The Role of Secure Access Service Edge in Digital Transformation

Transcription

welcome to z cast everybody i'm zeus caraval from zk research and i'm back for another one of my thought leadership videos uh today i'm joined by normal jay director of product management from cisco uh nirmal why don't you say hi to everybody tell us a little bit what you do hi everyone i'm nirmal jandiala i'm the product manager for the sassy offers at cisco i'm i manage a team that deals with the building sassy products and we are going to be talking sassy today before we get going though i do want to give a quick shout out to e-week my media sponsor all z casts are done in conjunction with the e-week e-speaks program so we are talking sassy today it's it's been this big uh shift in security that's moved to the cloud before we talk about sassy though let's do a little bit of table set interval uh you know companies today are going through a pretty significant transformation journey you know digital transformation network transformation everything's transformative it seems what um so what exactly is driving this transformation journey today yeah it's a good point so um there are as you mentioned digital transformation quite frankly it's actually not something new it's been going on for a long time now uh across many different verticals in fact uh you know more recently even education vertical was transforming more to the digital means primarily driven by pandemic and if you look under the hood what this transition really means is that organizations and companies are choosing to leverage the technology like for example take a look at automotive industry who would have imagined a few years ago that you would be getting features in your car through software updates and that's something that we see today right i mean i i have one of those cars and i get those uh features and i'm excited and it's a total transformation uh that i would not have imagined a few years back so many organizations many verticals in fact every vertical that i can think of is going through such transformation but when you look under the hood what does this transformation mean in terms of users in terms of applications in terms of the network design is that the applications are moving from on-prem locations to cloud delivered sas applications why because they can be accessed from anywhere and then there is transformation from the in the workforce as well like uh even though pandemic has accelerated uh the transformation from working from campus and on uh branch locations to more distributed work from home sort of settings even before the pandemic this transformation was happening and that's going to change how the networks look like how the security posture looks like and it has a downstream effect when that happens and the third thing is uh you know we talked about the branch locations there are a lot of distributor enterprises that have multiple branches whether it's retail whether it's financial there are many distributed enterprises and once uh the applications move to the on from on-prem data centers to the cloud the path that the user at the branch takes to go to the application is going to be different you need to directly access the internet from the branch versus the traditional hub and spoke models where you aggregate traffic at your data centers and have a pop for the internet so organizations are going through this transformation and the primary reason for this is to basically leverage the digital technology yeah you're right there have been um companies that were going through digital transformation obviously well before the pandemic began i don't think it was every company though and so that's one of the things the pandemic did is accelerated plans and it got companies that weren't really thinking digital first i think digital first now with that being said uh let me ask you candidly you know we have been seeing digital projects going on for a long time the pandemic did accelerate it but how many of these companies uh are actually we're where are our companies with digital transformation journeys how far along are they are we at the very beginning of this the middle towards the end how do you see this playing out yeah yeah we were good questions here so i i see that like um you know it depends on a lot of factors like the vertical that the organization is in it depends on the age of the company as well like uh for example uh companies that start that have started more recently have adopted cloud solutions right from day one whereas there are organizations that have been there for a long time and have traditional processes and they are on a journey to you know leverage cloud applications leverage digital technologies but in terms of verticals uh where i see a lot faster transmit transformation for example is in the financial sector uh is in the automotive industry surprisingly as we talked about before um where i see uh you know sort of like catching up is on the education and government sector but they are transforming as well so there are some differences in terms of what stage they are in but however it is also important to keep in mind that this transformation is like we said before that it has multiple downstream uh impacts on how the networks are set up how the technologies are leveraged and it's it's this sassy framework that we need to understand is what is required for the transformation for the organizations so uh when we talk about that sassy framework it involves multiple technology components so where i see faster adoption is actually in the larger enterprises because they do have the manpower they do have different teams to take care of this on the uh on the commercial and sort of smb side of um the segments they are they they do need like full turnkey sassy uh solution they cannot deal with multiple vendors multiple point solutions to build that sas a framework so there i see that option has been a bit slower than the larger enterprises all right well let's uh pivot a little bit to sassy before we get into sort of the nuts and bolts of sassy let's talk about the just the mechanics of it so sassy moves security to the cloud now obviously if we're moving apps to the cloud it's a little bit of fight fire with fire right we can't really secure cloud things with on-prem things and so you need to have a delivery model which matches it but one of the things customers have told me is uh when i move security to the cloud it actually makes things it can make things more complicated so first of all do you think that's true you know obviously that may you probably think the benefits are way up but talk about you know just this concept of moving security to the cloud and then the some of the complications it creates absolutely so one thing we fundamentally need to understand to understand the role of cloud security when you have users accessing applications directly that are in public cloud environments in service provider environments and so on and so forth the traffic is not coming to the corporate data center so you don't have one variable one point where you can actually apply a security policy and be covered for all those applications that the user is accessing for example if you take cisco today we have applications that can be accessed directly without turning on your vpn tunnel to the corporate network so to insert a security policy in that path requires an entity in the cloud and that can enforce this security policy now we can get a little bit deeper into what that policy constructs are and how that correlates to the on-prem security but fundamentally the role of cloud security is super important because without that you won't be able to apply a security policy to traffic that's going from the user to the app or from the branch to the application unless you're going to force them to go through your corporate data center which is not the ideal uh way to set up the network so having said that when they when you have this distributed uh spread out surface area of attack potentially right because you could have users accessing applications from anywhere so you need a cloud present a cloud security so that you are able to tackle that that's number one number two it also means that there are users in different geographies different paths are taken to go to the application so the enforcement points also needs to be distributed that means that you're not going to have one place where you're going to enforce cloud security it is also a distributed enforcement point now with these distributed enforcement points plus the on-prem uh security it admins often complain or sort of worry about how do i configure all this and manage it like i need one place to be able to go and describe a policy ultimately the policy is going to define one thing which user can connect to which application that's the goal we are trying to achieve regardless of whether they are on-prem or whether they are working remotely or whether a branch user is connecting directly to the app so to do all this and to make it a single policy framework for all these distributed enforcement points is where the complexity lies and having one single point of a single pane of glass and one view to see what's going on is where the complexity lies but then there are tools to work to that yeah that makes sense in fact i i think in some ways the uh legacy security being on-prem was highly inefficient obviously but that actually helped with the simplicity of it i suppose or the straightforwardness of it because there was only one way to deploy it with assassin there's multiple ways to deploy it so anytime you have choices of course it adds to the complexity now we talk about sassy specifically uh i'll ask you a bit of a tongue-in-cheek question is it is it real or is it not is it happening uh because if you look at the timing of sassy uh gartner predicts that by 2023 is when 20 to 40 of enterprises will be embracing sassy so uh what are your thoughts on that where exactly are we uh what's holding companies back and how does it progress from here excellent excellent point so uh i do believe it's 100 real because i've talked to a lot of customers and and it's a transformation journey like i mean as we mentioned sassy is not a point product sassy encompasses multiple technologies for example it still includes the traditional remote access vpn terminals it includes zero trust network access it includes uh cloud delivered security which typically consists of secure web gateway caspy solutions uh more recently rbi sort of technology for providing browser isolation cloud delivered firewall and it also includes uh sd-wan for branch connectivity and and then also technologies such as uh visibility engines for end-to-end network and application performance and monitoring so it's a combination of multiple technology stacks and uh one thing that we have to understand is that a lot of these technology elements by itself are not very new what's what's sort of the new thing here is bringing them all together and providing that as a cloud delivered stack that's cloud native agile and nimble what i mean by that is for example in the past if you have to set up a vpn to your to the corporate network you have to create a vpn cluster and manage it and typically this was done using large hardware appliances that required capex investment while that worked with with for example what pandemic has done is like it forced a lot of organizations to increase their vpn capacity and doing so with capex models is not very nimble and takes time so what customers are looking for is a very similar service but it's cloud delivered cloud native and agile that means i'm able to expand my capacity and decrease it as uh you know on demand so this entire sciency framework the technologies that we talked about quite frankly a lot of them exist so many organizations have some or many of these technologies already in in some cases it could be from one vendor in fact there is only a couple of vendors that i can think of who probably have this entire stack of sassy technologies but in a lot of cases customers have uh best of breed products from probably different vendors um to for this sassy framework so while it is very real and while customers need to do that to adapt to this digital transformation journey that we talked about earlier there are very different starting points for each organization because they have some or bits and pieces of these technology and they're not going to just throw them away and just consume something like as a service right they still want to get roi out of their existing investment so what's important for uh these large organizations that are sort of like leading that option is to be able to consume sciences solutions that are flexible that means that interoperate with other vendors or that provide flexibility to bring some components from a different vendor eventually eventually over a period of time maybe it'll all be like a single turnkey solution from one vendor or a few vendors but that's where i see the challenge like being able to uh migrate the existing framework to a framework where uh it is completely cloud native and potentially delivered by one or two vendors so um the that there's a lot of interest there's a it's actually a necessity and i do believe to your point um you know gartner's numbers in terms of adoption are very real and and i talked to a lot of customers and i hear them asking a lot of questions even if they're not actually adopting the framework today yeah and i think you we can actually see some faster acceleration like what gartner predicted i just think it's we're getting to the point where if you don't adopt sassy i'm not sure how you would actually secure a highly distributed organization now uh one of the reasons i like talking to people from cisco is because you guys have such a massive customer base right so in your conversation with customers you talked about some of the challenges what are some of the other challenges that you see with sassy what could they be doing differently and what's your advice to businesses on on how to move to sassy you know at a pace that's comfortable to them but also de-risks it excellent question you know uh i mentioned in my previous uh note that there are only a couple of vendors that i think have the full stack of cersei solutions and i do believe that cisco is one of 10. because we have all the technology stack so what i do see with the customers that i am interacting with is that a lot of them do it in a diy model what that means is like they are still leveraging that best of breed mindset meaning like for web security i'll use one vendor for sd-wan i could use another vendor for remote access i will use potentially another vendor so we have we see a lot of customers uh doing probably like 70 80 percent of the sassy stack from cisco and getting one or two other products from a different vendor and we see a lot of that adoption uh what however there is an ask from um the customers that to have this as a service turnkey solution that provides this unified management unified uh view of all the components and so on and so forth if you were to think of it in phases or steps and feel free to you know talk about cisco product though what would those steps be like for instance should you know you guys have a very good product called umbrella should you start there or is there another part that you recommended them starting excellent point like again like as i said there are you know sas is multiple pieces of technology and customers are at different starting points so for somebody uh who is let's just take the case of a distributed enterprise it's very likely that they probably have adopted st van for interconnecting their branches and getting sla driven policies uh already right it's very likely that they probably started on the sd-wan journey and then now okay now that you have sd-wan and you have direct internet access how do i get on how do i get cloud security stacks so that i can protect the user to application access when the traffic is going directly to the internet so then they would be looking at technologies such as umbrella sig and and bringing that as an add-on to their existing sd-wan deployment now on the flip side let's let's say if you have an organization that was relatively newer started adopting cloud technologies much faster and and in in that case their primary focus would have been i need cloud security first and then as they expand as they expand and acquire other companies or add more branches and whatnot then you would be adopting the sd-wan technologies to the existing umbrella uh sig deployment right so if there are different possible starting points but we do think the large larger piece of the pie is for at this point is larger companies that have sd-wan deployed and then trying to uh adopt cloud delivered security stack on top of that okay and so let's let's drill down you know for the last question let's drill down uh into cisco's sassy approach so uh tell me what your sassy portfolio looks like uh if you could maybe share share with us some you know i know cisco you can't give too many forward looking statements being a public traded company but as best you can could you can you share with us a little bit about the roadmap as well and what your overall approach to it is yeah i think it's actually just to make it very simple to sort of understand all this what we see as sassy broadly speaking is five different components right you like you need a remote access so one thing i want to make it clear is we keep hearing about the zero trust access applications moving to the cloud as much as i've talked about it there will always be some applications that will be on-prem or that will be in a cola and the reason for that could be multi-fold it could be compliance reasons it could be regulatory reasons it could be performance reasons uh there and and in some cases it could be also a reason for control like the organization wants to control uh that application a lot more right so for many reasons there will still continue to be some applications on on-prem for those you still need the traditional sort of vpn access now whether you call it uh always on vpn client list or whatever it is it's still a vpn tunnel to the corporate network so we consider sassy as five key pieces so the first one being the remote access piece second one is the zero truss network access basically what that means is if you you can access applications without the need for the tunnel that i talked about and then the third piece is the sd-wan piece and the fourth piece is the secure internet gateway or secure web which embeds actually secure web gateway to and the fifth piece is the monitoring piece that i talked about performance and monitoring piece all right well well thanks uh for that update i think that was a great discussion on you know where sassy is today where it's going and i think more importantly how it ties to these companies digital transformation efforts and uh we're always going to have some legacy kicking around i think as a you know i'll poke up my uh brethren analysts but there's some sometimes analysts a little too carried away and think everything's moving to the cloud or everything's going wireless or whatever and that's just never the case right these these transitions take a long time so um i think uh but i think what you you gave us a nice practical approach to assassin so with that being said yeah so that being said thanks for joining me on the z-cast and for everybody watching this don't forget to click to subscribe and i'll see you next time on another z cast

This transcript was generated automatically from the video's captions and may contain errors.

Written By
Zeus Kerravala
Zeus Kerravala
Published: Mar 31, 2022
Updated: Oct 17, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

In my latest ZKast, Nirmal Jandhyala, Director of Product Management at Cisco, explained what SASE is, and why enterprises are adopting the technology. Highlights of the ZKast interview, done in conjunction with eWEEK eSPEAKS, are below.

Zeus Kerravala

Zeus Kerravala is an eWEEK regular contributor and the founder and principal analyst with ZK Research. He spent 10 years at Yankee Group and prior to that held a number of corporate IT positions. Kerravala is considered one of the top 10 IT analysts in the world by Apollo Research, which evaluated 3,960 technology analysts and their individual press coverage metrics.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.