SASE & Zero-Trust Security

SASE & Zero-Trust Security

Pain points

Pain points

Fragmented Security Stacks

Many organizations juggle separate VPN, firewall, and cloud-security solutions, creating policy gaps and inconsistent user experiences.

Hybrid Workforce Demands

As employees work from anywhere, companies need secure, location-agnostic access to applications. Managed SASE offerings integrate networking, security, and identity to reduce IT complexity and support hybrid work.

Integration Challenges

Most firms recognize the benefits of zero-trust and SASE, but integrating them with existing SD-WAN and identity platforms can be daunting.

How Thomson Helps

How Thomson Helps

We assess your network and security posture and educate you on SASE options from leading carriers and managed service providers. Our vendor-neutral comparison highlights which solutions combine SD-WAN with zero-trust security (ZTNA, firewall-as-a-service, secure web gateways, and identity management).

We assist with procurement, configuration oversight, and policy alignment while carriers handle the technical delivery. By documenting each recommendation and staying vendor agnostic, we ensure you adopt the right SASE framework without over-committing to proprietary tools.

Case Study

Case Study

Our CEO
Our CEO
Our CEO

SASE Deployment for a Hybrid Workforce in a Post-Pandemic Era

Client Type:

National professional services company with 1,200 employees
National professional services company with 1,200 employees
National professional services company with 1,200 employees

Goal:

Redesign the company’s WAN and security model to support a permanent hybrid workforce, maintaining consistent connectivity, visibility, and compliance.

Situation:

During the pandemic, the client shifted entirely to remote operations using legacy VPN infrastructure and regional firewalls.

While initially functional, the setup began to strain as the company evolved into a hybrid model, with half of the employees working from home and half returning to the office.

As cloud adoption increased (with Microsoft 365, Salesforce, and AWS-hosted apps), performance issues and security blind spots also grew.

Hurdles:

  • VPN congestion & latency: VPN concentrators designed for 200 users were now serving 800+ remote sessions daily.

  • VPN congestion & latency: VPN concentrators designed for 200 users were now serving 800+ remote sessions daily.

  • VPN congestion & latency: VPN concentrators designed for 200 users were now serving 800+ remote sessions daily.

  • Inconsistent policy enforcement: Home based users bypassed corporate firewalls, creating security gaps and compliance risks.

  • Inconsistent policy enforcement: Home based users bypassed corporate firewalls, creating security gaps and compliance risks.

  • Inconsistent policy enforcement: Home based users bypassed corporate firewalls, creating security gaps and compliance risks.

  • Cloud backhaul inefficiency: Internet-bound traffic was backhauled through the corporate data center, doubling latency and bandwidth costs.

  • Cloud backhaul inefficiency: Internet-bound traffic was backhauled through the corporate data center, doubling latency and bandwidth costs.

  • Cloud backhaul inefficiency: Internet-bound traffic was backhauled through the corporate data center, doubling latency and bandwidth costs.

  • Visibility challenges: Lacked insight into user activity once traffic left the VPN tunnel, which complicated threat detection and compliance reporting.

  • Visibility challenges: Lacked insight into user activity once traffic left the VPN tunnel, which complicated threat detection and compliance reporting.

  • Visibility challenges: Lacked insight into user activity once traffic left the VPN tunnel, which complicated threat detection and compliance reporting.

Outcome:

  • SASE architecture implemented with integrated SD-WAN, ZTNA (Zero Trust Network Access), and CASB (Cloud Access Security Broker).

  • Remote users now connect directly to the nearest secure edge node, instead of tunneling through HQ, which improves app latency.

  • Unified policies follow users regardless of location or device, delivering a consistent security posture for both on-site and remote staff.

  • Phased migration allowed the decommissioning of legacy VPN hardware and the consolidation of redundant firewall appliances, cutting recurring costs.

Takeaway:

Hybrid work isn’t a trend; it’s the new normal.

SASE enables enterprises to deliver office grade security and performance to every user, everywhere while simplifying management and cutting legacy costs.

Because we work with all major carriers, our only loyalty and transparency is to your expectations, not any vendor.

Let Thomson Technologies simplify telecoms and core infrastructure for your business.

© 2024 Thomson Technologies

Let Thomson Technologies simplify telecoms and core infrastructure for your business.

© 2024 Thomson Technologies

Let Thomson Technologies simplify telecoms and core infrastructure for your business.

© 2024 Thomson Technologies