away from the perimeter-based Trusted Internet Connections model and toward SASE as part of their broader zero trust transition, citing the same architectural shortcomings described above. Table 1 summarizes how this compares to a legacy model.
Table 1. Legacy IT Architecture vs. SASE
Most IT leaders don’t disagree with this comparison in principle; the resistance is usually practical, not conceptual: sunk cost in existing hardware contracts, uncertainty about migration risk, or simply not having the internal bandwidth to run an audit while also keeping current operations running. That’s a legitimate constraint, and it’s exactly what the migration approach later in this piece is designed around.
Core Pillars Driving Modern SASE Frameworks
Three components carry most of the architectural weight in SASE, and they map closely to the network and identity pillars in CISA’s own zero trust model. Table 2 summarizes what each one solves; the sections below cover the three most relevant to the incidents discussed above.
Table 2. SASE Components and the Problems They Solve
Software-Defined Wide Area Network (SD-WAN) Integration
SD-WAN replaces a rack of branch routers and firewalls with a single software-defined appliance that steers traffic across broadband, 5G, and MPLS while enforcing one policy across every location, instead of a different configuration at each branch. It also improves resilience: if one connection type fails, traffic reroutes automatically instead of taking the branch offline, which matters as much for uptime as it does for security. For IT teams managing several branch offices, that alone often justifies the change before security is even part of the conversation.
Cloud Access Security Brokers (CASB) and Secure Web Gateways (SWG)
CASB and SWG sit between users and the cloud applications they use daily, enforcing data policy and filtering threats through a single inspection path instead of backhauling traffic through a data center. This also gives IT visibility into unsanctioned tools employees adopt on their own traffic a legacy perimeter was never positioned to see in the first place- and a growing source of exposure as more business processes move into SaaS applications IT never formally approved.
Implementing Universal Zero Trust Network Access (ZTNA)
ZTNA is the direct answer to the SonicWall incident described earlier. Instead of granting broad network access once someone authenticates, it verifies identity, device posture, and context on every request, and only exposes the specific application a user is authorized for. If a credential is stolen, exposure is limited to one application rather than the full network the same principle that would have limited the scope of Yale New Haven’s segmentation-related breach, and the reason ZTNA is usually the first component migrated in a phased rollout.
Operational Benefits for IT Leaders and Infrastructure Teams
Reducing Complexity and Management Overheads
Converging SD-WAN, VPN, firewalls, CASB, and ZTNA under one dashboard means fewer consoles and faster troubleshooting, instead of several teams pulling separate logs to reconstruct what happened after the fact. Versa Networks’ 2026 State of SASE + AI report found that 99% of senior IT and security leaders now name this convergence a strategic priority.
There’s also an operational cost to running several disconnected tools: each one generates its own alerts, which makes it harder for analysts to prioritize by severity rather than volume. A converged platform correlates activity across networking and security automatically, so related signals like unusual traffic paired with a suspicious login surface as one event instead of two separate ones that nobody connects until later. For a lean mid-market IT team without a dedicated security operations function, that correlation often matters more than any single feature, since it’s what determines whether an anomaly gets caught in minutes or discovered days later.
Cutting Costs Through Single-Vendor Consolidation
The same Versa report puts numbers behind the shift: enterprises that converged onto SASE instead of buying networking and security separately reported an average of $10.6M in licensing and telecom savings, $4.1M in reduced M&A cutover costs, $2.1M from breach reduction, and $2.0M in labor savings. For a mid-market company, the absolute numbers will be smaller, but the same categories of savings tend to apply: fewer renewals, fewer specialized certifications to maintain, and less time spent switching between vendor consoles. A company running separate VPN, firewall, and CASB contracts across a handful of vendors is often paying for overlapping capabilities without realizing it; consolidation tends to surface that overlap on its own.
The Compliance and Insurance Case
Convergence is also becoming less optional from an underwriting standpoint. According to Marsh McLennan’s 2025 cyber insurance data, 96% of insurers now require MFA on all remote access, email, and privileged accounts as a condition of coverage, and network segmentation increasingly appears in underwriting questionnaires as a firm requirement rather than a best practice. A flat, VPN-based network with implicit trust between users and resources is exactly the architecture underwriters are pricing against, while ZTNA and SD-WAN segmentation, the core pieces of a SASE model, are the controls insurers are asking to see documented at renewal. That turns convergence from a purely defensive investment into one with a measurable line on the next policy renewal, and it gives IT leaders a business case that lands with finance as well as with the security team.
Strategic Best Practices for Transitioning to a SASE Architecture
Converging networking and security isn’t a weekend project. Treating it like one is how companies end up with a half-migrated environment that’s more fragile than what it replaced, running two access models in parallel without a clear plan for retiring the old one, which tends to widen the exact gap this piece has been describing rather than closing it.
Auditing Existing Network and Security Stacks
You can’t converge tools you haven’t mapped: every VPN concentrator, firewall, CASB, and SD-WAN device currently in production, who owns it, and where policies overlap or contradict each other. Most mid-market environments we assess have never had this documented in one place.
A useful audit answers four questions for every device: What does it do? Who’s accountable for it? What would break if it went down? And what would an attacker reach if it were compromised? That last question is what actually determines migration order an unpatched print server on an isolated VLAN is a different risk than a VPN concentrator every remote employee authenticates through, even if the two look similar on a spreadsheet. Applied to a VPN concentrator specifically: it handles remote access for every field employee; IT owns it, but a contractor configured it two years ago; losing it would stop remote work entirely, and a compromise would expose every application reachable from inside the corporate network which is exactly the profile that makes it the obvious first phase of a migration, not an afterthought. In practice, this typically takes two to four weeks to compile properly for a mid-market environment, longer if ownership records are out of date, and it becomes the reference document the rest of the migration is built around
Phased Migration vs. Rip-and-Replace Approaches
Start with whatever segment would cause the most damage if compromised tomorrow, usually remote access, since that’s the door most 2025 incidents walked through. Prove the model there, then extend it network by network. A full rip-and-replace can move faster on paper, but it widens the risk window during the transition itself. For most mid-market companies still running day-to-day operations, phased migration is generally the safer path, and for an environment with a few hundred users, the full sequence typically runs six to twelve months depending on how many branch locations and legacy contracts are involved.
Key takeaways for a phased migration:
- Start with remote access; it’s the highest-risk, most self-contained swap, and where most 2025 incidents began.
- Use your busiest branch as the SD-WAN template before extending it network-wide.
- Extend CASB/SWG coverage to finance and HR systems next, since that’s typically where a breach does the most damage.
- Keep the legacy VPN running in parallel until ZTNA has carried production traffic for a full quarter.
- Measure each phase with a specific number: fewer standing access grants, fewer VPN-related tickets, faster detection, rather than judging by whether it “feels” complete.
- Document each phase’s outcome before starting the next one; it becomes the evidence auditors and insurers ask for at renewal.
If you want a clearer picture of where your own environment stands against this failure pattern, our free IT Blueprint is a focused 60–90-minute assessment that maps your current stack, flags where a 2025-style perimeter compromise would hit hardest, and lays out a phased path to convergence for your environment specifically.
Frequently Asked Questions
What is SASE, in plain terms?
A cloud-delivered architecture that combines networking (SD-WAN) and security (ZTNA, CASB, SWG) under one policy, instead of managing them as separate tools run by separate teams with separate consoles.
Is moving to SASE the same as just replacing our VPN?
Not exactly. Swapping VPN vendors doesn’t fix the underlying model. SASE changes how access is granted in the first place, verifying every request instead of trusting anyone already inside the network.
How long does a SASE migration realistically take for a mid-market company?
For most mid-market companies, a phased migration runs six to twelve months rather than weeks, starting with remote access and extending outward branch by branch.
Does SASE actually work for a hybrid or fully remote workforce?
Yes. Because policy is enforced at the cloud edge rather than a physical office perimeter, access controls stay consistent whether someone’s on the corporate network or working from home.
What’s the difference between SASE and Zero Trust?
Zero Trust (ZTNA) is one component inside SASE. SASE is the broader architecture that also includes SD-WAN, CASB, and secure web gateways, all governed by one policy engine and one set of reporting.
The Point of View We’re Not Going to Soften
Every company named in this piece had a firewall, and most had already invested in a VPN. That’s the uncomfortable part: this wasn’t a failure of spending; it was a failure of architecture, treating networking and security as separate purchases instead of one system with shared rules.
That’s the gap ourNetworks & SASE practice is built to close: converged, zero-trust architecture managed as one system, not another tool for your team to maintain on top of everything else.
Need Expert Help?
Schedule a consultation with our team to discuss your specific security needs.
Book a Free Consultation