Network security has long supported networks that were distinct places – such as offices, branches, and data centers – which shaped how data flowed and how security protected it. But in today’s distributed reality, a network is basically wherever work is happening. The new distributed networking world has turned every endpoint into its own network, and security models designed for centralized control can fracture, revealing gaps that attackers can exploit. The Centralized Network of Yesterday Traditionally, network security was built around control through concentration. Users, applications, and data could be consolidated in a small number of trusted locations, where IT and security teams could inspect traffic and enforce policies from the perimeter. The network had an inside and an outside, where users worked from inside offices and applications lived inside data centers. Security tools protected data from attackers on the outside. VPNs, firewalls, and other security software all emerged from this approach. But today with cloud services, SaaS platforms, and remote work now necessary for the distributed world, traffic no longer flows through a single chokepoint. Applications have moved to the outside of the perimeter, with “inside” no longer clearly defined. Many security solutions still cling to the centralized idea of a single chokepoint, forcing distributed activity through a central control that can’t protect a network that no longer has a center. Network Boundaries Become Infinite Edges In today’s new distributed world, applications no longer reside in data centers with SaaS platforms – the default way for collaboration, finance, and operations. Business infrastructure now resides on the cloud as users, contractors, and third parties access systems without ever setting foot inside an office. Infinite edges have replaced the traditional branch office, where networks stop having a fixed boundary and every user, device, and workload is now its own access point,
Designing SASE for Today's Distributed Networks
Read the original article
cybersecurity-insiders.com →