
What Is SASE? A Practical Guide to Converging Networking and Security
SASE converges networking and security into one cloud service. What it is, why it emerged, and how Saudi enterprises should approach the shift under Vision 2030.
SASE converges networking and security into one cloud service. What it is, why it emerged, and how Saudi enterprises should approach the shift under Vision 2030.

For a long time, networking and security lived in two different budgets, two different teams, and two different equipment racks. That split made sense when everything an employee needed sat inside a corporate data centre. It stopped making sense the moment your applications moved to the cloud and half your staff started working from home, a branch, or an airport lounge.
Here's the problem it created. To apply security policy, traffic from a branch office had to travel all the way back to a central data centre, pass through a stack of security appliances, and only then head out to the internet. Users felt the lag. Finance felt the cost of the circuits carrying all that backhauled traffic. And the security benefit? Often marginal, because the application the user wanted was sitting in a cloud region a few milliseconds away the whole time.
Secure Access Service Edge — SASE — is the answer to that mess. Gartner coined the term in 2019 to describe a single, cloud-delivered service that folds wide-area networking and network security together and delivers both close to the user, wherever the user happens to be. [1] For organisations across Saudi Arabia opening new sites, moving workloads to the cloud, and supporting hybrid teams, it has quietly become the reference architecture for how modern access should work.
What SASE actually is
Strip away the acronym and SASE is a simple idea: stop anchoring security to a physical location, and start delivering it as a service that follows the person.
Instead of routing every user through one central choke point, SASE inspects and secures traffic at distributed edge locations. The same policy applies whether someone is in a Riyadh head office, working from an apartment in Jeddah, or connecting from a hotel abroad. The model starts from the assumption that users, devices, and applications are scattered everywhere — so protection has to reach them, not the other way around.
That's a genuine shift in thinking. The old perimeter model treated the office network as a trusted zone and everything outside it as hostile. SASE drops that distinction. There's no inside and outside anymore, because your people and your applications don't respect those boundaries. What matters instead is identity, device posture, and context — who is asking, from what device, in what state, for which application.
The pieces it brings together
SASE isn't a single product you buy off a shelf. It's a set of capabilities that converge into one architecture:
SD-WAN handles intelligent, application-aware routing across multiple links, replacing the rigid MPLS-only designs most enterprises are still paying for.
Secure Web Gateway (SWG) inspects web traffic and enforces your acceptable-use and threat policies.
Cloud Access Security Broker (CASB) gives you visibility and control over how staff use cloud and SaaS applications — the shadow IT problem, essentially.
Firewall-as-a-Service (FWaaS) delivers firewalling from the cloud, so you scale capacity without shipping in more hardware.
Zero Trust Network Access (ZTNA) grants access to individual applications based on identity and context, rather than dropping a user onto the whole network the way a VPN does.
Worth knowing: the security-only slice of this — SWG, CASB, FWaaS, and ZTNA, minus the SD-WAN networking layer — is called Security Service Edge, or SSE. Plenty of organisations adopt SSE first, get comfortable, then converge it with SD-WAN to reach full SASE. That phased path is often the smart one, because it lets you prove the security model before you touch the underlying network.
Why the old model broke
The traditional hub-and-spoke design assumed applications lived in a corporate data centre and users dialled in. Cloud broke that assumption cleanly. When a user opens Microsoft 365, sending that traffic back to a central firewall before letting it reach Microsoft's servers adds latency and cost for almost no security gain. SASE inverts the logic. Security travels to the edge with the user, and traffic takes the shortest sensible path to the application — inspected and controlled the entire way, just not dragged halfway across the country first.
There's a second driver, too, and it's about risk rather than performance. Every backhauled connection, every broad VPN tunnel, every flat network segment is attack surface. The more places a user's traffic touches on its way to an application, the more opportunities an attacker has. By collapsing that path and enforcing least privilege at the application layer, SASE shrinks the surface an attacker can even reach.
What you get out of it
The payoffs are practical, not theoretical. You get consistent policy everywhere, so the controls that apply in the office also apply at home and on the road — no more "we secure the HQ properly and hope for the best with remote staff." You shrink your attack surface, because ZTNA hides applications and enforces least-privilege access instead of exposing a flat network. Users notice better performance, since direct-to-cloud routing kills the unnecessary backhaul. And your team manages fewer point products, which means less integration work, fewer consoles, and fewer patch cycles to chase.
That last point matters more than it first appears. Every disconnected security product is another vendor relationship, another console to watch, another set of logs that doesn't quite line up with the others. Consolidation into one architecture doesn't just simplify the diagram — it reduces the number of places a misconfiguration can hide.
SASE in the Saudi context
For organisations across the Kingdom pursuing Zero Trust and lining up with National Cybersecurity Authority (NCA) expectations, SASE offers a structured way to deliver identity-centric access and uniform security across scattered sites. [2] That matters a lot if you're expanding into new cities or running hybrid cloud. The Vision 2030 push has organisations opening locations faster than legacy WAN designs can comfortably absorb, and SASE was built for exactly that kind of distributed growth.
It also maps neatly onto the direction Saudi regulation is already moving. The NCA's controls push organisations toward identity-based access, continuous monitoring, and network segmentation — all of which are native to a SASE architecture rather than bolted on afterward. Adopting SASE isn't only a performance decision; done well, it puts you ahead of where compliance expectations are heading rather than scrambling to catch up.
A word of realism, though: SASE is a journey, not a purchase order. The organisations that struggle are the ones that try to swap everything at once. The ones that succeed sequence it — usually starting with SD-WAN modernisation or an SSE layer, then converging the rest as contracts renew and hardware ages out.
Frequently asked questions
Is SASE the same as SD-WAN? No. SD-WAN is one component of SASE — the networking layer. SASE adds the cloud-delivered security stack (SWG, CASB, FWaaS, ZTNA) on top. You can run SD-WAN without SASE, but you can't have full SASE without SD-WAN.
Do we have to replace all our existing hardware? No. A good SASE roadmap works with what you have and phases the transition, usually as circuits and appliances come up for renewal. Rip-and-replace is neither necessary nor advisable.
Does SASE replace our VPN? In most cases, yes — ZTNA is designed to replace broad VPN access with granular, per-application access. Many organisations run both briefly during the transition, then retire the VPN.
How long does a SASE rollout take? It depends on site count and complexity, but because it's phased, you see value early — often from the first SD-WAN or SSE stage — rather than waiting for a single big-bang cutover.
How ITBuilders helps
We design SASE around the environment you already have, rather than forcing a rip-and-replace that nobody's budget or nerves can handle. We start by assessing your current network and security stack, define a phased roadmap — often beginning with SD-WAN or an SSE layer — and integrate the components into one architecture that maps to your access and compliance requirements. Our engineers understand the local regulatory picture (NCA, SAMA, PDPL) and support you in both Arabic and English.
The result is a network that's simpler to run, quicker for your people, and more secure because of how it's built — not because of how many boxes you bolted on.
Want to see what a phased SASE roadmap looks like for your environment? Call 920-020-750 or email [email protected].
Sources & references
Turn this insight into a practical next step.
Discuss your environment with our team and get a clear recommendation grounded in your operational reality.


