Report | KuppingerCole Leadership Compass for SASE Integrated Suites, 2023
This report examines how SASE solutions consolidate SD-WAN, Secure Web Gateways, and Zero Trust architecture to enhance security and simplify network management. As remote work and cloud adoption grow, SASE offers scalable, cost-effective solutions to secure connectivity and protect organizational resources. Download the report to learn more about optimizing your security strategy with SASE.

SASE Integration Suites John Tolbert 6 February 2023
LEADERSHIP COMPASS: 81112
SASE Integration Suites
2
© 2023 KUPPINGERCOLE ANALYSTS AG 2
This report provides an overview of the market for Secure Access Service Edge (SASE)
Integration Suites. In this Leadership Compass, we examine the market segment, vendor
service functionality, relative market share, and innovative approaches to providing SASE
Integration solutions.
Contents
Contents .................................................................................................................................... 2
Figures ....................................................................................................................................... 3
Introduction / Executive Summary ............................................................................................ 4
Highlights ............................................................................................................................... 7
Market Segment .................................................................................................................... 8
Delivery Models ..................................................................................................................... 9
Required Capabilities .......................................................................................................... 10
Optional Capabilities ............................................................................................................ 12
Leadership ............................................................................................................................... 13
Overall Leadership .............................................................................................................. 13
Product Leadership ............................................................................................................. 14
Innovation Leadership ......................................................................................................... 16
Market Leadership ............................................................................................................... 18
Correlated View ....................................................................................................................... 20
The Market/Product Matrix .................................................................................................. 21
The Product/Innovation Matrix ............................................................................................ 23
The Innovation/Market Matrix .............................................................................................. 25
Products and Vendors at a Glance ......................................................................................... 26
Product/Vendor evaluation ...................................................................................................... 30
Aryaka Networks – SASE, SD-WAN Services .................................................................... 32
Cato Networks – SASE Cloud ............................................................................................. 35
Check Point – Harmony Connect ........................................................................................ 39
Cisco – Secure Connect ...................................................................................................... 43
Cloudflare – Cloudflare One ................................................................................................ 47
Ericom – ZTEdge Cloud Security Platform ......................................................................... 51
Lookout – SWG, CASB, and ZTNA ..................................................................................... 55
Open Systems – SASE + .................................................................................................... 59
Palo Alto Networks – SASE, Prisma Access, and Prisma SD-WAN .................................. 63
Versa Networks – SASE...................................................................................................... 67
LEADERSHIP COMPASS: 81112
SASE Integration Suites
3
© 2023 KUPPINGERCOLE ANALYSTS AG 3
Vendors to Watch .................................................................................................................... 71
Methodology ............................................................................................................................ 72
Types of Leadership ............................................................................................................ 72
Product rating ...................................................................................................................... 73
Vendor rating ....................................................................................................................... 74
Rating scale for products and vendors................................................................................ 75
Inclusion and exclusion of vendors ..................................................................................... 76
Figures
Figure 1: Overview of SASE Functions .................................................................................... 7
Figure 2: The Overall Leaders in Leadership Compass SASE Integration Suites ................ 13
Figure 3: The Product Leaders in Leadership Compass SASE Integration Suites ............... 14
Figure 4: The Innovation Leaders in Leadership Compass SASE Integration Suites ........... 16
Figure 5: The Market Leaders in Leadership Compass SASE Integration Suites ................. 18
Figure 6: The Market/Product Matrix for Leadership Compass SASE Integration Suites ..... 21
Figure 7: The Product/Innovation Matrix for Leadership Compass SASE Integration Suites 23
Figure 8: The Innovation/Market Matrix for Leadership Compass SASE Integration Suites . 25
LEADERSHIP COMPASS: 81112
SASE Integration Suites
4
© 2023 KUPPINGERCOLE ANALYSTS AG 4
Introduction / Executive Summary
With the rapid expansion of IT environments and adoption of cloud, and the ongoing Digital
Transformation, the need to provide secure access to organizational resources has become
paramount. The number and types of security tools addressing ever-evolving threats that are
in use across a typical organization continues to increase. Managing network connectivity
and security has become more expensive, complex, and time-consuming.
Secure Access Service Edge (SASE) solutions are designed to consolidate network and
security components, simplify management and licensing, and improve usability. SASE is the
union of a number of different networking and security technologies designed to improve
security posture as well as connectivity for remote offices, cloud services, contractors, and
remote employees, while driving down the cost of connectivity.
KuppingerCole defines SASE as the bundling of:
• Software Defined Wide Area Networking (SD-WAN)
• Secure Web Gateways (SWG)
• Remote Browser Isolation (RBI)
• Next Generation Firewalls (NGFW) and/or Firewall as a Service (FWaaS)
• Endpoint agents allowing secure remote access via modernized VPN technologies.
The agents may be bundled with or integrate with third-party products with security
features such as Endpoint Protection Detection & Response (EPDR) and Unified
Endpoint Management (UEM)
• Data Leakage Prevention (DLP) & Cloud Access Security Brokers (CASB)
• Zero Trust as the guiding security architecture incorporating digital identity
components such as digital identity storage, identity federation, Multi-Factor
Authentication (MFA), User Behavioral Analysis (UBA), and Role- and/or Attribute-
Based Access Controls (RBAC and ABAC respectively).
Therefore, we see that SASE is not a brand-new technology but is instead an innovative
packaging of security and networking solutions that can be better positioned to solve
contemporary and evolving business requirements. The technologies involved encompass
endpoints and both on-premises and cloud resident infrastructure and applications. SASE
Integration Suites must be capable of supporting hybrid environments. Moreover, most
organizations operate in and are further pursuing multi-cloud architectures.
Secure Access implies strong, multi-factor authentication and authorization for remote users
and devices, threat detection and protection, and fine-grained access controls. Work From
Home (WFH) and other drivers for remote work have been supported by VPNs for more than
two decades. The Covid pandemic necessitated WFH en masse, and the technologies that
remote work relies upon have proven to be highly effective. However, in many cases, the
performance of traditional VPNs has been strained. Scalability has been insufficient.
Managing network segmentation in conjunction with VPN access has become exceedingly
difficult in large enterprises. Organizations that allowed username/password authentication to
VPNs have become more aware of the significant risks of weak authentication and have
LEADERSHIP COMPASS: 81112
SASE Integration Suites
5
© 2023 KUPPINGERCOLE ANALYSTS AG 5
moved to require MFA. The deployment of MFA has increased complexity, thereby making
VPNs more difficult to manage.
Many organizations accept that Work from Anywhere (WFA) will be the norm going forward.
The need for Secure Access is greater than ever, with fraud, ransomware, and corporate
espionage on the rise. Remote worker access, including employees and contractors, needs
to be properly secured with strong authentication services and granular access controls.
Moreover, assurances that end user devices are not compromised must be part of the
Secure Access equation. Remote workers and contractors now do much of their work in the
cloud as well as by accessing resources in corporate data centers.
Prior to the pandemic, many kinds of organizations were experiencing tectonic shifts in
application and user distributions. The move to the cloud for applications and storage had
been gaining pace for the previous decade. Covid accelerated the migration to cloud
services. Protecting sensitive resources of an increasingly distributed enterprise with a large
mobile workforce is becoming a challenge that siloed security tools are not able to address
effectively. In addition to the growing number of potential threat vectors, the very scope of
corporate cybersecurity has grown immensely in recent years. SASE was postulated as a
means to connect distributed users more efficiently and securely with distributed
applications.
Organizations with a focus on IT security have been making users authenticate strongly for
years and have brought remote worker and branch office traffic back to the enterprise data
center(s) for security analysis. However, organizations with legacy VPN architectures found
that remote workers, offices, and contractors sometimes exercised options that decreased
overall security when encountering underperforming, backhauled connections. Some chose
to implement split-tunneling, allowing direct-to-cloud access for SaaS while routing internal
application traffic to data centers. In other cases, users disconnected themselves from slow
VPNs in order to go cloud-direct. In both of those scenarios, enterprises may lose the ability
to apply network, application, and data security policies. Older style, isolated VPN technology
will likely be replaced by contemporary, integrated SASE VPN solutions in the medium term.
Another problem that SASE’s updated approach to VPN addresses is automated routing and
failover between nodes. Early generation VPNs required user intervention to switch between
servers, which could often result in poor network performance as perceived by the user.
Moreover, advancements in cryptography and tunneling protocols such as WireGuard as
realized in some SASE solutions will provide security and routing benefits.
The Secure Service Edge part of SASE refers to the need for security where users and
networks intersect. Examples include LAN to LAN, data center to data center, branch office
to corporate, franchises to headquarters, remote production centers to HQ, sensors to
municipalities, on-premises to cloud, and remote users connecting to all scenarios above.
Security for these use cases tends to be more focused on device level assurance of integrity,
authentication, and authorization, supported by policies based on certificate authentication,
challenge-response, and allow- and deny-lists. In this scenario, NGFWs or FWaaS can
provide network and transport layer security, and CASB and SWG solutions provide the
session and application layer access controls and data object security. RBI acts as an
application layer web proxy that mediates users’ web requests, sandboxes suspicious
LEADERSHIP COMPASS: 81112
SASE Integration Suites
6
© 2023 KUPPINGERCOLE ANALYSTS AG 6
content, and renders web and application content safely, transmitting a view of the content
back to the user rather than the content itself.
SD-WAN technology was developed to enable businesses to use readily available high
speed internet connections rather than point-to-point private network services such as T1
lines, Frame Relay systems, or Multi-Protocol Labeling Switches (MPLS), or VPN mesh
architectures such as Dynamic MultiPoint VPN (DMVPN). Private networking solutions have
been reliable and reasonably secure for most customers, but expensive. These private
networking solutions are mainly delivered by telcos. In many cities around the world, it is now
possible for organizations to provision high speed internet connections (between 100 Mbps
to 1+ Gbps) from not only telcos, but also cable providers and other internet service
providers, often at a significant discount compared to point-to-point solutions. Mobile Network
Operators (MNOs) offer high-speed 4G LTE and 5G across many regions as well. SD-WAN
has also improved network and application performance by getting remote users and remote
offices closer to SaaS applications and enterprise services implemented at the edge
(services and entry points installed in high-bandwidth co-location facilities or by Content
Delivery Networks [CDNs]).
SD-WAN, SASE, and CDNs vendors use a variety of techniques to “accelerate” TCP
connections from the perspective of end users. Many point-to-point connections, including
those from remote workers, have unused capacity. The design of the transport protocol itself
can be the source of those kinds of bottlenecks. TCP, as implemented in OSes, will ramp up
the volume of data transmission until clients begin experiencing latency, packet loss, jitter,
etc. Then networking drivers and OSes will cut the data volumes (window size) in half, and
start trying to increase it again, but linearly.
A leading TCP optimization method involves the use of transparent TCP proxies. TCP
proxies sit between clients and target resources and buffer 2-3 TCP sequences ahead per
connection. This enables clients to receive data faster, and in the event of packet loss, retries
go to the proxy, which is in between and has stored up the next few rounds of data to
transfer. This method decreases the time that end users typically experience for large
downloads, uploads, and streaming. TCP optimization is particularly useful at the “edge,” at
Points of Presence that may be physically far from data centers and cloud resources.
Other TCP optimization methods involve changes to TCP flows, including Selective ACKs to
mitigate duplicate transmissions, using larger initial window sizes, and Bottleneck Bandwidth
testing to determine the optimal rates per connection.
The drawback for SD-WAN is that there is no explicit security beyond transport layer
encryption: meaning that point-to-point connection authentication and access controls, user
session authentication and authorization, and application authentication and access controls
are not addressed.
Since SD-WAN emerged, a number of security tool types have been extended to cover
shortcomings in the underlying model. SWGs are proxies used to consolidate and control
user and app web utilization. Endpoint Security tools discover and prevent exploitation of
vulnerabilities and execution of malware, provide application controls, and URL/content
filtering. NGFWs are application- and (in some cases) identity-aware firewalls. FWaaS are
LEADERSHIP COMPASS: 81112
SASE Integration Suites
7
© 2023 KUPPINGERCOLE ANALYSTS AG 7
cloud-hosted NGFWs. CASBs enable shadow IT discovery, Network Access Control (NAC)
points, and Data Leakage Prevention (DLP) Policy Enforcement Points (PEPs) for cloud-
hosted resources. Security stack vendors began packaging these as solutions to help
customers deal with the increasing complexity and risks of SD-WAN.
Zero Trust has arisen over the past decade and has become a primary means of addressing
access control use cases. Given the focus on the networking aspect, it is usually abbreviated
as ZTNA (Zero Trust Network Access). Often expressed as "Never trust, always verify",
ZTNA is an embodiment of the principle of least privilege, and at its core mandates that
every access request be properly authenticated and authorized. Thus, IAM (Identity and
Access Management) is a foundational element for ZTNA. Proper access management in
service of ZTNA means considering the requesting user's attributes, authentication and
environmental context, permissions and roles, source device information, and the requested
resource attributes. Zero Trust Architecture implies a concept where clients can access
services from everywhere, not relying only on internal network security mechanisms. In fact,
ZTNA has become the strategic IT security paradigm for many services and products.
Therefore, ZTNA is well-suited to help mitigate the shortcomings of SD-WAN and provide the
security structure for SASE.
SASE Integration Suites bring the power, flexibility, and costs saving potential of SD-WAN
together with security posture enhancements afforded by integrating CASB, Endpoint
Security, DLP, NGFW, SWG, RBI, and IAM in a Zero Trust Architecture. SASE, like Zero
Trust itself, embodies a wide range of functions that are often instantiated in multiple
products. Most enterprises, government agencies, non-profits, and small businesses already
have a plethora of security and networking solutions in place. SASE Integration Suites offer
the advantage of centralizing administrative control over these disparate technologies. SASE
Integration Suites must interoperate with tools in each security and identity domain to provide
comprehensive coverage and management for all requisite functions.
Figure 1: Overview of SASE Functions
LEADERSHIP COMPASS: 81112
SASE Integration Suites
8
© 2023 KUPPINGERCOLE ANALYSTS AG 8
Highlights
• The primary use cases for SASE are improving connectivity and security between
remote workers, contractors, data centers, branch offices and other distributed
facilities, and cloud-hosted resources.
• The rapid move to “Work from Anywhere” has caused performance problems in prior
generation VPN and site-to-site connections and has increased the size of many
organizations’ attack surfaces. SASE is gaining prominence as a concept and
solution architecture to address these and other issues.
• SASE is often defined within the IT security market as SD-WAN plus security. SD-
WAN enables the use of lower cost connections between users, sites, and cloud
resources. However, SD-WAN lacks security features beyond transport encryption.
• The SASE market is still emerging and evolving. The foundational features we
believe are necessary for SASE Integration Suites include SD-WAN (including VPN
for endpoints), firewall, Secure Web Gateway, Zero Trust Network Access, Remote
Browser Isolation, Data Protection (Data Leakage Protection and Cloud Access
Security Brokers), and Customer Support and Experience Management.
• The inclusion of endpoint security and management, such as the bundling of
Endpoint Protection Detection & Response (EPDR) and Unified Endpoint
Management (UEM) with SASE agents, is a desired goal of customers in order to
reduce the number of software agents deployed and complexity of enterprise IT
security and asset management. Such features are not built-in to SASE agents yet,
even amongst vendors who also have EPDR and UEM products.
• Not many of the vendors surveyed offer a complete range of SASE functions as
defined herein within their suites today. Some vendors’ SASE Integration Suites offer
these functions as add-ons from their own product/service portfolios, whereas others
partner with 3rd-party vendors, and other vendors leave it up to the customer to
acquire such functionality as needed. Some vendors whose SASE offerings are
currently incomplete have these additional features on their roadmap. This will be
indicated in the vendor analyses below, if known.
• The Overall Leaders in the Leadership Compass for SASE Integration Suites are
Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and Versa Networks.
• The Product Leaders in the Leadership Compass for SASE Integration Suites are
Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and Versa Networks.
• The Market Leaders in the Leadership Compass for SASE Integration Suites are
Cato Networks, Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and
Versa Networks.
• The Innovation Leaders in the Leadership Compass for SASE Integration Suites are
Cisco, Lookout, Palo Alto Networks, and Versa Networks.
Market Segment
Since SASE is not a revolutionary technology, traditional network and network security
vendors have been able to package and brand their products and services under the SASE
rubric. Several large vendors in the space had products and services that individually
addressed the technical functions and use cases defined for SASE, and it has been fairly
LEADERSHIP COMPASS: 81112
SASE Integration Suites
9
© 2023 KUPPINGERCOLE ANALYSTS AG 9
easy to group what they have available as a unified SASE offering. Other vendors offer
multiple products available under different SKUs but provide discounted packages that meet
the definition of SASE. Some of the innovation in this market involves evolving licensing and
subscription models to meet customer demand. The SASE market does have some smaller
players that initially offered a subset of the required functionality but have been moving to
add the full feature set that is typically associated with SASE.
Most vendors in this initial Leadership Compass on SASE Integration Suites do not currently
offer all features outlined herein as built-in capabilities. Instead, the larger vendors provide a
base set of SASE functions and offer as add-ons other products across their portfolios. Some
of the SASE specialist vendors take the approach of partnering with other vendors or
providing integration with multiple 3rd-party products. This is most commonly the case for
EPDR. UEM is also not a core component in SASE Integration Suites, but many SASE
services reviewed here do collect device information for risk-adaptive authentication, and
some have integrations with major UEM platforms.
Delivery Models
All solutions in this space have both on-premises and cloud components. Users’ endpoints
need agents that provide upgraded VPN capabilities, plus endpoint security functions
including anti-malware, detection & response, endpoint management, and DLP. Agents are
available for Windows desktops and servers, Macs, and Linux machines.
Most SASE solutions have gateways that facilitate site-to-site and site-to-cloud connectivity.
Gateways are usually delivered as physical or virtual appliances for easier installation. In
many cases, vendor services handle the dynamic selection of the most efficient routing from
between gateways, data centers, and cloud-hosted resources. In addition to laying the
foundation for SD-WAN, gateways can provide host- or site-based firewall services, secure
web gateway functions, and network threat detection and response capabilities.
PoPs, or Points of Presence, are locations where the SASE vendors have equipment and/or
facilities (SASE vendor equipment is sometimes co-located in other service provider facilities,
such as Telcos, MNOs, and cloud IaaS providers). PoPs are where SASE customer traffic
enters and exits their network/cloud. PoPs are where SASE vendors deploy cloud-based
security functions, such as FWaaS, SWG, RBI, CASB, etc. Most global SASE vendors
operate multiple PoPs per continent. Some have multiple PoPs per major metropolitan area.
Network performance inside the SASE cloud/backbone should be sufficient for most
customers, but one of the main considerations is latency between customer sites and remote
users to the PoPs. From a prospective customer standpoint, it is important to know where
SASE PoPs are located so that one can evaluate the vendor(s) with the most suitable PoP
locations and architecture. Another consideration is the number of and locations of vendors’
Network Operations Centers (NOCs), and the round-the-clock support models they offer.
Other SASE features are cloud-native, generally including secure web gateways, cloud
access controls, firewall services, Remote Browser Isolation, and management dashboards
and consoles.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
10
© 2023 KUPPINGERCOLE ANALYSTS AG 10
Services from vendors are an important part of SASE Integration Suites. Not only are
services needed for installation, software maintenance, and optimized routing, but most of
the players in the market provide technical support services for both administrative users and
end users as part of a standard contract. Offering direct support to remote workers and
contractors can be a service differentiator among SASE Integration Suites.
Required Capabilities
This Leadership Compass analyzes the main attributes and functions of SASE Integration
Suite solutions, including
• Flexible deployment models covering the most common permutations of distributed
sites, remote workers, contractors, and cloud resources. For on-premises data center
components, high-capacity gateway devices which provide distributed SASE services
(as described below) are advantageous. Solutions should include image files for
IaaS. Lastly, agents for desktop/laptop, server, and mobile operating systems must
be available. The more variety in OSes supported, the better suited a vendor’s
offering will be to organizations that are running multiple, diverse OSes.
• SD-WAN deployment and configuration, automated traffic routing and bandwidth
management. Some vendors do not use the standard overlay approach, rather they
rely upon network service providers. Depending on individual vendors’ approaches,
they may partner with network service providers or leverage customers’ existing ISPs.
• Secure connectivity between nodes, servers, and cloud resources. This essentially
means Virtual Private Network (VPN), although in some quarters that term has fallen
out of fashion. A number of protocols can provide secure connectivity and/or
tunneling (authenticated users and devices with encrypted data transfer) between
points: IPsec, SSH, TLS, and WireGuard. Innovation in this category would include
automated availability and performance testing between nodes with automatic failover
and routing based on the results of those tests; and the use of modern protocols such
as TLS 1.3 and WireGuard.
• Secure Web Gateways for web traffic policy enforcement, URL filtering, malware
detection, and content inspection. SWGs are proxy services that handle a variety of
internet and web traffic, applying policies in conjunction with customers’ IAM and
Network Access Control solutions. CASB functions are often integrated with SWGs.
• Next Generation Firewalls and Firewall-as-a-Service features to protect networks,
offices, data centers, cloud instances, and other resources from Denial of Service
(DoS), DNS, and application layer attacks. NGFW services include packet filtering,
Deep Packet Inspection (DPI), Encrypted Traffic Analysis, application awareness
(including the ability to route and filter based on traffic types), and network
segmentation. NGFWs may perform traffic decryption for security analysis, or in a few
cases, examine encrypted traffic using advanced Network Detection & Response
(NDR) methods such as JA3/JA3S, Mercury, etc. The firewall/NDR components, in
conjunction with Endpoint Protection Detection & Response tools (described below) if
present, usually can take mitigating actions such as process termination, connection
termination, node isolation, blocking of IPs/URLs, and initiating packet capture on
endpoints, gateways, and in the cloud.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
11
© 2023 KUPPINGERCOLE ANALYSTS AG 11
• Support for identity federation for Zero Trust Network Access (ZTNA). A small subset
of SASE vendors offers full Identity and Access Management (IAM) or Identity-as-a-
Service (IDaaS), thus acting as Identity Providers (IdPs) for their customers. Most
SASE solutions are identity relying parties, accepting Open ID Connect (OIDC) and
Security Assertion Markup Language (SAML) assertions for federated authentication
to their resources. In the latter scenario, the choice of authenticators depends on the
customers’ existing IAM or IDaaS. Strong and Multi-Factor Authentication (MFA)
options are recommended for SASE.
• Risk-adaptive and/or continuous authentication features for ZTNA. Although in many
cases SASE customers use identity services outside of the SASE solution, the SASE
Integration Suites can harvest authentication and session data to perform risk-
adaptive and continuous authentication and authorization.
• Remote Browser Isolation to protect end user devices from compromise from
malicious content from web and email. Remote Browser Isolation (RBI) is generally
hosted by SASE vendors in their clouds, allow customers to use the most widely
deployed browsers, with few configuration changes. Acquisition, scanning, and
execution of remote content happens in the vendors’ RBI environments, with inert
results passed to users. Remote Browser Isolation should be able to be applied by
user and resource types. Pixel rendering is an older but slower method for RBI. DOM
rewriting is a newer and faster RBI method. Pixel rendering is theoretically safer for
end users but has high latency. DOM rewriting may miss some malicious content in
web traffic. A few vendors are deploying newer technologies in this area that do not
conform to the models described here. Some SASE Integration Suites rely on 3rd-
party products for RBI functions.
• Data Leakage Prevention (DLP) functions, including data discovery and classification,
and definition and enforcement of security policies on endpoints. DLP systems
typically look for common data types such as Personally Identifiable Information (PII),
credit card numbers, Social Security Numbers, and other government identifiers, etc.
Customers should be able to create their own data types for DLP mechanisms to
enforce. Some SASE Integration Suites rely on 3rd-party products for DLP functions.
Enforcement actions include controlling the abilities to:
o Upload files to sites / attach files to email
o Read data
o Copy content to clipboard
o Download files
o Move or copy files via USB, Bluetooth, or optical drives
o Change file permissions
o Etc.
• Cloud Access Security Broker functions to discover cloud service usage, discover and
classify data, and enforce data security policy compliance in the cloud. In this context,
cloud includes major SaaS services such as Microsoft O365 and Teams, GSuite,
Salesforce, Slack, Concur, ServiceNow, JIRA, etc. Regarding data discovery,
classification, policy definition and enforcement, DLP and CASB should be
functionally similar across vendor solutions. User/group to resource entitlement
management and Role-Based Access Control (RBAC) are the most common access
control paradigms used. The use of Attribute-Based Access Control (ABAC) is
LEADERSHIP COMPASS: 81112
SASE Integration Suites
12
© 2023 KUPPINGERCOLE ANALYSTS AG 12
preferred. Some SASE Integration Suites rely on 3rd-party products for CASB
functions.
• Utilization of Cyber Threat Intelligence (CTI), either from sources internal to the
vendor, or from external subscriptions or open sources. CTI includes lists of known
malicious IPs, URLs, domains, file hashes and metadata, etc.
• Built-in link status, network utilization, security component status, and user
experience dashboards and reports
• SASE Integration Managed Services, allowing customers to offload deployment and
maintenance tasks to the vendor or Managed Service Provider partners
• Support for standards that facilitate interoperability with other components in the
security and IAM architecture. Relevant standards in IAM include FIDO, JWT, OAuth,
OIDC, and SAML. Standards for security are concerned with inter-application
information sharing and include CEF, REST API, SNMP, STIX, syslog, TAXII, etc.
• Certifications and attestations of compliance with applicable security and cloud
hosting programs, such as UK Cyber Essentials, US FedRAMP, ICSA, ISO/IEC
15408, ISO 27001/27018, SSAE SOC 2 Type 2, CSA Star Level, etc.
Optional Capabilities
The following sets of capabilities are not currently required but are considered as innovative
combinations of capabilities that may become essential parts of SASE Integration Suites in
the years ahead.
• Endpoint Protection Detection & Response (EPDR) for identifying malware or
malicious behavior and preventing damage, application control, URL/content filtering;
detection and remediation of malware or other security incidents on desktops,
servers, laptops, and mobile devices. There are four approaches that vendors can
take to EPDR in SASE:
o EPDR functions bundled in the SASE agent and included in the subscription. No
vendor currently offers EPDR and SASE together.
o EPDR available from the same vendor but licensed and instantiated separately.
o Partnership with one or more EPDR vendors.
o In some cases, SASE vendors do not offer as built-in or partner with EPDR
vendors but rather leave the choice to the customer about how to procure, deploy,
and manage endpoint security.
• Unified Endpoint Management (UEM) for asset management, device vulnerability and
security posture assessments. SASE endpoint agents have access to detailed device
information. Some vendors integrate with full UEM solutions in their wider suites;
some vendor products provide interoperability with 3rd-party UEM solutions via APIs;
and others do not leverage device information outside of the Device Posture Checks
that they perform for network access control.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
13
© 2023 KUPPINGERCOLE ANALYSTS AG 13
Leadership
Selecting a vendor of a product or service must not only be based on the information
provided in a KuppingerCole Leadership Compass. The Leadership Compass provides a
comparison based on standardized criteria and can help identify vendors that shall be further
evaluated. However, a thorough selection includes a subsequent detailed analysis and a
Proof of Concept of pilot phase, based on the specific criteria of the customer.
The Overall Leadership rating provides a combined view of the ratings for
• Product Leadership
• Innovation Leadership
• Market Leadership
The Overall Leadership chart is linear, with Followers appearing on the left side, Challengers
in the center, and Leaders on the right.
Overall Leadership
Figure 2: The Overall Leaders in Leadership Compass SASE Integration Suites
Overall Leaders are (in alphabetical order):
• Check Point
• Cisco
• Cloudflare
• Lookout
• Palo Alto Networks
• Versa Networks
The Overall Challengers are (in alphabetical order): Aryaka Networks, Cato Networks,
Ericom Software, and Open Systems. There are no vendors in the Followers section.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
14
© 2023 KUPPINGERCOLE ANALYSTS AG 14
Product Leadership
Product Leadership is the first major category examined below. This view is mainly based on
the presence and completeness of required features as defined above. The vertical axis
shows the product strength plotted against the combined/overall strength on the horizontal
axis. The Product Leadership Chart is rectangular and divided into thirds. Product Leaders
occupy the top section. Challengers are in the center. Followers are in the lower section.
Figure 3: The Product Leaders in Leadership Compass SASE Integration Suites
Product Leaders (in alphabetical order):
• Check Point
• Cisco
• Cloudflare
• Lookout
LEADERSHIP COMPASS: 81112
SASE Integration Suites
15
© 2023 KUPPINGERCOLE ANALYSTS AG 15
• Palo Alto Networks
• Versa Networks
The Product Challengers are (in alphabetical order): Aryaka Networks, Cato Networks,
Ericom Software, and Open Systems. There are no Followers in the Product Leadership
rating.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
16
© 2023 KUPPINGERCOLE ANALYSTS AG 16
Innovation Leadership
Next, we examine innovation in the marketplace. Innovation is, from our perspective, a key
capability in all IT market segments. Customers require innovation to meet evolving and even
emerging business requirements. Innovation is not about delivering a constant flow of new
releases. Rather, innovative companies take a customer-oriented upgrade approach,
delivering customer-requested and other cutting-edge features, while maintaining
compatibility with previous versions.
This view is mainly based on the evaluation of innovative features, services, and/or technical
approaches as defined in section 1.4. The vertical axis shows the amount of innovation
plotted against the combined/overall strength on the horizontal axis. The Innovation
Leadership Chart is rectangular and divided into thirds. Innovation Leaders occupy the top
section. Challengers are in the center. Followers are in the lower section.
Figure 4: The Innovation Leaders in Leadership Compass SASE Integration Suites
LEADERSHIP COMPASS: 81112
SASE Integration Suites
17
© 2023 KUPPINGERCOLE ANALYSTS AG 17
Innovation Leaders (in alphabetical order):
• Cisco
• Lookout
• Palo Alto Networks
• Versa Networks
The Innovation Challengers are (in alphabetical order): Aryaka Networks, Cato Networks,
Check Point, Cloudflare, Ericom Software, and Open Systems. There are no Followers in the
Innovation rating.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
18
© 2023 KUPPINGERCOLE ANALYSTS AG 18
Market Leadership
Lastly, we analyze Market Leadership. This is an amalgamation of the number of customers,
number of reported PoPs and NOCs, numbers of employees, the geographic distribution of
customers, the size of deployments and services, the size and geographic distribution of the
partner ecosystem, and financial health of the participating companies. Market Leadership,
from our point of view, requires global reach.
The vertical axis shows the market strength plotted against the combined/overall strength on
the horizontal axis. The Market Leadership Chart is rectangular and divided into thirds.
Market Leaders occupy the top section. Challengers are in the center. Followers are in the
lower section.
Figure 5: The Market Leaders in Leadership Compass SASE Integration Suites
Market Leaders (in alphabetical order):
LEADERSHIP COMPASS: 81112
SASE Integration Suites
19
© 2023 KUPPINGERCOLE ANALYSTS AG 19
• Cato Networks
• Check Point
• Cisco
• Cloudflare
• Lookout
• Palo Alto Networks
• Versa Networks
The Market Challengers are (in alphabetical order): Aryaka Networks, Ericom Software, and
Open Systems. There are no Followers in the Market Leadership rating.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
20
© 2023 KUPPINGERCOLE ANALYSTS AG 20
Correlated View
While the Leadership charts identify leading vendors in certain categories, many customers
are looking not only for a product leader, but for a vendor that is delivering a solution that is
both feature-rich and continuously improved, which would be indicated by a strong position in
both the Product Leadership ranking and the Innovation Leadership ranking. Therefore, we
provide the following analyses that correlate various Leadership categories and deliver an
additional level of information and insight.
The following charts are rectangular and divided into nine equal sections. A dashed line
intersects the rectangle at the point where x- and y-axis values are equal.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
21
© 2023 KUPPINGERCOLE ANALYSTS AG 21
The Market/Product Matrix
The first of these correlated views contrasts Product Leadership and Market Leadership.
The vertical axis represents the market position plotted against product strength rating on the
horizontal axis.
Figure 6: The Market/Product Matrix for Leadership Compass SASE Integration Suites
Vendors below the line have a weaker market position than expected according to their
product maturity. Vendors above the line are sort of “overperformers” when comparing
Market Leadership and Product Leadership. All the vendors below the line are
underperforming in terms of market share. However, we believe that each has a chance for
significant growth.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
22
© 2023 KUPPINGERCOLE ANALYSTS AG 22
The square at the top right contains the Market Champions, which are (in alphabetical order):
Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and Versa Networks.
Cato Networks is in the top center above the line. Aryaka Networks is in the center square
above the line. Ericom Software and Open Systems are also in the center square but below
the line. The other squares are empty.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
23
© 2023 KUPPINGERCOLE ANALYSTS AG 23
The Product/Innovation Matrix
This view shows how Product Leadership and Innovation Leadership are correlated. It is not
surprising that there is a pretty good correlation between the two views with a few
exceptions. The distribution and correlation are tightly constrained to the line, with a
significant number of established vendors plus some smaller vendors.
The vertical axis represents the product strength rating plotted against innovation on the
horizontal axis.
Figure 7: The Product/Innovation Matrix for Leadership Compass SASE Integration Suites
Vendors below the line are more innovative, vendors above the line are, compared to the
current Product Leadership positioning, less innovative.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
24
© 2023 KUPPINGERCOLE ANALYSTS AG 24
The square at the top right contains the Technology Leaders, which are (in alphabetical
order): Cisco, Lookout, Palo Alto Networks, and Versa Networks.
Check Point and Cloudflare are in the top center box. Open Systems is in the center square
above the line. Aryaka Networks, Cato Networks, and Ericom Software are in the center
square below the line. All other squares are empty.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
25
© 2023 KUPPINGERCOLE ANALYSTS AG 25
The Innovation/Market Matrix
The third matrix shows how Innovation Leadership and Market Leadership are related. Some
vendors might perform well in the market without being Innovation Leaders. This might
impose a risk for their future position in the market, depending on how they improve their
Innovation Leadership position. On the other hand, vendors which are highly innovative have
a good chance for improving their market position. However, there is always a possibility that
they might also fail, especially in the case of smaller vendors.
The vertical axis represents the market position rating plotted against innovation on the
horizontal axis.
Figure 8: The Innovation/Market Matrix for Leadership Compass SASE Integration Suites
LEADERSHIP COMPASS: 81112
SASE Integration Suites
26
© 2023 KUPPINGERCOLE ANALYSTS AG 26
Vendors above the line are performing well in the market as well as showing Innovation
Leadership; while vendors below the line show an ability to innovate though having less
market share, and thus the biggest potential for improving their market position.
The square at the top right contains the Big Ones, which are (in alphabetical order): Cisco,
Lookout, Palo Alto Networks, and Versa Networks.
Cato Networks, Check Point, and Cloudflare are in the top center square above the line.
Aryaka Networks is in the center square above the line. Ericom Software and Open Systems
are in the center square below the line. All other squares are empty.
Products and Vendors at a Glance
This section provides an overview of the various products we have analyzed within this
KuppingerCole Leadership Compass on SASE Integration Suites. Aside from the rating
overview, we provide additional comparisons that put Product Leadership, Innovation
Leadership, and Market Leadership in relation to each other. These allow identifying, for
instance, highly innovative but specialized vendors or local players that provide strong
product features but do not have a global presence and large customer base yet.
Based on our evaluation, a comparative overview of the ratings of all the products covered in
this document is shown in Table 1.
Product Security Functionality Deployment Interoperability Usability
Aryaka Networks Positive Neutral Neutral Neutral Positive
Cato Networks Strong
Positive Positive Neutral Weak
Strong
Positive
Check Point Strong
Positive Positive Positive Positive
Strong
Positive
Cisco Strong
Positive
Strong
Positive Positive Positive
Strong
Positive
Cloudflare Positive Positive Strong Positive Positive Strong
Positive
Ericom Positive Positive Neutral Neutral Positive
Lookout Strong
Positive
Strong
Positive Positive Strong Positive Positive
Open Systems Positive Neutral Neutral Neutral Positive
Palo Alto Networks Strong
Positive
Strong
Positive Strong Positive Positive
Strong
Positive
Versa Networks Strong
Positive
Strong
Positive Positive Strong Positive
Strong
Positive
Table 1: Comparative overview of the ratings for the product capabilities
LEADERSHIP COMPASS: 81112
SASE Integration Suites
27
© 2023 KUPPINGERCOLE ANALYSTS AG 27
In addition, we provide in Table 2 an overview which also contains four additional ratings for
the vendor, going beyond the product view provided in the previous section. While the rating
for Financial Strength applies to the vendor, the other ratings apply to the product.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
28
© 2023 KUPPINGERCOLE ANALYSTS AG 28
Vendor Innovativeness Market Position Financial Strength Ecosystem
Aryaka Networks Neutral Positive Positive Strong Positive
Cato Networks Positive Strong Positive Positive Strong Positive
Check Point Positive Strong Positive Strong Positive Strong Positive
Cisco Strong Positive Strong Positive Strong Positive Strong Positive
Cloudflare Positive Strong Positive Strong Positive Strong Positive
Ericom Neutral Neutral Neutral Neutral
Lookout Strong Positive Strong Positive Positive Positive
Open Systems Neutral Weak Neutral Weak
Palo Alto Networks Strong Positive Strong Positive Strong Positive Strong Positive
Versa Networks Strong Positive Strong Positive Positive Positive
Table 2: Comparative overview of the ratings for vendors
In Tables 3 and 4, we provide a short overview of SASE functional areas provided by each
vendor. The functional areas are described above. The answer key is below:
Yes = this solution includes this functionality as part of their SASE Integration Suite
No = these features are not available in the vendor’s SASE Integration Suite
Via Partners = Though the functionality is not present in the vendor’s platform, they do have
partnerships and/or API level connectors with 3rd-party products and services that can
provide it. This is perceived to be a more substantive approach than those vendors which
state that the functionality in question could be obtained by customers coding between their
APIs and 3rd-party service APIs.
Add-on = This vendor offers another product or service within their broader portfolio that can
provide this functionality but licensed separately.
For Zero Trust Network Access (ZTNA), we indicate which SASE Integration Suites serve as
Identity Providers (IdP) and those which can act as Relying Parties (RP) to external IAM and
IDaaS solutions.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
29
© 2023 KUPPINGERCOLE ANALYSTS AG 29
Table 3: SASE functions per vendor
Product SD-WAN SWG FW EPDR UEM
Aryaka Networks Yes Yes Yes No No
Cato Networks Yes Yes Yes No No
Check Point Yes Yes Yes Yes No
Cisco Yes Yes Yes Add-on No
Cloudflare Yes Yes Yes Via partners Via partners
Ericom Yes Yes Yes No No
Lookout Yes Yes No No Via partners
Open Systems Yes Yes Yes No Via partners
Palo Alto Networks Yes Yes Yes Add-on Via partners
Versa Networks Yes Yes Yes No Via partners
Table 4: SASE Functions per vendor, continued
Product ZTNA UBA DLP CASB RBI
Aryaka Networks RP Yes Via partners Via partners No
Cato Networks RP Yes Yes Yes No
Check Point IdP / RP No Yes Yes Yes*
Cisco IdP / RP Yes Yes Yes Yes
Cloudflare RP Yes Yes Yes Yes
Ericom IdP / RP Yes Yes Yes Yes
Lookout RP Yes Yes Yes Yes
Open Systems IdP / RP Yes No Via partner No
Palo Alto Networks IdP / RP Yes Yes Yes Via partners
Versa Networks RP Yes Yes Yes Yes
*Check Point provides capabilities similar to what is described for Remote Browser Isolation
using different technology.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
30
© 2023 KUPPINGERCOLE ANALYSTS AG 30
Product/Vendor evaluation
This section contains a quick rating for every product/service we’ve included in this
KuppingerCole Leadership Compass document. For many of the products there are
additional KuppingerCole Product Reports and Executive Views available, providing more
detailed information.
Spider graphs
In addition to the ratings for our standard categories such as Product Leadership and
Innovation Leadership, we add a spider chart for every vendor we rate, looking at specific
capabilities for the market segment researched in the respective Leadership Compass. For
the LC SASE, we look at the following eight categories:
• Connectivity – this category rates the transport layer offerings available within the
solution and/or ability for customers to select SD-WAN operators; traffic capacities;
number, size, and distribution of Points of Presence (PoPs); scalability and service
level guarantees.
• ZTNA (Zero Trust Network Access) – this category evaluates the authentication and
authorization options present for end users, administrative users, devices, and
resources. Preference is given for MFA, federation, and attribute and/or policy-based
access controls. This rating also considers interoperability with IAM/IDaaS solutions
beyond identity federation, such as Privileged Access Management (PAM).
• Endpoint – this category measures the variety of endpoint OSes for which agents are
available, and EPDR and UEM features that are either available as add-ons from the
SASE vendor or tightly integrated with 3rd-party sources. As of the publication date,
no SASE vendors offer EPDR bundled with their SASE solutions.
• Network security – this dimension represents the capabilities for detecting and
responding to threats at the network level, such as DDoS, command & control traffic,
botnet traffic, reconnaissance by adversaries, lateral movement, and data exfiltration
attempts. Many of these functions are implemented in the on-premises and/or cloud-
hosted virtual appliance components of the SASE solution. These functions are
typically handled by the Next-Generation Firewall and Firewall-as-a-Service
components. However, in some vendor solutions, these functions are implemented in
the SWG components.
• Web security – distinct from the network security rubric, this heading rates the Secure
Web Gateway and Remote Browser Isolation features within each solution. In most
cases, these functions are cloud-hosted, but, depending on the vendor’s architecture,
may also be present in the on-premises gateway appliances. In a few vendor
solutions, RBI functions are outsourced but integrated.
• Data protection – this category evaluates the DLP/CASB types of functionalities
present in reviewed products, such as the ability to define access control policies
centrally, and to discover, classify, and enforce data access control policies on
endpoints and the cloud. The policy management interface can be hosted by the
vendor in the cloud or by the customer on gateways. The discovery, classification,
and enforcement functions are mostly carried out by endpoint DLP agents and cloud-
resident CASB agents.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
31
© 2023 KUPPINGERCOLE ANALYSTS AG 31
• Administration – this metric examines the features of the administrative interface,
including overall ease-of-use for deploying and managing connectivity, quality of
dashboards and various kinds of utilization and security reports, ability to investigate
performance and possible security events, and connections with customer
infrastructure such as ITSM, SIEM, and SOAR systems.
• End user support – this category rates the availability and methods for vendor-direct
support for customer end users. Preference is given for solutions that include direct
assistance for end-users via phone, email, other messaging apps, etc. This rating
also takes into account language coverage for documentation and technical support.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
32
© 2023 KUPPINGERCOLE ANALYSTS AG 32
Aryaka Networks – SASE, SD-WAN Services
Aryaka Networks was founded in 2009 and is headquartered in San Mateo, CA. The
company is a late-stage venture-backed network security specialist. Aryaka’s SASE solution
includes SD-WAN, SWG, FWaaS, ZTNA, and DLP. Aryaka Networks offers individual SASE
components separately including SD-WAN, Multi-Cloud Networking, and VPN-as-a-Service,
as well as Content Delivery Networking, WAN Optimization, bandwidth aggregation, QOS,
SaaS acceleration, and other services. Aryaka Network Access Point (ANAP) is the on-
premises gateway, with models ranging in bandwidth from 150Mbps to 3Gbps. The
enterprise console is hosted in co-location facilities. All-inclusive site connectivity is billed by
Mbps throughput, and per-user and per-SaaS app accessed. Tiered subscription models
offering volume discounts are available. Their NOC is in India. They have 32 POPs in APAC,
EMEA, and NA.
Aryaka leverages tier-1 carriers for their layer 2/3 SD-WAN overlay. They provision circuits to
ISPs for customers if needed. Aryaka uses multiple TCP optimization techniques. 4G and 5G
are supported. The SWG is SaaS-hosted, and performs URL filtering, malware scanning and
sandboxing, and supports customer configurable allow/deny lists and authentication policies.
Certificate policy enforcement is not yet present. Firewall services include DNS filtering,
Deep Packet Inspection (DPI), application traffic detection and analysis, network
segmentation, and threat detection and response actions such as session termination, host
isolation, and packet capture. Aryaka partners with a few leading NGFW vendors as well.
Agents are available for Windows 7-11, 20H2, and Server 2022; all major Linux types; and
MacOS 10+. The agents use IPsec tunneling to get to Aryaka PoPs. An agentless approach
is on the roadmap. The agents do not provide endpoint security functions. No
incompatibilities with other vendors’ EPDR agents are reported. Aryaka agents do not
provide endpoint management features, nor do they integrate directly with UEM solutions.
For ZTNA, Aryaka acts as an IAM relying party, integrating with Microsoft Active Directory
(AD) and Azure AD, Okta, Ping, and any SAML-enabled Identity Provider (IdP).
Authentication services are handled by these external identity services. Aryaka employs
Machine Learning (ML)-based User Behavioral Analysis (UBA). Connectors are available for
many SaaS apps.
DLP and CASB are not built-in, but Aryaka does have partnering arrangements with leading
vendors. They are planning to build these toolsets into their SASE solution.
Aryaka does not support Remote Browser Isolation at present. IPaaS, SNMP, and syslog
enable connectivity with customers’ other security solutions. No connectors for customer
SOARs are available.
The Aryaka console has site and link dashboards, SLA metrics, and billing reports. The
customer admin interface is easy to use and extensible as needed. It supports the full range
of functions including access control and QoS policy creation and investigative drill-downs.
The SWG dashboard is currently separate from the main interface, but Aryaka plans to
merge them; for now, SSO is enabled between them. Aryaka provides technical support for
both customer admins via phone, email, and website, but not for customer end users.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
33
© 2023 KUPPINGERCOLE ANALYSTS AG 33
Aryaka Networks is both ISO 27001 and SOC 2 Type 2 certified. Their strengths are in the
SD-WAN, traffic acceleration, SWG, and firewall aspects of SASE. Zero Trust Networking
and IAM integration are also present. Other components are in work. DLP/CASB can be
added on via 3rd-party vendor relationships. Organizations that already have EPDR and UEM
but that need better connectivity for remote workers and field locations will want to consider
Aryaka’s solution.
Security Positive
Functionality Neutral
Deployment Neutral
Interoperability Neutral
Usability Positive
Strengths
• SD-WAN plus circuit provisioning for customers if needed
• Dual private layers 2 and 3 backbone
• High availability SLA: 99.999%
• High-speed gateways
• Multiple traffic acceleration methods used
• WAN, app, and SaaS optimization
• IPaaS for integration with ITSM
• Excellent admin interface
Challenges
• Does not have browser isolation
• DLP/CASB optionally provided through 3rd-party vendors; own DLP/CASB planned
• No agentless connectivity options yet
• ZTNA enhancements are in work
• ABAC model not supported
• No direct support for end users
LEADERSHIP COMPASS: 81112
SASE Integration Suites
34
© 2023 KUPPINGERCOLE ANALYSTS AG 34
LEADERSHIP COMPASS: 81112
SASE Integration Suites
35
© 2023 KUPPINGERCOLE ANALYSTS AG 35
Cato Networks – SASE Cloud
Cato Networks, based in Tel Aviv, was founded in 2015. They are a well-funded venture-
backed specialist in SD-WAN and security. Cato offers a wide range of SASE components,
individual products, and the SASE subset called Secure Service Edge. For SASE, Cato
Network has SD-WAN, SWG, NGFW, ZTNA, and CASB features. Cato Socket is the
physical or virtual gateway appliance, with bandwidth ranges between 500Mbps and 5Gbps.
The Cato Management Console is hosted in IaaS in Ireland. Pricing is based on numbers of
users and bandwidth. Cato has 80+ PoPs covering APAC, EMEA, LatAm, and NA.
Cato uses multiple tier-1 backbone providers upon which they construct their global
backbone service and leverages multiple techniques for TCP acceleration. Cato SASE Cloud
is SaaS, providing SWG and firewall services including URL filtering, ML-powered malware
detection, customer configurable access control and certificate policies and allow/deny lists.
In terms of firewall-type services, Cato SASE Cloud offers DNS filtering, Deep Packet
Inspection, advanced malware detection, and network zone enforcement.
Cato has agents for Windows 8-11, CentOS, Ubuntu, MacOS, Android, and iOS. TLS 1.2/1.3
is used for remote client to PoPs. The agents have limited endpoint security features. Cato’s
SPACE product does Device Posture Checks (DPC) and can initiate patching or other
remediations. There are no connectors for UEM products, but customers can configure
connections over APIs if needed. Agents are not needed for clients behind Cato Socket
devices.
Cato acts as an identity relying party, and has integrations with Microsoft AD, Azure AD,
Google, and OneLogin. However, SAML is not supported. Built-in MFA is limited to OTP.
Cato performs ML-enhanced UBA, evaluating multiple risk factors. Many integrations for
SaaS apps are available.
For DLP and CASB, Cato performs data discovery and classification on 360+ pre-defined
data types. Customers cannot create their own data labels. Disk/file encryption and Data
Access Governance interoperability are not present yet. A few common DLP/CASB
enforcement actions are not supported. The CASB component enables cloud usage
discovery. Their NGFW and CASB functions recognize nearly 6,000 application types.
User/group entitlements and RBAC models are available, working in concert with customer
IAM/IDaaS.
Cato does not have Browser Isolation currently, but it is planned. Customers can access log
data via GraphQL, the Cato Cloud API, or csv export. Syslog and SNMP are not supported.
There are no connectors for SIEM, SOAR, or ITSM.
Cato’s customer admin dashboard includes many out-of-the-box reports covering a wide
variety of common regulatory compliance metrics. Customer admin support is unlimited via
email, phone, and website, but support is not directly provided for customer end users.
Cato Networks has obtained ISO 27001 and SOC 2 Type 2 certifications. Though the service
is missing some SASE features, Cato SASE includes a global backbone with traffic
acceleration, SWG, firewall services, and DLP/CASB. Their DLP/CASB recognizes an
above-average number of data types. Cato needs to support additional standards for
LEADERSHIP COMPASS: 81112
SASE Integration Suites
36
© 2023 KUPPINGERCOLE ANALYSTS AG 36
interoperability with customer IAM and security components. Organizations looking for the
networking enhancement side of SASE, and that have other security tools in place to provide
endpoint security and management, will want to consider Cato Networks.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
37
© 2023 KUPPINGERCOLE ANALYSTS AG 37
Security Strong Positive
Functionality Positive
Deployment Neutral
Interoperability Weak
Usability Strong Positive
Strengths
• High availability SLA: 99.999%
• High-speed gateways
• Multiple, converged Tier 1 network providers form their global private backbone
• Cato SPACE performs DPCs, routing decisions, traffic optimization, and has endpoint
remediation capabilities
• Supports Encrypted Traffic Analysis and User Behavioral Analysis
• Excellent admin dashboard with many reports available, including regulatory and
security policy compliance
Challenges
• Lacks Remote Browser Isolation functions
• Does not support SAML for IdP interoperability
• DLP/CASB has a good subset of expected enforcement actions available; ABAC not
supported
• Only GraphQL is supported for API
• Lacks connectors for ITSM, SIEM, and SOAR
Leader in
LEADERSHIP COMPASS: 81112
SASE Integration Suites
38
© 2023 KUPPINGERCOLE ANALYSTS AG 38
LEADERSHIP COMPASS: 81112
SASE Integration Suites
39
© 2023 KUPPINGERCOLE ANALYSTS AG 39
Check Point – Harmony Connect
Check Point is a global cybersecurity leader, founded in 1993 in Tel Aviv. Check Point
Harmony Connect is the primary SASE product. Check Point Harmony Total is a bundling of
endpoint, browser, mobile, and SASE products. Check Point also offers next-gen firewalls,
edge security solutions, IoT security gateways, VPNs, cloud security solutions, and complete
SOC management solutions. In terms of SASE components, Check Point has SD-WAN,
SWG, NGFW, EPDR, ZTNA, and DLP. Gateways are Docker-based containers with up to
850Mbps bandwidth each. The enterprise management console is SaaS-hosted across
multiple IaaS providers. Licensing costs are calculated per user, with two different packages:
one for internet access and one for remote access plus ZTNA. Check Point has 80+ PoPs
around the world.
Customers typically add Check Point security services over their existing SD-WAN
connections. Check Point recently launched their own SD-WAN service. Check Point hosts
their SWG, but customers can choose to install it on-prem or in IaaS. SWG features include
URL and SNI filtering, and advanced Content Disarm & Reconstruction (CDR) technology,
which removes executable code from email and web sessions allowing safe delivery of
previously infected content. Their SWG supports customer configurable web access and
certificate policies and allow/deny lists. Firewall functions include DNS filtering, Deep Packet
Inspection, sandboxing, and network segmentation. Other functions include application
control, C2 protection, and integrated IPS.
Agents are available for Windows 8-11 and MacOS; Linux agents are in work. Agents use
TLS 1.3 for comms to PoPs. Check Point supports agentless reverse proxy access to their
PoPs as well. Check Point Harmony Endpoint provides full EPDR functionality and can
collect device information for access controls. Agents can be deployed via InTune. No
incompatibilities with other vendors’ EPDR products are reported.
Check Point can serve as an IdP, offering username/password and mobile push
authentication. CheckPoint can be a relying party to Microsoft AD, Azure AD, Duo, Google,
Okta, Ping, or any SAML issuing IdP. OIDC is not supported. UBA is on their product
roadmap. There are no pre-built connectors for SaaS apps.
For DLP and CASB, Check Point performs data discovery and classification, drawing up on
more than 800 pre-defined data types. Customers can create their own data types to search
on as well. Integration with Data Access Governance and file encryption management is not
supported. The endpoint agent can prevent unauthorized copying of files to removable
media, uploading data to sites, downloading files, and attaching to email. Check Point’s DLP
extends to messaging apps such as Slack and Teams, and SaaS apps such as Box,
Dropbox, OneDrive, etc., allowing granular control over what users can share over those
channels.
Check Point Harmony Browse provides a “nano agent” in users’ browsers to prevent
phishing, corporate credential reuse, and known and zero-day malware. The most common
browsers are supported. This add-on solution is an alternative to Browser Isolation, which
Check Point believes performs better.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
40
© 2023 KUPPINGERCOLE ANALYSTS AG 40
Check Point products use REST API, SNMP, and syslog for communicating with other
security components. There are no specific connectors for ITSM or 3rd-party SOAR solutions,
however. The admin interface is intuitive, allowing customers to easily manage access rules
and check status and security of connections. Many reports are available. Check Point
provides support for both customer admins and end users over phone, web, and email.
Check Point has certifications in ICSA, ISO 27001/27017/27018, NIAPC, SOC 2 Type 2, UK
Cyber Essentials, and for multiple relevant products in Common Criteria. As a long-
established global security vendor in many product categories, it is not surprising that Check
Point emphasizes the security aspects of SASE: firewall, secure remote access VPN, EPDR,
SWG, and ZTNA. Check Point was an Overall, Product, Innovation, and Market Leader in the
Leadership Compass on Network Detection & Response. SD-WAN is in early availability and
will be GA in early 2023. The DLP capabilities in Check Point Harmony Connect and the
Harmony Browse add-on (the Browser Isolation alternative) are innovative. Organizations
looking for rigorous security in a SASE solution should put Check Point on their evaluation
list.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
41
© 2023 KUPPINGERCOLE ANALYSTS AG 41
Security Strong Positive
Functionality Positive
Deployment Positive
Interoperability Positive
Usability Strong Positive
Strengths
• Strong DLP features that prevent data exfiltration via messaging and collaboration
platforms
• Content Disarm & Reconstruction increases protection and user productivity
• TLS 1.3 support
• Can serve as IdP or RP for Zero Trust Network Access
• Harmony Browse add-on is an innovative Browser Isolation alternative
• Harmony Total has EPDR
• Excellent customer admin interface
Challenges
• SASE and endpoint security agents are distinct but can be managed from central
console
• Does not currently perform UBA
• OIDC not supported for ZTNA
• ABAC model is not supported
Leader in
LEADERSHIP COMPASS: 81112
SASE Integration Suites
42
© 2023 KUPPINGERCOLE ANALYSTS AG 42
LEADERSHIP COMPASS: 81112
SASE Integration Suites
43
© 2023 KUPPINGERCOLE ANALYSTS AG 43
Cisco – Secure Connect
Cisco is a global network and security leader, founded in 1984, and headquartered in the
Bay Area of California. Cisco is well-known for networking products, and has solutions for
mobile, cloud, and IoT. Cisco has products addressing all aspects of SASE. Any Cisco
networking device that supports IPsec termination can serve as a gateway. Cisco offers
gateways for clientless ZTNA, which can be delivered as containers or VMs. Enterprise
management consoles are SaaS-hosted in IaaS and Cisco facilities. Licensing costs are
determined on a per-user basis. Cisco has four NOCs and 26 PoPs distributed globally.
Customers can provision Cisco SD-WAN on top of their existing ISP connections. Multiple
traffic acceleration techniques are employed. Cisco hosts SWG for clients. It performs URL
filtering, malware detection and sandboxing, DNS security, web access control and certificate
policy enforcement, and allows customers to maintain their own allow/deny lists. The firewall
includes DNS filtering, Deep Packet Inspection, IDS/IPS, malware detection, and security
analysis integration. Cisco XDR enables thorough detection and detailed responses including
process termination, session termination, host isolation, and automatic firewall rule updates.
Agents are available for Windows 8-11, Ubuntu, MacOS 10.14+, Android, and iOS. Reverse
proxy architecture for agentless access is supported. Agents use IPsec and TLS 1.2 for PoP
communications. Cisco Secure Endpoint (sold separately) contains full EPDR functionality.
No incompatibilities with other EPDR tools have been discovered. Cisco Secure Connect
interoperates with many UEM platforms.
Cisco can act as a relying party to any OIDC or SAML enabled identity provider. Cisco
Secure Connect includes Duo identity provider services with multiple MFA options including
username/password, mobile push, SMS OTP, Duo authenticator app, CAC/PIV card, FIDO
2.0 & WebAuthn, OIDC, RADIUS, and SAML. Cisco integrates with Identity Governance and
Privileged Access Management services. The solution performs ML-enhanced UBA. Many
connectors for SaaS apps are present.
Cisco’s DLP and CASB do data discovery and can classify hundreds of pre-defined data
types, and customers can create their own. File encryption management is not supported,
and there are no integrations with Data Access Governance systems. Enforcement actions
are limited. CASB is implemented in the firewall and SWG components, and additional
functions can be obtained in Cisco Umbrella and Cloudlock. Cloud resource usage can be
detected. Access controls are constrained to user/group entitlements. Customer key
management is not addressed.
Cisco offers Browser Isolation as SaaS, which intercepts and protects all covered users’ web
traffic using the DOM rewriting approach. Email can also be protected if clients use web
email interfaces.
Cisco leverages their Cisco Secure Malware Analytics for threat intelligence. All relevant
communication protocols are supported, enabling facile connections with other parts of
customer IAM and security architectures such as SIEM and SOAR. ServiceNow ITSM can be
integrated. The Cisco Defense Orchestrator Console presents much information but is easy
to navigate and use. Moreover, it can be customized as needed. Cisco handles technical
LEADERSHIP COMPASS: 81112
SASE Integration Suites
44
© 2023 KUPPINGERCOLE ANALYSTS AG 44
support for their customer admins as well as end users over phone, email, chat, and their
website.
Cisco is planning US FedRAMP Moderate certification for Secure Connect, but no other
certifications have been completed yet. Cisco is an Overall, Product, Innovation, and Market
leader in the Leadership Compass on Zero Trust Network Access and Leadership Compass
on Network Detection & Response. Though there are just a few areas of improvement
possible, Cisco’s Secure Connect is a very comprehensive solution that should be on the
short list of any organization looking for SASE.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
45
© 2023 KUPPINGERCOLE ANALYSTS AG 45
Security Strong Positive
Functionality Strong Positive
Deployment Positive
Interoperability Positive
Usability Strong Positive
Strengths
• Good array of SASE components and services
• High-speed gateways
• Cisco XDR is bundled, which enables real-time response to incidents
• Full featured firewall, SWG, and secure VPN
• Complete IDaaS with wide range of MFA options available in Duo, packaged with
Secure Connect
• Many pre-defined data types for DLP
• Excellent standards support facilitates interoperability with many 3rd-party products in
IAM and security
Challenges
• Secure Endpoint is sold separately
• DLP and CASB enforcement actions are limited; full CASB requires Cloudlock add-on
• No integration with Data Access Governance
• File encryption at the endpoint and key management in the cloud are not addressed
Leader in
LEADERSHIP COMPASS: 81112
SASE Integration Suites
46
© 2023 KUPPINGERCOLE ANALYSTS AG 46
LEADERSHIP COMPASS: 81112
SASE Integration Suites
47
© 2023 KUPPINGERCOLE ANALYSTS AG 47
Cloudflare – Cloudflare One
Cloudflare was founded in 2009 and is headquartered in San Francisco, CA. Cloudflare is a
leading Content Delivery Network (CDN) and provider of network security services such as
API gateway, WAF, DDoS protection, and bot management. For SASE components,
Cloudflare has SD-WAN, SWG, FWaaS, Layer 7 DDoS protection, ZTNA, DLP, CASB, and
RBI. Gateways are delivered as software agents or Docker containers, with bandwidth only
limited by customer equipment. The enterprise management console is hosted by Cloudflare
in their facilities. Service pricing is determined by numbers of users and bandwidth.
Cloudflare has edge computing facilities in 275 cities in 100 countries.
Cloudflare offers Network-as-a-Service (NaaS), Magic WAN, and integrates with leading SD-
WAN vendors like HP, Aruba, and Cisco, and leverages multiple IP and TCP optimization
methods. All their SASE components are delivered via their global network. Cloudflare One
performs URL filtering and signature-based malware scanning. Customers can write their
own allow/deny lists and web access and certificate rules. Firewall functions include DNS
filtering, application awareness, Deep Packet Inspection, and network segmentation;
Encrypted Traffic Analysis and Intrusion Detection are on the roadmap.
Cloudflare has agents for Windows 8-11 and Server 20H2/2022, most major Linux types,
MacOS 10+, Android, and iOS. Agentless reverse proxy architecture is supported. Agents
use WireGuard for communicating with PoPs. Cloudflare does not provide EPDR
functionality, but partners with some major vendors. The Cloudflare agents do have some
incompatibilities with 3rd-party security software: check the latest Cloudflare documentation
for updates. Cloudflare performs Device Posture Checks for compliance with customer
access control policies. A number of UEM integrations are available.
In the context of ZTNA, Cloudflare acts as an identity proxy and relying party. Any OIDC or
SAML issuing IdP can be used. Authentication policies can leverage any authenticator
supported by these IdPs. As an identity proxy, Cloudflare supports secure token exchange.
Cloudflare performs basic UBA, evaluating many risk factors surrounding each session, and
can optionally consider some 3rd-party intelligence sources. Advanced UBA with ML
detection models is on their roadmap.
Agent-based DLP is on Cloudflare’s roadmap. Cloudflare One can detect US SSNs and
credit card numbers and enforce policies on those data types via their gateway and SWG.
CASB is limited to cloud resource usage and data security policy violation detection.
Cloudflare has integrations for some popular SaaS apps such as Microsoft O365, Google
Workspace, Box, Salesforce, Slack, and GitHub. Data discovery and classification are limited
at present, but the Remote Browser Isolation function can prevent upload/download of data
by file types. Encryption management and Data Access Governance interoperability are not
present. User/group to resource entitlement and RBAC methods are supported.
Cloudflare uses its patented Network Vector Rendering (NVR) technology for Remote
Browser Isolation. NVR streams draw commands instead of pixels to deliver remote
browsers to users without introducing the latency of the more common, bandwidth-intensive
pixel rendering method. Cloudflare believes this approach is safer because it removes the
LEADERSHIP COMPASS: 81112
SASE Integration Suites
48
© 2023 KUPPINGERCOLE ANALYSTS AG 48
risk of the transport layer becoming an attack vector. Their NVR runs in the SWG and CASB
components or purely as SaaS by Cloudflare.
The primary response action available is to initiate packet capture for analysis and action by
other security tools. Cloudflare has REST APIs and supports Terraform for security tool
integration, including ITSM, SIEM, and SOAR. Syslog and SNMP have not been requested
much by their customers and are therefore not currently supported. Cloudflare has setup
wizards to quickly enable customers to create web access control rules. The admin interface
is straightforward to use and contains basic dashboards, analytics, and reports. Their
customers generally use the API to push logs to 3rd-party SIEM tools for in-depth analysis.
Customers cannot at present create new report types. Support for customer admins is
unlimited, and both standard and premium options are available. Admin support channels
include phone, email, website, and Slack. Direct end user support is not available.
Cloudflare is ISO 27001, PCI-DSS, and HIPAA/HITRUST certified. SOC 2 Type 2
certification has not been achieved. US FedRAMP certification is in progress. Cloudflare
offers maximum scalability in their SASE solution. Cloudflare has some innovative features,
such as the NVR Remote Browser Isolation method and WireGuard protocol for VPN. It
needs to extend the solution with full DLP/CASB, UBA, and to support more standard
communications protocols to increase interoperability. Organizations that have scalability as
a primary requirement for SASE and that want to leverage their existing EPDR and
DLP/CASB tools will want to closely evaluate Cloudflare’s SASE services.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
49
© 2023 KUPPINGERCOLE ANALYSTS AG 49
Security Positive
Functionality Positive
Deployment Strong Positive
Interoperability Positive
Usability Strong Positive
Strengths
• Large globally distributed edge presence, sophisticated traffic acceleration
• Massive backbone capacity
• 100% uptime guarantee
• Encrypted Traffic Analysis for security
• WireGuard for VPN
• Innovative Remote Browser Isolation built on Network Vector Rendering technology
• HIPAA/HITRUST certification
• Freemium model for SMBs under 50 seats
Challenges
• Signature-based malware scanning only; no sandboxing
• Does not perform Encrypted Traffic Analysis
• UBA is in work, but 3rd-party solutions can be harnessed currently
• Agent-based DLP is in development, DLP and CASB functions are limited
• No direct support for end users
Leader in
LEADERSHIP COMPASS: 81112
SASE Integration Suites
50
© 2023 KUPPINGERCOLE ANALYSTS AG 50
LEADERSHIP COMPASS: 81112
SASE Integration Suites
51
© 2023 KUPPINGERCOLE ANALYSTS AG 51
Ericom – ZTEdge Cloud Security Platform
Ericom Software was founded in 1993 and is headquartered in New Jersey and has R&D in
and Israel. Ericom had been primarily focused on remote access and web security solutions
but moved into SASE last year when it introduced its ZTEdge platform targeted at midsize
enterprises and small businesses. Ericom’s SASE offerings include SD-WAN, SWG, NGFW,
ZTNA, DLP, CASB, RBI, and basic IAM with MFA. Additional functions include Content
Disarm & Reconstruction (CDR) via integration, virtual meeting security and web application
isolation. All gateways are cloud-hosted with up to 10Gbps bandwidth. Pricing is per-user
per-year. ZTEdge is managed by Ericom in three NOCs in a follow-the-sun support system.
Ericom has 51 PoPs deployed in public IaaS providers across APAC, EMEA, LatAm, and
NA.
ZTEdge uses a private backbone (with full mesh options) for their SD-WAN service, which
they term “Cloud Area Network”. Routing optimization is used, but traffic acceleration is not.
The SWG performs URL filtering and malware scanning but omits some other security
analysis functions. Customers can elect to use the built-in CDR services as an alternative to
traditional sandboxing technology (which is not available in the solution). Customers can
create web access and certificate policies and customized allow/deny lists. ZTEdge firewall
services perform DNS filtering, Deep Packet Inspection, and Encrypted Traffic Analysis;
however, application detection is not supported.
Agents are available for Windows 10/11, Windows Server 2016+, all major Linux types,
MacOS 10+, and Android. Their Web Application Isolation feature, which is a reverse proxy
architecture, provides agentless connection options. Agents communicate with PoPs over
WireGuard. ZTEdge does not perform endpoint security functions such as malware
prevention and detection. There are no known incompatibilities with other vendors’ EPDR
solutions. Their agent does collect device info for posture checks but there are no
integrations with third-party UEM platforms.
For ZTNA, Ericom can act as an IdP, accepting username/password, hardware tokens,
OAuth, OIDC, RADIUS, and SAML authentication; it can be a relying party to any OIDC or
SAML issuing IdP. No connectors for SaaS apps are available. ZTEdge’s ZTNA component
does basic UBA, examining multiple risk factors but does not accept external sources of
intelligence.
In terms of DLP and CASB, ZTEdge does not do data discovery but can provide limited
enforcement for a large list of common data types. DLP rules must be edited using RegExp.
Encryption management and Data Access Governance integration are not part of the feature
set. It can detect cloud usage. Only user/group to resource entitlements are supported as
access controls.
ZTEdge has full Remote Browser Isolation features, leveraging multiple rendering
approaches. ZTEdge emphasizes their Virtual Meeting Isolation solution, which protects end
user meeting hardware interfaces (microphones and cameras) within Zoom, Google Meet,
Microsoft Teams, and Cisco WebEx.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
52
© 2023 KUPPINGERCOLE ANALYSTS AG 52
ZTEdge only alerts customers about incidents via syslog to their SIEMs. No connectors for
ITSM or SOAR are available yet. It can capture packets for analysis, terminate sessions,
isolate hosts, and block comms by IP and port. The customer admin dashboard shows all the
relevant status items and allows drill-down for further investigations. An automatic policy
builder is being refined which should make access control authoring and maintenance easier.
Technical support for customer admins is available in either business day or 24/7 packages,
over phone, email, web, and Slack. Direct end user support is offered by Ericom, and is also
provided through some MSSP relationships.
ZTEdge is not ISO 27001 certified, but SOC 2 Type 2 has been achieved. ZTEdge has high
uptime guarantees. ZTEdge also has some innovative features, such as the use of
WireGuard and its use of isolation technology to secure not just web browsing, but also
virtual meetings, instant messaging, and unmanaged device access to cloud applications.
ZTEdge is missing some aspects of full SASE as outlined above, but customers can choose
3rd-party products to address those gaps as needed. Enterprises, especially mid-size
businesses and mid-market organizations, looking for a solution that covers the functional
components addressed by this solution (including specialties in secure video conferencing)
should consider ZTEdge.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
53
© 2023 KUPPINGERCOLE ANALYSTS AG 53
Security Positive
Functionality Positive
Deployment Neutral
Interoperability Neutral
Usability Positive
Strengths
• High availability SLA: 99.999%
• WireGuard for VPN
• Can act as RP or IdP with MFA for ZTNA
• Includes integrated 3rd-party CDR service
• DLP enforcement functions leverage long list of pre-defined data types
• Multiple Remote Browser Isolation technologies included as standard in SWG
• Virtual Meeting Isolation for optimal security in Zoom, Teams, Meet, and WebEx
Challenges
• No traffic acceleration
• Sandboxing, network segmentation, and advanced network traffic analysis are not
supported
• Does not do data discovery/classification; limited DLP/CASB features
• Some security certifications are still in progress
LEADERSHIP COMPASS: 81112
SASE Integration Suites
54
© 2023 KUPPINGERCOLE ANALYSTS AG 54
LEADERSHIP COMPASS: 81112
SASE Integration Suites
55
© 2023 KUPPINGERCOLE ANALYSTS AG 55
Lookout – SWG, CASB, and ZTNA
Lookout was founded in 2002 and is headquartered in San Francisco, CA. Lookout started
as a mobile security vendor but has evolved into an endpoint-to-cloud security vendor.
Lookout addresses most aspects of SASE: SD-WAN, FWaaS, SWG, ZTNA, DLP, CASB,
and RBI. On-premises concentrators are delivered as physical appliances with 120 Mbps
bandwidth capabilities. The enterprise console is hosted in AWS. Lookout did not disclose
the number and distribution of PoPs, although it states that the APAC, EMEA, and NA
regions are covered.
Lookout partners with a single large SD-WAN provider and add security services for
customers. Traffic acceleration is not offered. Lookout’s SWG is SaaS-hosted, and MSSPs
operate it as well. Their SWG does URL filtering, malware scanning, and sandboxing.
Customers can edit web access and certificate policies and allow/deny lists. Firewall services
allow creation of simple rules based on source, destination, traffic type, and group attributes.
Lookout has agents for Windows 10/11 and Windows Server 2016+. MacOS, iOS, and
Android agents are on their roadmap. Agents use IPsec for communicating with their PoPs.
Reverse proxies enable agentless access. Lookout performs malware scanning in the cloud,
and has mobile security agents, but endpoint security functions are not present in the
deployed agents. There are no known incompatibilities with other vendors’ EPDR tools.
Lookout has integrations with IBM MaaS 360, Ivanti, Microsoft Endpoint Manager, and
VMware Workspace One for UEM.
Lookout can act as an identity relying party to Microsoft AD, Azure AD, Duo, Google, Okta, or
any SAML-enabled IdP; thus, MFA to Lookout SASE is mediated by the customer’s IdP.
OIDC is not supported. Many connectors for SaaS apps are available and customers can
create their own for HTTPS, SSH, and RDP protocols. Lookout performs UBA powered by
ML detection models.
DLP and CASB features include data discovery and classification. The solution understands
Boldon James, Microsoft AIP, and Titus classification systems. Many data types and rule
templates are present out-of-the-box, and customers can create and edit more extensively.
Lookout handles policy-based encryption. Integration with Data Access Governance
solutions is not available. The full range of DLP enforcement actions is present. The CASB
side detects cloud resource usage and supports cloud security posture assessments for IaaS
and SaaS. Customers are provided with multiple key management options. User/group
entitlement, RBAC, and ABAC models are supported.
SaaS-based Remote Browser Isolation encompassing the major methods is offered. All
covered end users’ web and email traffic can be scanned and scrubbed. Lookout leverages
their own plus 3rd-party threat intelligence.
Customers can be alerted via email, Slack, or ServiceNow. In terms of response actions,
Lookout can regulate downloads/uploads, terminate sessions, block comms by IP and port,
and isolate hosts. Additional capabilities are available via their platform’s interoperability with
multiple ITSM, SIEM, and SOAR platforms over REST APIs. The administrative interfaces
present information clearly, facilitate traffic analysis through their dedicated engine, enable
LEADERSHIP COMPASS: 81112
SASE Integration Suites
56
© 2023 KUPPINGERCOLE ANALYSTS AG 56
forensic investigations, and can be extended if needed. Technical support for both admins
and end users is available in tiered options for business day or 24/7 coverage, over phone,
email, web, and Zoom.
Lookout is ISO 27001, SOC 2 Type 2, and US FedRAMP Moderate certified. The only major
functional omission, a firewall service, is due to be addressed soon. Higher capacity
gateways would be beneficial. Lookout has strengths in DLP/CASB, Remote Browser
Isolation, and fine-grained authorization. Organizations that are seeking SASE solutions with
innovative data security features should closely evaluate Lookout’s platform.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
57
© 2023 KUPPINGERCOLE ANALYSTS AG 57
Security Strong Positive
Functionality Strong Positive
Deployment Positive
Interoperability Strong Positive
Usability Positive
Strengths
• Advanced UBA and risk-based authentication for ZTNA
• DLP and CASB work with 3rd-party data classification solutions
• Full range of DLP enforcement actions and policy-based encryption available
• Many SaaS apps supported
• RBAC and ABAC allow granular authorization
• Thorough Remote Browser Isolation methods employed
• ITSM, SIEM, and SOAR interoperability
• Customer admin interface is comprehensive, easy to navigate, and supports forensic
investigations
Challenges
• Limited endpoint agents available, though more are planned
• NGFW on their roadmap for the near term
• Gateways do not come in virtualized or containerized deployments; with typical max
throughput of 120Mbps each
• No traffic acceleration
• OIDC is not supported for ZTNA
Leader in
LEADERSHIP COMPASS: 81112
SASE Integration Suites
58
© 2023 KUPPINGERCOLE ANALYSTS AG 58
LEADERSHIP COMPASS: 81112
SASE Integration Suites
59
© 2023 KUPPINGERCOLE ANALYSTS AG 59
Open Systems – SASE +
Open Systems was founded in 1990. They are headquartered in Zurich, Switzerland. For
SASE, they have SD-WAN, SWG, NGFW, ZTNA, and CASB. Some functions are provided
through partnerships. Gateways are deployed as physical or virtual appliances with between
5-10Gbps throughput. The enterprise management console is jointly hosted in their facilities
and Azure PaaS in Switzerland. Pricing is based on the numbers of users and includes the
managed service fee for 24x7 support and customer success team. Open Systems
leverages hundreds of Unitas Global, Neterra, Equinix, and Microsoft facilities across six
continents as PoPs.
Open Systems partners with a networking provider for transport. Open Systems offers traffic
shaping/compression and application caching for acceleration. Their SWG can be run on-
premises, in IaaS, and Open Systems hosts it as SaaS. The SWG performs URL filtering,
malware scanning and blocking, and enables access control and certificate policy
enforcement. Sandboxing and Advanced Threat Protection (ATP) are add-ons. CASB
functions integrate with the SWG. Open Systems’ firewall services include DNS filtering,
ATP, NDR with Encrypted Traffic Analysis and Deep Packet Inspection, and application
detection and routing.
Open Systems has agents for Windows 7-11, Windows Server 2016+, all major Linux
variants, MacOS 10+, Android, and iOS. Agentless options are available through a reverse
proxy architecture. Open Systems does not provide built-in EPDR features but recommends
use of Microsoft Defender for endpoint security functions. No UEM capabilities or integrations
are available.
For ZTNA, Open Systems can serve as a relying party to Google, Microsoft AD & Azure AD,
Okta, Ping, or any IdP/IDaaS that supports LDAP, OIDC, RADIUS, or SAML. Directory
synchronization is available out-of-the-box. Open Systems can also act as an IdP and
authentication service, accepting username/password, SMS OTP, CAC/PIV, and FIDO 2.0
methods. Open Systems has some connectors for popular SaaS apps.
The DLP functions that are available are blocking up/downloads, controlling clipboard
capabilities, and controlling access to network drives and printers. CASB functions are
provided with the base product license through partnership with a prominent CASB vendor.
Remote Browser Isolation is not part of the solution yet.
Customers can be alerted via email, SMS, SNMP, and through their ticketing API.
Interoperability with ITSM, SIEM, and SOAR platforms can be achieved through their REST
API. Open Systems NOC can take remedial actions including terminating connections,
isolating endpoints, and blocking traffic by IP or domain. The customer admin dashboards
show most of the common statistics. The interface could use some modernization. Open
Systems’ technical account managers must make changes to report information and
structures if customers desire. As an MSSP, Open Systems provides 24/7 support for
customers over phone, email, web, or Microsoft Teams, for both customer admin users and
end users.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
60
© 2023 KUPPINGERCOLE ANALYSTS AG 60
Open Systems is ISO 27001 and SOC 2 Type 2 certified. Their solution is missing some
expected features as listed above. Their strengths are in the firewall, SWG, and agent
support areas. They also emphasize services and have a relatively long history in the MSSP
business, which they leverage to help operationalize SASE for their multi-national enterprise
customers. Organizations that are looking for the subset of SASE functions available should
consider Open Systems SASE +.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
61
© 2023 KUPPINGERCOLE ANALYSTS AG 61
Security Positive
Functionality Neutral
Deployment Neutral
Interoperability Neutral
Usability Positive
Strengths
• High-speed gateways
• Advanced firewall capabilities include ETA and application aware routing
• Support for wide variety of OSes
• Multiple traffic acceleration techniques used
• Can act as both IdP and relying party for ZTNA functions
• Syslog support for SIEM interoperability; API integration with ServiceNow ITSM
Challenges
• Does not have agent-based DLP, or RBI built-in; EPDR and CASB functions are
available via partnerships
• SWG policy authoring and report customization requires vendor support
• No IGA or PAM support
• CTI and SOAR integrations require some coding
• Admin interface needs improvement
LEADERSHIP COMPASS: 81112
SASE Integration Suites
62
© 2023 KUPPINGERCOLE ANALYSTS AG 62
LEADERSHIP COMPASS: 81112
SASE Integration Suites
63
© 2023 KUPPINGERCOLE ANALYSTS AG 63
Palo Alto Networks – SASE, Prisma Access, and Prisma SD-WAN
Palo Alto Networks, founded in 2005 in Santa Clara, CA, is the pioneer in Next Generation
Firewall (NGFW) technology. Palo Alto Networks also offers endpoint security, SOAR, XDR,
threat intelligence feeds, Cloud Native Application Protection Platform (CNAPP), and other
security products. For SASE, Palo Alto Networks has SD-WAN, SWG, NGFW & FWaaS,
EDPR, and ZTNA. Additional services include DLP, CASB, sandboxing, DNS security, IoT
security, and Advanced Threat Protection. Remote Browser Isolation is available through
partners. Gateways are available as physical or virtual appliances, and VM instances that
can run in IaaS, with throughput up to 635 Gbps. The enterprise management console is
hosted as SaaS running in data centers in North America and Europe. There are four
editions of their SASE services, with options for local or global PoP access, and options for
standard or premium support. Subscriptions are based on measures of numbers of users or
network bandwidth required. More than one hundred Prisma Access PoPs are available
across six continents.
Palo Alto Networks partners with multiple global Tier 1 telecom and cloud service providers
for connectivity. Their SASE solution relies on connection quality monitoring for optimization;
TCP acceleration techniques are not used. The SWG can run on-prem or as a SaaS in the
cloud. MSSPs also operate the product using Palo Alto Networks’ multitenancy capabilities.
Prisma Access does advanced URL filtering and malware detection/prevention and
sandboxing. Customers can write access control and certificate policies and allow/deny lists.
CASB functions are integrated into Prisma Access and support SSPM capabilities. The
NGFW performs DNS filtering, Deep Packet Inspection, application-aware routing, and
network segmentation.
Palo Alto Networks has agents for Windows 7-11, most major Linux distributions, MacOS
10+, iOS, and Android. Clientless mode is supported via reverse proxy architecture. Agents
can use IPsec and TLS 1.2/1.3 for tunneling. Full endpoint security is provided by Palo Alto
Networks’ Cortex XDR product (not included as part of the base SASE license). The agents
collect detailed device information for security posture checks. Palo Alto has integrations with
Ivanti/MobileIron, JAMF, Microsoft Endpoint Manager, and VMware Workspace One for
UEM.
Palo Alto Networks can act as an IdP or as a relying party to SAML-based IdPs such as
Microsoft AD, Azure AD, Duo, Google, Okta, and Ping Identity. Directory sync over APIs or
SCIM is permitted. OIDC is not supported. In cases where Palo Alto Networks is acting as
IdP, MFA options include username/password, mobile push, SMS OTP, mobile app,
CAC/PIV cards, FIDO 2.0, hardware tokens, and RADIUS. Many SaaS app connectors are
present. Palo Alto Networks provides some UBA within the SASE product, and advanced
UBA capabilities available as an add-on through Palo Alto Networks’ Cortex XDR.
For DLP and CASB, data discovery and classification features are present. Prisma Access
recognizes many file and non-file data types. Customers can extend these as needed.
Endpoint encryption management and Data Access Governance integrations are not
present. A few expected DLP/CASB enforcement action types are not available. Customers
can manage cloud instance encryption keys via the console. User/group entitlements, RBAC,
and ABAC models are supported.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
64
© 2023 KUPPINGERCOLE ANALYSTS AG 64
Palo Alto Networks does not have RBI built-in, but does partner with Authentic8, Ericom
ZTEdge, Menlo Security, and Proofpoint.
A full range of alerting mechanisms are used, including Microsoft Teams and Slack. Palo Alto
Networks has excellent automated response capabilities covering all expected actions. CEF,
syslog, and REST APIs facilitate interoperability with any SIEM. ServiceNow ITSM
integrations and Palo Alto Networks’ XSOAR integrations are available. The customer admin
interface starts with well-designed but customizable dashboards and allows drill downs for
detailed analyses. Many reports are available and more can be created if needed. Customer
support for both admins and end users is available via phone, email, or web.
Palo Alto Networks has obtained many security certifications, including ISO 27001/27018,
SOC 2 Type 2, Common Criteria, French ANSSI, German C5, ICSA Labs, UK NSCS, and
US FedRAMP. Palo Alto Networks is an Overall, Product, Innovation and Market Leader in
the Leadership Compass Zero Trust Network Access and Leadership Security Orchestration
Automation & Response. Their solutions are scalable, innovative, and focused on security
and interoperability. Palo Alto Networks Prisma SASE should be near the top of the
consideration list for any organization looking for these services.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
65
© 2023 KUPPINGERCOLE ANALYSTS AG 65
Security Strong Positive
Functionality Strong Positive
Deployment Strong Positive
Interoperability Positive
Usability Strong Positive
Strengths
• Deeply configurable management interface well-suited for experts, and professional
services available
• 99.999% uptime for Prisma Access
• Extremely scalable, high-speed gateways
• Broad OS support
• Excellent firewall services
• Can act as IdP or IAM relying party
• CASB key management
• Connectors to 3rd-party UEMs present
• Many file types discoverable and schema can be extended by customers as needed
in DLP implementation
• ABAC for granular authorization in DLP & CASB (add-on)
Challenges
• Complex subscription model
• Remote Browser Isolation not built-in but available through partners
• TCP acceleration techniques not used
• OIDC is not supported for ZTNA
• Bundling Cortex XDR would be advantageous for customers
Leader in
LEADERSHIP COMPASS: 81112
SASE Integration Suites
66
© 2023 KUPPINGERCOLE ANALYSTS AG 66
LEADERSHIP COMPASS: 81112
SASE Integration Suites
67
© 2023 KUPPINGERCOLE ANALYSTS AG 67
Versa Networks – SASE
San Jose, CA based Versa Networks was launched in 2012. Versa is a SASE specialist. In
terms of SASE components, Versa has SD-WAN, SWG, NGFW, ZTNA, DLP, CASB, Unified
Threat Management (UTM) and Remote Browser Isolation. Gateways can be delivered as
physical or virtual appliances (VNF). The enterprise management console can be hosted by
customers and Versa has SaaS-hosted options available. Versa also offers full SOC-as-a-
Service. Pricing is based on numbers of users and deployed gateways. Versa has multiple
NOCs and more than 90 PoPs worldwide and can add PoPs on demand for customer
coverage and capacity needs.
Customers can use their existing ISPs with the Versa SD-WAN overlay. Versa employs a
complete range of traffic acceleration techniques. Versa SWG can be deployed on-prem or in
IaaS, and they operate it as SaaS. Versa leverages multiple tunnels per endpoint, resulting in
a mesh-like network architecture for all nodes which provides automatic failover and
improved connectivity and performance. The SWG does URL filtering, malware detection
and sandboxing. Customers can provide their own certificates for decryption and can
manage their own web access control polices. The firewall does DNS filtering, Deep Packet
Inspection, application-aware routing, network/application segmentation, anti-malware
scanning, and intrusion prevention.
Versa has agents for Windows 7-11, Windows Server 2016+, all major Linux types, MacOS
10+, iOS, Chromebook, and Android. Reverse proxies and PAC files enable agentless
access. IPsec, SSH, and TLS 1.2/1.3 are supported. Versa does not have built-in EPDR
functions, but it does scan for malware at its cloud ingress/egress points, and it integrates
with 3rd-party endpoint security solutions to gather information for device posture checks.
Versa also has connectors for Citrix and Microsoft Endpoint Manager UEM platforms.
For ZTNA, Versa is an identity relying party, and can work with any OIDC or SAML issuing
IdP. Kerberos, RADIUS, and SAML can also be used. Authentication policies are therefore
constrained by customers’ IdPs. SaaS app connectors are available. Versa does UBA,
leveraging ML-powered detection models: Versa’s UBA supports geo-fencing, new device
detection, auto-logout of SaaS during suspicious events, and many other access control
features. Versa’s Identity Engine can facilitate on-premises IAM to IDaaS migrations.
For DLP and CASB, Versa does data discovery and classification. It understands the most
common file types and interoperates with Microsoft AIP. All expected enforcement actions
are available within policies. Advanced functions include the ability to redact sensitive
portions of files, encrypt sensitive files, and adding/removing an AIP labels. The CASB
component can detect cloud resource usage. Their CASB can prevent unauthorized data
disclosure in modern messaging and collaboration solutions such as Slack and Microsoft
Teams. Their DLP/CASB supports policy-based encryption and user/group entitlement,
RBAC, and ABAC methodologies. Versa can distinguish work vs. personal accounts in some
SaaS apps and enforce controls appropriately.
Versa offers Remote Browser Isolation using DOM rewrite methods. Customers can create
complex policies as needed leveraging multiple user, device, and environmental attributes.
This can protect client email only if viewed in web email interfaces.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
68
© 2023 KUPPINGERCOLE ANALYSTS AG 68
Versa utilizes multiple CTI sources. CEF and syslog support enable log transfers to SIEMs;
REST and Webhooks are also supported for application integration. For incident response,
Versa alerts customers over email, SMS, and SNMP. The expected range of remedial
actions is available: session termination, traffic blocking by IP or port, node isolation, etc.
Versa has a connector for ServiceNow ITSM; and integrations for Elastic, LogRhythm, Palo
Alto XSOAR, Securonix, and ServiceNow SOAR platforms. Versa Concerto is the single-
entry point for managing all SASE functions. The console is well-designed and intuitive for
customer admins to set policies, get status, and start investigations if needed. Technical
support for both customer admins and end users is available over phone, email, and web
channels, with no limits on case numbers.
Versa Networks is ISO 27001 and PCI-DSS v3 certified. Versa Networks’ solution covers all
major functions of SASE. More connectors for 3rd-party ITSM platforms would be useful for
some customers. Versa has multiple strengths in SASE: SD-WAN connectivity,
authentication context examination, broad OS support, and DLP/CASB being some of the
most noteworthy. Any organization looking for the full range of SASE features should have
Versa on their shortlist for RFP evaluation.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
69
© 2023 KUPPINGERCOLE ANALYSTS AG 69
Security Strong Positive
Functionality Strong Positive
Deployment Positive
Interoperability Strong Positive
Usability Strong Positive
Strengths
• Full array of traffic acceleration techniques
• Multiple tunnels connect each endpoint
• Agents for a wide range of OSes
• High-speed gateways
• Interoperability with 3rd-party UEM tools
• Sophisticated ML-based UBA and DPC for lowering authentication risks
• Excellent DLP and CASB features
• RBAC and ABAC for granular authorization
• More performant Remote Browser Isolation technique used, which can be selectively
applied by policies
• SIEM and SOAR interoperability
Challenges
• No network partnerships but customers use their own ISPs
• RBI does not quarantine email clients
• More ITSM connectors would be beneficial for some customers
Leader in
LEADERSHIP COMPASS: 81112
SASE Integration Suites
70
© 2023 KUPPINGERCOLE ANALYSTS AG 70
LEADERSHIP COMPASS: 81112
SASE Integration Suites
71
© 2023 KUPPINGERCOLE ANALYSTS AG 71
Vendors to Watch
Besides the vendors covered in detail in this document, we observe some other vendors in
the market that readers should be aware of. These vendors may not fully fit the market
definition but offer a significant contribution to the market space. This may be for their
supportive capabilities to the solutions reviewed in this document, for their unique methods of
addressing the challenges of this segment or may be a fast-growing startup that may be a
strong competitor in the future. Other companies listed here are considered SASE vendors
but did not participate in this report.
• Fortinet – Fortinet is a global security company serving organizations both large and
small. They have a SASE offering, along with their own SD-WAN, NOC management.
Other security products include NGFW, IPS, Zero Trust Network Access, IAM, WAF,
Cloud Workload Protection and Cloud Security Posture Management, CASB,
EDR/NDR, Distributed Deception Platforms, SIEM, SOAR, sandbox and threat intel
services, and email security. Fortinet was unable to participate in this report.
• Juniper Networks – Juniper is a network and cloud security stack vendor,
headquartered in Sunnyvale. Their SASE offering includes SD-WAN, Security
Director (policy creation and management), Secure Edge (FWaaS, SWG, DLP/CASB,
and malware prevention/detection), and SmartSession Router. In addition to SASE,
Juniper offers a wide range of networking hardware and software for customer data
centers, including enterprises, telcos, MNOs, and cloud service providers. Juniper
was unable to participate in this report.
• Perimeter 81 - Perimeter 81 was launched in 2018 and is headquartered in Tel Aviv.
Perimeter 81 is a network security specialist. For SASE, their services include SWG,
NGFW, and ZTNA. They emphasize Software Defined Perimeters (SDP) as a modern
alternative to VPN. More than 40 PoPs are available, with most in the US and EU.
Perimeter 81 offers some innovative components of SASE, and they are actively
adding features. They provide extended support for both customer administrators and
end users. KuppingerCole will track Perimeter 81 and include them in future reports.
• Systancia – Systancia was founded in 1998 and originally focused on technologies
such as virtual desktops. They are headquartered in France. In terms of SASE
functionality, Systancia offers UEM, ZTNA with passive biometric authentication,
AI/ML enhanced detection models for UBA, and innovative VDI-based Remote
Browser Isolation; EPDR and firewall services are available through a technical
partnership. Systancia was a Product Leader in the Leadership Compass on Zero
Trust Network Access.
• VMware (Broadcom) – VMware is an international cloud computing, virtualization,
development tool, container application lifecycle, container operational management,
container and endpoint security and software defined network, load balancer and API
ingress vendor headquartered in Palo Alto, California. Founded in 1998, the company
was an early pioneer in hardware virtualization technology. VMware offers a broad
portfolio of security tools, including products for both running and securing cloud
workloads. VMware has SASE solutions that include both site connectivity and WFA
capabilities. VMware was acquired by Broadcom in May 2022. VMware was not able
to participate in this report.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
72
© 2023 KUPPINGERCOLE ANALYSTS AG 72
• Zscaler – Zscaler is a global information security company that provides an
integrated cloud-based platform for Internet security, compliance, advanced threat
protection, and other information security services. Founded in 2008, the company is
headquartered in San Jose, California. Zscaler offers full SASE services but was not
able to participate in this report.
Methodology
KuppingerCole Leadership Compass is a tool which provides an overview of a particular IT
market segment and identifies the leaders within that market segment. It is the compass
which assists you in identifying the vendors and products/services in that market which you
should consider for product decisions. It should be noted that it is inadequate to pick vendors
based only on the information provided within this report.
Customers must always define their specific requirements and analyze in greater detail what
they need. This report doesn’t provide any recommendations for picking a vendor for a
specific customer scenario. This can be done only based on a more thorough and
comprehensive analysis of customer requirements and a more detailed mapping of these
requirements to product features, i.e., a complete assessment.
Types of Leadership
We look at four types of leaders:
• Product Leaders: Product Leaders identify the leading-edge products in the particular
market. These products deliver most of the capabilities we expect from products in
that market segment. They are mature.
• Market Leaders: Market Leaders are vendors which have a large, global customer
base and a strong partner network to support their customers. A lack in global
presence or breadth of partners can prevent a vendor from becoming a Market
Leader.
• Innovation Leaders: Innovation Leaders are those vendors which are driving
innovation in the market segment. They provide several of the most innovative and
upcoming features we hope to see in the market segment.
• Overall Leaders: Overall Leaders are identified based on a combined rating, looking
at the strength of products, the market presence, and the innovation of vendors.
Overall Leaders might have slight weaknesses in some areas, but they become
Overall Leaders by being above average in all areas.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
73
© 2023 KUPPINGERCOLE ANALYSTS AG 73
For every area, we distinguish between three levels of products:
• Leaders: This identifies the Leaders as defined above. Leaders are products which
are exceptionally strong in certain areas.
• Challengers: This level identifies products which are not yet Leaders but have specific
strengths which might make them Leaders. Typically, these products are also mature
and might be leading-edge when looking at specific use cases and customer
requirements.
• Followers: This group contains vendors whose products lag in some areas, such as
having a limited feature set or only a regional presence. The best of these products
might have specific strengths, making them a good or even best choice for specific
use cases and customer requirements but are of limited value in other situations.
Our rating is based on a broad range of input and long experience in that market segment.
Input consists of experience from KuppingerCole advisory projects, feedback from customers
using the products, product documentation, and a questionnaire sent out before creating the
KuppingerCole Leadership Compass, and other sources.
Product rating
KuppingerCole Analysts AG as an analyst company regularly evaluates products/services
and vendors. The results are, among other types of publications and services, published in
the KuppingerCole Leadership Compass Reports, KuppingerCole Executive Views,
KuppingerCole Product Reports, and KuppingerCole Vendor Reports. KuppingerCole uses a
standardized rating to provide a quick overview on our perception of the products or vendors.
Providing a quick overview of the KuppingerCole rating of products requires an approach
combining clarity, accuracy, and completeness of information at a glance.
KuppingerCole uses the following categories to rate products:
• Security
• Functionality
• Deployment
• Interoperability
• Usability
Security is a measure of the degree of security within the product / service. This is a key
requirement and evidence of a well-defined approach to internal security as well as
capabilities to enable its secure use by the customer are key factors we look for. The rating
includes our assessment of security vulnerabilities and the way the vendor deals with them.
Functionality is a measure of three factors: what the vendor promises to deliver, the state of
the art and what KuppingerCole expects vendors to deliver to meet customer requirements.
To score well there must be evidence that the product / service delivers on all of these.
Deployment is measured by how easy or difficult it is to deploy and operate the product or
service. This considers the degree in which the vendor has integrated the relevant individual
LEADERSHIP COMPASS: 81112
SASE Integration Suites
74
© 2023 KUPPINGERCOLE ANALYSTS AG 74
technologies or products. It also looks at what is needed to deploy, operate, manage, and
discontinue the product / service.
Interoperability refers to the ability of the product / service to work with other vendors’
products, standards, or technologies. It considers the extent to which the product / service
supports industry standards as well as widely deployed technologies. We also expect the
product to support programmatic access through a well-documented and secure set of APIs.
Usability is a measure of how easy the product / service is to use and to administer. We
look for user interfaces that are logically and intuitive as well as a high degree of consistency
across user interfaces across the different products / services from the vendor.
We focus on security, functionality, ease of delivery, interoperability, and usability for the
following key reasons:
• Increased People Participation—Human participation in systems at any level is the
highest area of cost and the highest potential for failure of IT projects.
• Lack of excellence in Security, Functionality, Ease of Delivery, Interoperability, and
Usability results in the need for increased human participation in the deployment and
maintenance of IT services.
• Increased need for manual intervention and lack of Security, Functionality, Ease of
Delivery, Interoperability, and Usability not only significantly increase costs, but
inevitably lead to mistakes that can create opportunities for attack to succeed and
services to fail.
KuppingerCole’s evaluation of products / services from a given vendor considers the degree
of product Security, Functionality, Ease of Delivery, Interoperability, and Usability which to be
of the highest importance. This is because lack of excellence in any of these areas can result
in weak, costly, and ineffective IT infrastructure.
Vendor rating
We also rate vendors on the following characteristics
• Innovativeness
• Market position
• Financial strength
• Ecosystem
Innovativeness is measured as the capability to add technical capabilities in a direction
which aligns with the KuppingerCole understanding of the market segment(s). Innovation has
no value by itself but needs to provide clear benefits to the customer. However, being
innovative is an important factor for trust in vendors because innovative vendors are more
likely to remain leading-edge. Vendors must support technical standardization initiatives.
Driving innovation without standardization frequently leads to lock-in scenarios. Thus, active
participation in standardization initiatives adds to the positive rating of innovativeness.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
75
© 2023 KUPPINGERCOLE ANALYSTS AG 75
Market position measures the position the vendor has in the market or the relevant market
segments. This is an average rating over all markets in which a vendor is active. Therefore,
being weak in one segment doesn’t lead to a very low overall rating. This factor considers the
vendor’s presence in major markets.
Financial strength even while KuppingerCole doesn’t consider size to be a value by itself,
financial strength is an important factor for customers when making decisions. In general,
publicly available financial information is an important factor therein. Companies which are
venture-financed are in general more likely to either fold or become an acquisition target,
which present risks to customers considering implementing their products.
Ecosystem is a measure of the support network vendors have in terms of resellers, system
integrators, and knowledgeable consultants. It focuses mainly on the partner base of a
vendor and the approach the vendor takes to act as a “good citizen” in heterogeneous IT
environments.
Again, please note that in KuppingerCole Leadership Compass documents, most of these
ratings apply to the specific product and market segment covered in the analysis, not to the
overall rating of the vendor.
Rating scale for products and vendors
For vendors and product feature areas, we use a separate rating with five different levels,
beyond the Leadership rating in the various categories. These levels are
Strong positive Outstanding support for the subject area, e.g., product functionality, or
outstanding position of the company for financial stability.
Positive Strong support for a feature area or strong position of the company, but
with some minor gaps or shortcomings. Using Security as an example, this
can indicate some gaps in fine-grained access controls of administrative
entitlements. For market reach, it can indicate the global reach of a partner
network, but a rather small number of partners.
Neutral Acceptable support for feature areas or acceptable position of the
company, but with several requirements we set for these areas not being
met. Using functionality as an example, this can indicate that some of the
major feature areas we are looking for aren’t met, while others are well
served. For Market Position, it could indicate a regional-only presence.
Weak Below-average capabilities in the product ratings or significant challenges
in the company ratings, such as very small partner ecosystem.
Critical Major weaknesses in various areas. This rating most commonly applies to
company ratings for market position or financial strength, indicating that
vendors are very small and have a very low number of customers.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
76
© 2023 KUPPINGERCOLE ANALYSTS AG 76
Inclusion and exclusion of vendors
KuppingerCole tries to include all vendors within a specific market segment in their
Leadership Compass documents. The scope of the document is global coverage, including
vendors which are only active in regional markets such as Germany, Israel, or the US.
However, there might be vendors which don’t appear in a Leadership Compass document
due to various reasons:
• Limited market visibility: There might be vendors and products which are not on our
radar yet, despite our continuous market research and work with advisory customers.
This usually is a clear indicator of a lack in Market Leadership.
• Declined to participate: Vendors might decide to not participate in our evaluation and
refuse to become part of the Leadership Compass document. KuppingerCole tends to
include their products anyway if sufficient information for evaluation is available, thus
providing a comprehensive overview of leaders in the market segment.
• Lack of information supply: Products of vendors which don’t provide the information
we have requested for the Leadership Compass document will not appear in the
document unless we have access to sufficient information from other sources.
• Borderline classification: Some products might have only small overlap with the
market segment we are analyzing. In these cases, we might decide not to include the
product in that KuppingerCole Leadership Compass.
The target is providing a comprehensive view of the products in a market segment.
KuppingerCole will provide regular updates on their Leadership Compass documents.
We provide a quick overview about vendors not covered and their offerings in chapter
Vendors to Watch. In that chapter, we also look at some other interesting offerings around
the market and in related market segments.
LEADERSHIP COMPASS: 81112
SASE Integration Suites
77
© 2023 KUPPINGERCOLE ANALYSTS AG 77
Related Research
Leadership Compass Endpoint Protection Detection & ResponseLeadership Compass
Network Detection & ResponseLeadership Compass Zero Trust Network Access
Leadership Compass Unified Endpoint Management
Market Compass Cloud Delivered Security
Advisory Note Implementing SASE
Whitepaper Security Operations in the Age of Zero Trust
Whitepaper The Role of Identity for Zero Trust
Copyright
©2023 KuppingerCole Analysts AG all rights reserved. Reproduction and distribution of this publication in any form is forbidden
unless prior written permission. All conclusions, recommendations and predictions in this document represent KuppingerCole´s
initial view. Through gathering more information and performing deep analysis, positions presented in this document will be
subject to refinements or even major changes. KuppingerCole disclaim all warranties as to the completeness, accuracy and/or
adequacy of this information. Even if KuppingerCole research documents may discuss legal issues related to information
security and technology, KuppingerCole do not provide any legal services or advice and its publications shall not be used as
such. KuppingerCole shall have no liability for errors or inadequacies in the information contained in this document. Any opinion
expressed may be subject to change without notice. All product and company names are trademarks or registered® trademarks
of their respective holders. Use of them does not imply any affiliation with or endorsement by them.
KuppingerCole Analysts support IT professionals with outstanding expertise in defining IT strategies and in relevant decision-
making processes. As a leading analyst company, KuppingerCole provides first-hand vendor-neutral information. Our services
allow you to feel comfortable and secure in taking decisions essential to your business.
KuppingerCole, founded in 2004, is a global, independent analyst organization headquartered in Europe. We specialize in
providing vendor-neutral advice, expertise, thought leadership, and practical relevance in Cybersecurity, Digital Identity & IAM
(Identity and Access Management), Cloud Risk and Security, and Artificial Intelligence, as well as for all technologies fostering
Digital Transformation. We support companies, corporate users, integrators, and software manufacturers in meeting both
tactical and strategic challenges and make better decisions for the success of their business. Maintaining a balance between
immediate implementation and long-term viability is at the heart of our philosophy.
For further information, please contact clients@kuppingercole.com.
Contents Figures Introduction / Executive Summary Highlights Market Segment Delivery Models Required Capabilities Optional Capabilities
Leadership Overall Leadership Product Leadership Innovation Leadership Market Leadership
Correlated View The Market/Product Matrix The Product/Innovation Matrix The Innovation/Market Matrix
Products and Vendors at a Glance Product/Vendor evaluation Aryaka Networks – SASE, SD-WAN Services Cato Networks – SASE Cloud Check Point – Harmony Connect Cisco – Secure Connect Cloudflare – Cloudflare One Ericom – ZTEdge Cloud Security Platform Lookout – SWG, CASB, and ZTNA Open Systems – SASE + Palo Alto Networks – SASE, Prisma Access, and Prisma SD-WAN Versa Networks – SASE
Vendors to Watch Methodology Types of Leadership Product rating Vendor rating Rating scale for products and vendors Inclusion and exclusion of vendors