The Rise of SASE and 'Connectivity Security' - The Specialization of Advanced SSE Vendors
In 2026, the SASE (Secure Access Service Edge) market is reaching a critical turning point. Advanced SSE (Security Service Edge) pure-play vendors, once hailed as the 'kings of cloud security,' are being forced to redefine themselves due to the limitations of their architecture, and the market is shifting toward two directions: 'true network integration' and 'internet-native.' This article analyzes the challenges facing enterprise system security and examines the outlook for the SASE market over the next few years.
1. The Debt of 'Network Absence' in SSE
In the early 2020s, SSE, represented by Zscaler and Netskope, grew rapidly as a location-agnostic security solution. However, from the perspective of 2026, SSE can be evaluated as an 'incomplete intermediate form' on the way to an architecture that aligns with the reality of SASE.
The greatest flaw of SSE lies in the fact that it lacked integrated network management. SSE is a proxy-based 'secure gateway' that sacrifices 'network convenience'—such as line quality from branch to gateway, latency introduced by proxy intervention, and the handling of non-Web protocols. This 'network hole' is a bottleneck that cannot be ignored in the modern era, where business digitalization is accelerating and the importance of networks is increasing. Therefore, there is a movement to value SASE, which is network-integrated, over the SSE pure-play model, a trend visible in the strategies of Gartner and major vendors. On the other hand, in industries requiring high confidentiality such as finance and government, deep traffic inspection and existing network integration remain important, and there is a high possibility that hybrid configurations adding SD-WAN to traditional SSE or SSE will persist for a long time.
2. The Reality of the 'Half-Baked' Status Faced by Zscaler/Netskope
The 'Zero Trust SD-WAN' using Airgap technology acquired by Zscaler and the 'NewEdge' catch-up measures by Netskope have, ironically, exposed the limitations of their own architectures.
Limitations of Proxies
The proxy method, which decomposes and reconstructs all packets, is effective for advanced DLP (Data Loss Prevention) but involves structural latency for modern applications requiring real-time performance and the processing of massive IoT traffic. In traditional SSE, TLS decryption and L7 inspection are easily centralized, which becomes a factor in increased latency, especially in real-time communications.Bolt-on SD-WAN
For SSE vendors that 'added on' network functions later, there is concern from user enterprises that their 'integration as a single vendor' is weak. Methods requiring complex tunnel settings and appliance management increase administrative effort and difficulty, contrary to the expectations of 'simplicity' and 'integration' in the cloud era, and are facing harsh scrutiny from the market.
These vendors may be pushed into a limited market: the conservative enterprise sector that prioritizes 'advanced governance and isolation' above all else.
3. The Establishment of 'Two Major Forces' Dividing the Market
While Zscaler's ARR continues to maintain high growth, Cloudflare and Cato are also rapidly expanding in the enterprise sector. Over the next few years, major players in the SASE market are expected to move in the following two directions.
① 'Network Infrastructure Integration' Forces (Cato Networks, Palo Alto Networks, Fortinet, Cisco, HPE)
A camp that defines 'security as an essential element of network infrastructure.' Vendors that possess their own global L3 backbone (dedicated high-speed communication network), such as Cato Networks, provide enterprises with the practical benefit of 'guaranteed communication quality' in addition to security functions. 'True SASE,' which integrates inter-branch communication, cloud connectivity, and remote access with unified policies and a private network, is expected to gain support from the majority of companies because it significantly reduces operational burdens.
② 'Internet-Native' (Cloudflare One)
A camp that defines 'the network as the internet itself.' The approach utilizing an Anycast network, represented by Cloudflare, optimizes intermediate paths as an integrated network (Cloudflare is based on a powerful CDN) and completes processing in real-time at the edge. This model, which is highly transparent, low-latency, and does not sacrifice speed, is the optimal solution for the needs of modern enterprises that premise their operations on SaaS and AI utilization.
4. Outlook and Roadmap for the Next Few Years
Companies that do not require high levels of confidentiality are likely to increasingly choose platforms based on 'business mobility (connectivity)' rather than 'depth of security.' It is highly likely that they will move to a control plane where 'network, authentication, security, and observability' can be handled under a single policy.
2026-2027: Network-integrated SASE is valued, and the application area for SSE pure-play vendors is limited
Zscaler and Netskope are likely to maintain their superiority as 'highly specialized tools' in the short term to meet the advanced compliance requirements of specific industries (finance, public sector, healthcare, etc.) where demand for DLP and CASB remains strong. On the other hand, they are predicted to lose market share as general-purpose infrastructure. While Zscaler and Netskope continue to maintain high growth, Cloudflare, Cato, and Prisma Access are also rapidly expanding into the enterprise sector as their functions, data protection, and operational integration mature.2028 and beyond: Routing abstraction and autonomous control by AI
The concept of a 'Connectivity Cloud' (a cloud-based foundation that integrates network, security, and application delivery) advocated by Cloudflare will spread, and an era will arrive where routing is further automated and abstracted. It is predicted that even SD-WAN settings will be minimized, and a highly autonomous network environment will be realized where AI dynamically assigns the optimal path and security strength according to the type of traffic.
Prospects
The weaknesses that emerged as a result of Secure Service Edge (SSE) downplaying the importance of networking are difficult to compensate for with bolt-on features. Companies are turning their attention away from highly specialized SSE, which requires complex tunnel management, toward more general and flexible solutions like SASE, where infrastructure and security are seamlessly integrated. In other words, interest is shifting toward control planes that can cross-integrate identity, policy, and telemetry.
The era of 'sacrificing the network for the sake of security' is coming to an end.
As companies select their next-generation infrastructure, it is an opportunity to re-examine whether 'strict management (SSE)' or 'connection flexibility (Native SASE)' should be the management priority, given the prerequisites of governance, zero trust, and SaaS control. In the future SASE market, it is highly likely that the SSE type, which emphasizes 'deep governance,' and the connectivity security type, which emphasizes 'network integration and low latency,' will coexist by catering to different use cases.strict management (SSE)andconnection flexibility (Native SASE)should be the management priority, given the prerequisites of governance, zero trust, and SaaS control. In the future SASE market, it is highly likely that the SSE type, which emphasizes 'deep governance,' and the connectivity security type, which emphasizes 'network integration and low latency,' will coexist by catering to different use cases.
いいなと思ったら応援しよう!
この記事は noteマネー にピックアップされました

