Report | KuppingerCole Leadership Compass for SASE Integrated Suites, 2023

Report | KuppingerCole Leadership Compass for SASE Integrated Suites, 2023

This report examines how SASE solutions consolidate SD-WAN, Secure Web Gateways, and Zero Trust architecture to enhance security and simplify network management. As remote work and cloud adoption grow, SASE offers scalable, cost-effective solutions to secure connectivity and protect organizational resources. Download the report to learn more about optimizing your security strategy with SASE.

Report | KuppingerCole Leadership Compass for SASE Integrated Suites, 2023

SASE Integration Suites John Tolbert 6 February 2023

LEADERSHIP COMPASS: 81112

SASE Integration Suites

2

© 2023 KUPPINGERCOLE ANALYSTS AG 2

This report provides an overview of the market for Secure Access Service Edge (SASE)

Integration Suites. In this Leadership Compass, we examine the market segment, vendor

service functionality, relative market share, and innovative approaches to providing SASE

Integration solutions.

Contents

Contents .................................................................................................................................... 2

Figures ....................................................................................................................................... 3

Introduction / Executive Summary ............................................................................................ 4

Highlights ............................................................................................................................... 7

Market Segment .................................................................................................................... 8

Delivery Models ..................................................................................................................... 9

Required Capabilities .......................................................................................................... 10

Optional Capabilities ............................................................................................................ 12

Leadership ............................................................................................................................... 13

Overall Leadership .............................................................................................................. 13

Product Leadership ............................................................................................................. 14

Innovation Leadership ......................................................................................................... 16

Market Leadership ............................................................................................................... 18

Correlated View ....................................................................................................................... 20

The Market/Product Matrix .................................................................................................. 21

The Product/Innovation Matrix ............................................................................................ 23

The Innovation/Market Matrix .............................................................................................. 25

Products and Vendors at a Glance ......................................................................................... 26

Product/Vendor evaluation ...................................................................................................... 30

Aryaka Networks – SASE, SD-WAN Services .................................................................... 32

Cato Networks – SASE Cloud ............................................................................................. 35

Check Point – Harmony Connect ........................................................................................ 39

Cisco – Secure Connect ...................................................................................................... 43

Cloudflare – Cloudflare One ................................................................................................ 47

Ericom – ZTEdge Cloud Security Platform ......................................................................... 51

Lookout – SWG, CASB, and ZTNA ..................................................................................... 55

Open Systems – SASE + .................................................................................................... 59

Palo Alto Networks – SASE, Prisma Access, and Prisma SD-WAN .................................. 63

Versa Networks – SASE...................................................................................................... 67

LEADERSHIP COMPASS: 81112

SASE Integration Suites

3

© 2023 KUPPINGERCOLE ANALYSTS AG 3

Vendors to Watch .................................................................................................................... 71

Methodology ............................................................................................................................ 72

Types of Leadership ............................................................................................................ 72

Product rating ...................................................................................................................... 73

Vendor rating ....................................................................................................................... 74

Rating scale for products and vendors................................................................................ 75

Inclusion and exclusion of vendors ..................................................................................... 76

Figures

Figure 1: Overview of SASE Functions .................................................................................... 7

Figure 2: The Overall Leaders in Leadership Compass SASE Integration Suites ................ 13

Figure 3: The Product Leaders in Leadership Compass SASE Integration Suites ............... 14

Figure 4: The Innovation Leaders in Leadership Compass SASE Integration Suites ........... 16

Figure 5: The Market Leaders in Leadership Compass SASE Integration Suites ................. 18

Figure 6: The Market/Product Matrix for Leadership Compass SASE Integration Suites ..... 21

Figure 7: The Product/Innovation Matrix for Leadership Compass SASE Integration Suites 23

Figure 8: The Innovation/Market Matrix for Leadership Compass SASE Integration Suites . 25

LEADERSHIP COMPASS: 81112

SASE Integration Suites

4

© 2023 KUPPINGERCOLE ANALYSTS AG 4

Introduction / Executive Summary

With the rapid expansion of IT environments and adoption of cloud, and the ongoing Digital

Transformation, the need to provide secure access to organizational resources has become

paramount. The number and types of security tools addressing ever-evolving threats that are

in use across a typical organization continues to increase. Managing network connectivity

and security has become more expensive, complex, and time-consuming.

Secure Access Service Edge (SASE) solutions are designed to consolidate network and

security components, simplify management and licensing, and improve usability. SASE is the

union of a number of different networking and security technologies designed to improve

security posture as well as connectivity for remote offices, cloud services, contractors, and

remote employees, while driving down the cost of connectivity.

KuppingerCole defines SASE as the bundling of:

• Software Defined Wide Area Networking (SD-WAN)

• Secure Web Gateways (SWG)

• Remote Browser Isolation (RBI)

• Next Generation Firewalls (NGFW) and/or Firewall as a Service (FWaaS)

• Endpoint agents allowing secure remote access via modernized VPN technologies.

The agents may be bundled with or integrate with third-party products with security

features such as Endpoint Protection Detection & Response (EPDR) and Unified

Endpoint Management (UEM)

• Data Leakage Prevention (DLP) & Cloud Access Security Brokers (CASB)

• Zero Trust as the guiding security architecture incorporating digital identity

components such as digital identity storage, identity federation, Multi-Factor

Authentication (MFA), User Behavioral Analysis (UBA), and Role- and/or Attribute-

Based Access Controls (RBAC and ABAC respectively).

Therefore, we see that SASE is not a brand-new technology but is instead an innovative

packaging of security and networking solutions that can be better positioned to solve

contemporary and evolving business requirements. The technologies involved encompass

endpoints and both on-premises and cloud resident infrastructure and applications. SASE

Integration Suites must be capable of supporting hybrid environments. Moreover, most

organizations operate in and are further pursuing multi-cloud architectures.

Secure Access implies strong, multi-factor authentication and authorization for remote users

and devices, threat detection and protection, and fine-grained access controls. Work From

Home (WFH) and other drivers for remote work have been supported by VPNs for more than

two decades. The Covid pandemic necessitated WFH en masse, and the technologies that

remote work relies upon have proven to be highly effective. However, in many cases, the

performance of traditional VPNs has been strained. Scalability has been insufficient.

Managing network segmentation in conjunction with VPN access has become exceedingly

difficult in large enterprises. Organizations that allowed username/password authentication to

VPNs have become more aware of the significant risks of weak authentication and have

LEADERSHIP COMPASS: 81112

SASE Integration Suites

5

© 2023 KUPPINGERCOLE ANALYSTS AG 5

moved to require MFA. The deployment of MFA has increased complexity, thereby making

VPNs more difficult to manage.

Many organizations accept that Work from Anywhere (WFA) will be the norm going forward.

The need for Secure Access is greater than ever, with fraud, ransomware, and corporate

espionage on the rise. Remote worker access, including employees and contractors, needs

to be properly secured with strong authentication services and granular access controls.

Moreover, assurances that end user devices are not compromised must be part of the

Secure Access equation. Remote workers and contractors now do much of their work in the

cloud as well as by accessing resources in corporate data centers.

Prior to the pandemic, many kinds of organizations were experiencing tectonic shifts in

application and user distributions. The move to the cloud for applications and storage had

been gaining pace for the previous decade. Covid accelerated the migration to cloud

services. Protecting sensitive resources of an increasingly distributed enterprise with a large

mobile workforce is becoming a challenge that siloed security tools are not able to address

effectively. In addition to the growing number of potential threat vectors, the very scope of

corporate cybersecurity has grown immensely in recent years. SASE was postulated as a

means to connect distributed users more efficiently and securely with distributed

applications.

Organizations with a focus on IT security have been making users authenticate strongly for

years and have brought remote worker and branch office traffic back to the enterprise data

center(s) for security analysis. However, organizations with legacy VPN architectures found

that remote workers, offices, and contractors sometimes exercised options that decreased

overall security when encountering underperforming, backhauled connections. Some chose

to implement split-tunneling, allowing direct-to-cloud access for SaaS while routing internal

application traffic to data centers. In other cases, users disconnected themselves from slow

VPNs in order to go cloud-direct. In both of those scenarios, enterprises may lose the ability

to apply network, application, and data security policies. Older style, isolated VPN technology

will likely be replaced by contemporary, integrated SASE VPN solutions in the medium term.

Another problem that SASE’s updated approach to VPN addresses is automated routing and

failover between nodes. Early generation VPNs required user intervention to switch between

servers, which could often result in poor network performance as perceived by the user.

Moreover, advancements in cryptography and tunneling protocols such as WireGuard as

realized in some SASE solutions will provide security and routing benefits.

The Secure Service Edge part of SASE refers to the need for security where users and

networks intersect. Examples include LAN to LAN, data center to data center, branch office

to corporate, franchises to headquarters, remote production centers to HQ, sensors to

municipalities, on-premises to cloud, and remote users connecting to all scenarios above.

Security for these use cases tends to be more focused on device level assurance of integrity,

authentication, and authorization, supported by policies based on certificate authentication,

challenge-response, and allow- and deny-lists. In this scenario, NGFWs or FWaaS can

provide network and transport layer security, and CASB and SWG solutions provide the

session and application layer access controls and data object security. RBI acts as an

application layer web proxy that mediates users’ web requests, sandboxes suspicious

LEADERSHIP COMPASS: 81112

SASE Integration Suites

6

© 2023 KUPPINGERCOLE ANALYSTS AG 6

content, and renders web and application content safely, transmitting a view of the content

back to the user rather than the content itself.

SD-WAN technology was developed to enable businesses to use readily available high

speed internet connections rather than point-to-point private network services such as T1

lines, Frame Relay systems, or Multi-Protocol Labeling Switches (MPLS), or VPN mesh

architectures such as Dynamic MultiPoint VPN (DMVPN). Private networking solutions have

been reliable and reasonably secure for most customers, but expensive. These private

networking solutions are mainly delivered by telcos. In many cities around the world, it is now

possible for organizations to provision high speed internet connections (between 100 Mbps

to 1+ Gbps) from not only telcos, but also cable providers and other internet service

providers, often at a significant discount compared to point-to-point solutions. Mobile Network

Operators (MNOs) offer high-speed 4G LTE and 5G across many regions as well. SD-WAN

has also improved network and application performance by getting remote users and remote

offices closer to SaaS applications and enterprise services implemented at the edge

(services and entry points installed in high-bandwidth co-location facilities or by Content

Delivery Networks [CDNs]).

SD-WAN, SASE, and CDNs vendors use a variety of techniques to “accelerate” TCP

connections from the perspective of end users. Many point-to-point connections, including

those from remote workers, have unused capacity. The design of the transport protocol itself

can be the source of those kinds of bottlenecks. TCP, as implemented in OSes, will ramp up

the volume of data transmission until clients begin experiencing latency, packet loss, jitter,

etc. Then networking drivers and OSes will cut the data volumes (window size) in half, and

start trying to increase it again, but linearly.

A leading TCP optimization method involves the use of transparent TCP proxies. TCP

proxies sit between clients and target resources and buffer 2-3 TCP sequences ahead per

connection. This enables clients to receive data faster, and in the event of packet loss, retries

go to the proxy, which is in between and has stored up the next few rounds of data to

transfer. This method decreases the time that end users typically experience for large

downloads, uploads, and streaming. TCP optimization is particularly useful at the “edge,” at

Points of Presence that may be physically far from data centers and cloud resources.

Other TCP optimization methods involve changes to TCP flows, including Selective ACKs to

mitigate duplicate transmissions, using larger initial window sizes, and Bottleneck Bandwidth

testing to determine the optimal rates per connection.

The drawback for SD-WAN is that there is no explicit security beyond transport layer

encryption: meaning that point-to-point connection authentication and access controls, user

session authentication and authorization, and application authentication and access controls

are not addressed.

Since SD-WAN emerged, a number of security tool types have been extended to cover

shortcomings in the underlying model. SWGs are proxies used to consolidate and control

user and app web utilization. Endpoint Security tools discover and prevent exploitation of

vulnerabilities and execution of malware, provide application controls, and URL/content

filtering. NGFWs are application- and (in some cases) identity-aware firewalls. FWaaS are

LEADERSHIP COMPASS: 81112

SASE Integration Suites

7

© 2023 KUPPINGERCOLE ANALYSTS AG 7

cloud-hosted NGFWs. CASBs enable shadow IT discovery, Network Access Control (NAC)

points, and Data Leakage Prevention (DLP) Policy Enforcement Points (PEPs) for cloud-

hosted resources. Security stack vendors began packaging these as solutions to help

customers deal with the increasing complexity and risks of SD-WAN.

Zero Trust has arisen over the past decade and has become a primary means of addressing

access control use cases. Given the focus on the networking aspect, it is usually abbreviated

as ZTNA (Zero Trust Network Access). Often expressed as "Never trust, always verify",

ZTNA is an embodiment of the principle of least privilege, and at its core mandates that

every access request be properly authenticated and authorized. Thus, IAM (Identity and

Access Management) is a foundational element for ZTNA. Proper access management in

service of ZTNA means considering the requesting user's attributes, authentication and

environmental context, permissions and roles, source device information, and the requested

resource attributes. Zero Trust Architecture implies a concept where clients can access

services from everywhere, not relying only on internal network security mechanisms. In fact,

ZTNA has become the strategic IT security paradigm for many services and products.

Therefore, ZTNA is well-suited to help mitigate the shortcomings of SD-WAN and provide the

security structure for SASE.

SASE Integration Suites bring the power, flexibility, and costs saving potential of SD-WAN

together with security posture enhancements afforded by integrating CASB, Endpoint

Security, DLP, NGFW, SWG, RBI, and IAM in a Zero Trust Architecture. SASE, like Zero

Trust itself, embodies a wide range of functions that are often instantiated in multiple

products. Most enterprises, government agencies, non-profits, and small businesses already

have a plethora of security and networking solutions in place. SASE Integration Suites offer

the advantage of centralizing administrative control over these disparate technologies. SASE

Integration Suites must interoperate with tools in each security and identity domain to provide

comprehensive coverage and management for all requisite functions.

Figure 1: Overview of SASE Functions

LEADERSHIP COMPASS: 81112

SASE Integration Suites

8

© 2023 KUPPINGERCOLE ANALYSTS AG 8

Highlights

• The primary use cases for SASE are improving connectivity and security between

remote workers, contractors, data centers, branch offices and other distributed

facilities, and cloud-hosted resources.

• The rapid move to “Work from Anywhere” has caused performance problems in prior

generation VPN and site-to-site connections and has increased the size of many

organizations’ attack surfaces. SASE is gaining prominence as a concept and

solution architecture to address these and other issues.

• SASE is often defined within the IT security market as SD-WAN plus security. SD-

WAN enables the use of lower cost connections between users, sites, and cloud

resources. However, SD-WAN lacks security features beyond transport encryption.

• The SASE market is still emerging and evolving. The foundational features we

believe are necessary for SASE Integration Suites include SD-WAN (including VPN

for endpoints), firewall, Secure Web Gateway, Zero Trust Network Access, Remote

Browser Isolation, Data Protection (Data Leakage Protection and Cloud Access

Security Brokers), and Customer Support and Experience Management.

• The inclusion of endpoint security and management, such as the bundling of

Endpoint Protection Detection & Response (EPDR) and Unified Endpoint

Management (UEM) with SASE agents, is a desired goal of customers in order to

reduce the number of software agents deployed and complexity of enterprise IT

security and asset management. Such features are not built-in to SASE agents yet,

even amongst vendors who also have EPDR and UEM products.

• Not many of the vendors surveyed offer a complete range of SASE functions as

defined herein within their suites today. Some vendors’ SASE Integration Suites offer

these functions as add-ons from their own product/service portfolios, whereas others

partner with 3rd-party vendors, and other vendors leave it up to the customer to

acquire such functionality as needed. Some vendors whose SASE offerings are

currently incomplete have these additional features on their roadmap. This will be

indicated in the vendor analyses below, if known.

• The Overall Leaders in the Leadership Compass for SASE Integration Suites are

Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and Versa Networks.

• The Product Leaders in the Leadership Compass for SASE Integration Suites are

Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and Versa Networks.

• The Market Leaders in the Leadership Compass for SASE Integration Suites are

Cato Networks, Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and

Versa Networks.

• The Innovation Leaders in the Leadership Compass for SASE Integration Suites are

Cisco, Lookout, Palo Alto Networks, and Versa Networks.

Market Segment

Since SASE is not a revolutionary technology, traditional network and network security

vendors have been able to package and brand their products and services under the SASE

rubric. Several large vendors in the space had products and services that individually

addressed the technical functions and use cases defined for SASE, and it has been fairly

LEADERSHIP COMPASS: 81112

SASE Integration Suites

9

© 2023 KUPPINGERCOLE ANALYSTS AG 9

easy to group what they have available as a unified SASE offering. Other vendors offer

multiple products available under different SKUs but provide discounted packages that meet

the definition of SASE. Some of the innovation in this market involves evolving licensing and

subscription models to meet customer demand. The SASE market does have some smaller

players that initially offered a subset of the required functionality but have been moving to

add the full feature set that is typically associated with SASE.

Most vendors in this initial Leadership Compass on SASE Integration Suites do not currently

offer all features outlined herein as built-in capabilities. Instead, the larger vendors provide a

base set of SASE functions and offer as add-ons other products across their portfolios. Some

of the SASE specialist vendors take the approach of partnering with other vendors or

providing integration with multiple 3rd-party products. This is most commonly the case for

EPDR. UEM is also not a core component in SASE Integration Suites, but many SASE

services reviewed here do collect device information for risk-adaptive authentication, and

some have integrations with major UEM platforms.

Delivery Models

All solutions in this space have both on-premises and cloud components. Users’ endpoints

need agents that provide upgraded VPN capabilities, plus endpoint security functions

including anti-malware, detection & response, endpoint management, and DLP. Agents are

available for Windows desktops and servers, Macs, and Linux machines.

Most SASE solutions have gateways that facilitate site-to-site and site-to-cloud connectivity.

Gateways are usually delivered as physical or virtual appliances for easier installation. In

many cases, vendor services handle the dynamic selection of the most efficient routing from

between gateways, data centers, and cloud-hosted resources. In addition to laying the

foundation for SD-WAN, gateways can provide host- or site-based firewall services, secure

web gateway functions, and network threat detection and response capabilities.

PoPs, or Points of Presence, are locations where the SASE vendors have equipment and/or

facilities (SASE vendor equipment is sometimes co-located in other service provider facilities,

such as Telcos, MNOs, and cloud IaaS providers). PoPs are where SASE customer traffic

enters and exits their network/cloud. PoPs are where SASE vendors deploy cloud-based

security functions, such as FWaaS, SWG, RBI, CASB, etc. Most global SASE vendors

operate multiple PoPs per continent. Some have multiple PoPs per major metropolitan area.

Network performance inside the SASE cloud/backbone should be sufficient for most

customers, but one of the main considerations is latency between customer sites and remote

users to the PoPs. From a prospective customer standpoint, it is important to know where

SASE PoPs are located so that one can evaluate the vendor(s) with the most suitable PoP

locations and architecture. Another consideration is the number of and locations of vendors’

Network Operations Centers (NOCs), and the round-the-clock support models they offer.

Other SASE features are cloud-native, generally including secure web gateways, cloud

access controls, firewall services, Remote Browser Isolation, and management dashboards

and consoles.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

10

© 2023 KUPPINGERCOLE ANALYSTS AG 10

Services from vendors are an important part of SASE Integration Suites. Not only are

services needed for installation, software maintenance, and optimized routing, but most of

the players in the market provide technical support services for both administrative users and

end users as part of a standard contract. Offering direct support to remote workers and

contractors can be a service differentiator among SASE Integration Suites.

Required Capabilities

This Leadership Compass analyzes the main attributes and functions of SASE Integration

Suite solutions, including

• Flexible deployment models covering the most common permutations of distributed

sites, remote workers, contractors, and cloud resources. For on-premises data center

components, high-capacity gateway devices which provide distributed SASE services

(as described below) are advantageous. Solutions should include image files for

IaaS. Lastly, agents for desktop/laptop, server, and mobile operating systems must

be available. The more variety in OSes supported, the better suited a vendor’s

offering will be to organizations that are running multiple, diverse OSes.

• SD-WAN deployment and configuration, automated traffic routing and bandwidth

management. Some vendors do not use the standard overlay approach, rather they

rely upon network service providers. Depending on individual vendors’ approaches,

they may partner with network service providers or leverage customers’ existing ISPs.

• Secure connectivity between nodes, servers, and cloud resources. This essentially

means Virtual Private Network (VPN), although in some quarters that term has fallen

out of fashion. A number of protocols can provide secure connectivity and/or

tunneling (authenticated users and devices with encrypted data transfer) between

points: IPsec, SSH, TLS, and WireGuard. Innovation in this category would include

automated availability and performance testing between nodes with automatic failover

and routing based on the results of those tests; and the use of modern protocols such

as TLS 1.3 and WireGuard.

• Secure Web Gateways for web traffic policy enforcement, URL filtering, malware

detection, and content inspection. SWGs are proxy services that handle a variety of

internet and web traffic, applying policies in conjunction with customers’ IAM and

Network Access Control solutions. CASB functions are often integrated with SWGs.

• Next Generation Firewalls and Firewall-as-a-Service features to protect networks,

offices, data centers, cloud instances, and other resources from Denial of Service

(DoS), DNS, and application layer attacks. NGFW services include packet filtering,

Deep Packet Inspection (DPI), Encrypted Traffic Analysis, application awareness

(including the ability to route and filter based on traffic types), and network

segmentation. NGFWs may perform traffic decryption for security analysis, or in a few

cases, examine encrypted traffic using advanced Network Detection & Response

(NDR) methods such as JA3/JA3S, Mercury, etc. The firewall/NDR components, in

conjunction with Endpoint Protection Detection & Response tools (described below) if

present, usually can take mitigating actions such as process termination, connection

termination, node isolation, blocking of IPs/URLs, and initiating packet capture on

endpoints, gateways, and in the cloud.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

11

© 2023 KUPPINGERCOLE ANALYSTS AG 11

• Support for identity federation for Zero Trust Network Access (ZTNA). A small subset

of SASE vendors offers full Identity and Access Management (IAM) or Identity-as-a-

Service (IDaaS), thus acting as Identity Providers (IdPs) for their customers. Most

SASE solutions are identity relying parties, accepting Open ID Connect (OIDC) and

Security Assertion Markup Language (SAML) assertions for federated authentication

to their resources. In the latter scenario, the choice of authenticators depends on the

customers’ existing IAM or IDaaS. Strong and Multi-Factor Authentication (MFA)

options are recommended for SASE.

• Risk-adaptive and/or continuous authentication features for ZTNA. Although in many

cases SASE customers use identity services outside of the SASE solution, the SASE

Integration Suites can harvest authentication and session data to perform risk-

adaptive and continuous authentication and authorization.

• Remote Browser Isolation to protect end user devices from compromise from

malicious content from web and email. Remote Browser Isolation (RBI) is generally

hosted by SASE vendors in their clouds, allow customers to use the most widely

deployed browsers, with few configuration changes. Acquisition, scanning, and

execution of remote content happens in the vendors’ RBI environments, with inert

results passed to users. Remote Browser Isolation should be able to be applied by

user and resource types. Pixel rendering is an older but slower method for RBI. DOM

rewriting is a newer and faster RBI method. Pixel rendering is theoretically safer for

end users but has high latency. DOM rewriting may miss some malicious content in

web traffic. A few vendors are deploying newer technologies in this area that do not

conform to the models described here. Some SASE Integration Suites rely on 3rd-

party products for RBI functions.

• Data Leakage Prevention (DLP) functions, including data discovery and classification,

and definition and enforcement of security policies on endpoints. DLP systems

typically look for common data types such as Personally Identifiable Information (PII),

credit card numbers, Social Security Numbers, and other government identifiers, etc.

Customers should be able to create their own data types for DLP mechanisms to

enforce. Some SASE Integration Suites rely on 3rd-party products for DLP functions.

Enforcement actions include controlling the abilities to:

o Upload files to sites / attach files to email

o Read data

o Copy content to clipboard

o Download files

o Move or copy files via USB, Bluetooth, or optical drives

o Change file permissions

o Etc.

• Cloud Access Security Broker functions to discover cloud service usage, discover and

classify data, and enforce data security policy compliance in the cloud. In this context,

cloud includes major SaaS services such as Microsoft O365 and Teams, GSuite,

Salesforce, Slack, Concur, ServiceNow, JIRA, etc. Regarding data discovery,

classification, policy definition and enforcement, DLP and CASB should be

functionally similar across vendor solutions. User/group to resource entitlement

management and Role-Based Access Control (RBAC) are the most common access

control paradigms used. The use of Attribute-Based Access Control (ABAC) is

LEADERSHIP COMPASS: 81112

SASE Integration Suites

12

© 2023 KUPPINGERCOLE ANALYSTS AG 12

preferred. Some SASE Integration Suites rely on 3rd-party products for CASB

functions.

• Utilization of Cyber Threat Intelligence (CTI), either from sources internal to the

vendor, or from external subscriptions or open sources. CTI includes lists of known

malicious IPs, URLs, domains, file hashes and metadata, etc.

• Built-in link status, network utilization, security component status, and user

experience dashboards and reports

• SASE Integration Managed Services, allowing customers to offload deployment and

maintenance tasks to the vendor or Managed Service Provider partners

• Support for standards that facilitate interoperability with other components in the

security and IAM architecture. Relevant standards in IAM include FIDO, JWT, OAuth,

OIDC, and SAML. Standards for security are concerned with inter-application

information sharing and include CEF, REST API, SNMP, STIX, syslog, TAXII, etc.

• Certifications and attestations of compliance with applicable security and cloud

hosting programs, such as UK Cyber Essentials, US FedRAMP, ICSA, ISO/IEC

15408, ISO 27001/27018, SSAE SOC 2 Type 2, CSA Star Level, etc.

Optional Capabilities

The following sets of capabilities are not currently required but are considered as innovative

combinations of capabilities that may become essential parts of SASE Integration Suites in

the years ahead.

• Endpoint Protection Detection & Response (EPDR) for identifying malware or

malicious behavior and preventing damage, application control, URL/content filtering;

detection and remediation of malware or other security incidents on desktops,

servers, laptops, and mobile devices. There are four approaches that vendors can

take to EPDR in SASE:

o EPDR functions bundled in the SASE agent and included in the subscription. No

vendor currently offers EPDR and SASE together.

o EPDR available from the same vendor but licensed and instantiated separately.

o Partnership with one or more EPDR vendors.

o In some cases, SASE vendors do not offer as built-in or partner with EPDR

vendors but rather leave the choice to the customer about how to procure, deploy,

and manage endpoint security.

• Unified Endpoint Management (UEM) for asset management, device vulnerability and

security posture assessments. SASE endpoint agents have access to detailed device

information. Some vendors integrate with full UEM solutions in their wider suites;

some vendor products provide interoperability with 3rd-party UEM solutions via APIs;

and others do not leverage device information outside of the Device Posture Checks

that they perform for network access control.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

13

© 2023 KUPPINGERCOLE ANALYSTS AG 13

Leadership

Selecting a vendor of a product or service must not only be based on the information

provided in a KuppingerCole Leadership Compass. The Leadership Compass provides a

comparison based on standardized criteria and can help identify vendors that shall be further

evaluated. However, a thorough selection includes a subsequent detailed analysis and a

Proof of Concept of pilot phase, based on the specific criteria of the customer.

The Overall Leadership rating provides a combined view of the ratings for

• Product Leadership

• Innovation Leadership

• Market Leadership

The Overall Leadership chart is linear, with Followers appearing on the left side, Challengers

in the center, and Leaders on the right.

Overall Leadership

Figure 2: The Overall Leaders in Leadership Compass SASE Integration Suites

Overall Leaders are (in alphabetical order):

• Check Point

• Cisco

• Cloudflare

• Lookout

• Palo Alto Networks

• Versa Networks

The Overall Challengers are (in alphabetical order): Aryaka Networks, Cato Networks,

Ericom Software, and Open Systems. There are no vendors in the Followers section.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

14

© 2023 KUPPINGERCOLE ANALYSTS AG 14

Product Leadership

Product Leadership is the first major category examined below. This view is mainly based on

the presence and completeness of required features as defined above. The vertical axis

shows the product strength plotted against the combined/overall strength on the horizontal

axis. The Product Leadership Chart is rectangular and divided into thirds. Product Leaders

occupy the top section. Challengers are in the center. Followers are in the lower section.

Figure 3: The Product Leaders in Leadership Compass SASE Integration Suites

Product Leaders (in alphabetical order):

• Check Point

• Cisco

• Cloudflare

• Lookout

LEADERSHIP COMPASS: 81112

SASE Integration Suites

15

© 2023 KUPPINGERCOLE ANALYSTS AG 15

• Palo Alto Networks

• Versa Networks

The Product Challengers are (in alphabetical order): Aryaka Networks, Cato Networks,

Ericom Software, and Open Systems. There are no Followers in the Product Leadership

rating.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

16

© 2023 KUPPINGERCOLE ANALYSTS AG 16

Innovation Leadership

Next, we examine innovation in the marketplace. Innovation is, from our perspective, a key

capability in all IT market segments. Customers require innovation to meet evolving and even

emerging business requirements. Innovation is not about delivering a constant flow of new

releases. Rather, innovative companies take a customer-oriented upgrade approach,

delivering customer-requested and other cutting-edge features, while maintaining

compatibility with previous versions.

This view is mainly based on the evaluation of innovative features, services, and/or technical

approaches as defined in section 1.4. The vertical axis shows the amount of innovation

plotted against the combined/overall strength on the horizontal axis. The Innovation

Leadership Chart is rectangular and divided into thirds. Innovation Leaders occupy the top

section. Challengers are in the center. Followers are in the lower section.

Figure 4: The Innovation Leaders in Leadership Compass SASE Integration Suites

LEADERSHIP COMPASS: 81112

SASE Integration Suites

17

© 2023 KUPPINGERCOLE ANALYSTS AG 17

Innovation Leaders (in alphabetical order):

• Cisco

• Lookout

• Palo Alto Networks

• Versa Networks

The Innovation Challengers are (in alphabetical order): Aryaka Networks, Cato Networks,

Check Point, Cloudflare, Ericom Software, and Open Systems. There are no Followers in the

Innovation rating.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

18

© 2023 KUPPINGERCOLE ANALYSTS AG 18

Market Leadership

Lastly, we analyze Market Leadership. This is an amalgamation of the number of customers,

number of reported PoPs and NOCs, numbers of employees, the geographic distribution of

customers, the size of deployments and services, the size and geographic distribution of the

partner ecosystem, and financial health of the participating companies. Market Leadership,

from our point of view, requires global reach.

The vertical axis shows the market strength plotted against the combined/overall strength on

the horizontal axis. The Market Leadership Chart is rectangular and divided into thirds.

Market Leaders occupy the top section. Challengers are in the center. Followers are in the

lower section.

Figure 5: The Market Leaders in Leadership Compass SASE Integration Suites

Market Leaders (in alphabetical order):

LEADERSHIP COMPASS: 81112

SASE Integration Suites

19

© 2023 KUPPINGERCOLE ANALYSTS AG 19

• Cato Networks

• Check Point

• Cisco

• Cloudflare

• Lookout

• Palo Alto Networks

• Versa Networks

The Market Challengers are (in alphabetical order): Aryaka Networks, Ericom Software, and

Open Systems. There are no Followers in the Market Leadership rating.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

20

© 2023 KUPPINGERCOLE ANALYSTS AG 20

Correlated View

While the Leadership charts identify leading vendors in certain categories, many customers

are looking not only for a product leader, but for a vendor that is delivering a solution that is

both feature-rich and continuously improved, which would be indicated by a strong position in

both the Product Leadership ranking and the Innovation Leadership ranking. Therefore, we

provide the following analyses that correlate various Leadership categories and deliver an

additional level of information and insight.

The following charts are rectangular and divided into nine equal sections. A dashed line

intersects the rectangle at the point where x- and y-axis values are equal.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

21

© 2023 KUPPINGERCOLE ANALYSTS AG 21

The Market/Product Matrix

The first of these correlated views contrasts Product Leadership and Market Leadership.

The vertical axis represents the market position plotted against product strength rating on the

horizontal axis.

Figure 6: The Market/Product Matrix for Leadership Compass SASE Integration Suites

Vendors below the line have a weaker market position than expected according to their

product maturity. Vendors above the line are sort of “overperformers” when comparing

Market Leadership and Product Leadership. All the vendors below the line are

underperforming in terms of market share. However, we believe that each has a chance for

significant growth.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

22

© 2023 KUPPINGERCOLE ANALYSTS AG 22

The square at the top right contains the Market Champions, which are (in alphabetical order):

Check Point, Cisco, Cloudflare, Lookout, Palo Alto Networks, and Versa Networks.

Cato Networks is in the top center above the line. Aryaka Networks is in the center square

above the line. Ericom Software and Open Systems are also in the center square but below

the line. The other squares are empty.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

23

© 2023 KUPPINGERCOLE ANALYSTS AG 23

The Product/Innovation Matrix

This view shows how Product Leadership and Innovation Leadership are correlated. It is not

surprising that there is a pretty good correlation between the two views with a few

exceptions. The distribution and correlation are tightly constrained to the line, with a

significant number of established vendors plus some smaller vendors.

The vertical axis represents the product strength rating plotted against innovation on the

horizontal axis.

Figure 7: The Product/Innovation Matrix for Leadership Compass SASE Integration Suites

Vendors below the line are more innovative, vendors above the line are, compared to the

current Product Leadership positioning, less innovative.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

24

© 2023 KUPPINGERCOLE ANALYSTS AG 24

The square at the top right contains the Technology Leaders, which are (in alphabetical

order): Cisco, Lookout, Palo Alto Networks, and Versa Networks.

Check Point and Cloudflare are in the top center box. Open Systems is in the center square

above the line. Aryaka Networks, Cato Networks, and Ericom Software are in the center

square below the line. All other squares are empty.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

25

© 2023 KUPPINGERCOLE ANALYSTS AG 25

The Innovation/Market Matrix

The third matrix shows how Innovation Leadership and Market Leadership are related. Some

vendors might perform well in the market without being Innovation Leaders. This might

impose a risk for their future position in the market, depending on how they improve their

Innovation Leadership position. On the other hand, vendors which are highly innovative have

a good chance for improving their market position. However, there is always a possibility that

they might also fail, especially in the case of smaller vendors.

The vertical axis represents the market position rating plotted against innovation on the

horizontal axis.

Figure 8: The Innovation/Market Matrix for Leadership Compass SASE Integration Suites

LEADERSHIP COMPASS: 81112

SASE Integration Suites

26

© 2023 KUPPINGERCOLE ANALYSTS AG 26

Vendors above the line are performing well in the market as well as showing Innovation

Leadership; while vendors below the line show an ability to innovate though having less

market share, and thus the biggest potential for improving their market position.

The square at the top right contains the Big Ones, which are (in alphabetical order): Cisco,

Lookout, Palo Alto Networks, and Versa Networks.

Cato Networks, Check Point, and Cloudflare are in the top center square above the line.

Aryaka Networks is in the center square above the line. Ericom Software and Open Systems

are in the center square below the line. All other squares are empty.

Products and Vendors at a Glance

This section provides an overview of the various products we have analyzed within this

KuppingerCole Leadership Compass on SASE Integration Suites. Aside from the rating

overview, we provide additional comparisons that put Product Leadership, Innovation

Leadership, and Market Leadership in relation to each other. These allow identifying, for

instance, highly innovative but specialized vendors or local players that provide strong

product features but do not have a global presence and large customer base yet.

Based on our evaluation, a comparative overview of the ratings of all the products covered in

this document is shown in Table 1.

Product Security Functionality Deployment Interoperability Usability

Aryaka Networks Positive Neutral Neutral Neutral Positive

Cato Networks Strong

Positive Positive Neutral Weak

Strong

Positive

Check Point Strong

Positive Positive Positive Positive

Strong

Positive

Cisco Strong

Positive

Strong

Positive Positive Positive

Strong

Positive

Cloudflare Positive Positive Strong Positive Positive Strong

Positive

Ericom Positive Positive Neutral Neutral Positive

Lookout Strong

Positive

Strong

Positive Positive Strong Positive Positive

Open Systems Positive Neutral Neutral Neutral Positive

Palo Alto Networks Strong

Positive

Strong

Positive Strong Positive Positive

Strong

Positive

Versa Networks Strong

Positive

Strong

Positive Positive Strong Positive

Strong

Positive

Table 1: Comparative overview of the ratings for the product capabilities

LEADERSHIP COMPASS: 81112

SASE Integration Suites

27

© 2023 KUPPINGERCOLE ANALYSTS AG 27

In addition, we provide in Table 2 an overview which also contains four additional ratings for

the vendor, going beyond the product view provided in the previous section. While the rating

for Financial Strength applies to the vendor, the other ratings apply to the product.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

28

© 2023 KUPPINGERCOLE ANALYSTS AG 28

Vendor Innovativeness Market Position Financial Strength Ecosystem

Aryaka Networks Neutral Positive Positive Strong Positive

Cato Networks Positive Strong Positive Positive Strong Positive

Check Point Positive Strong Positive Strong Positive Strong Positive

Cisco Strong Positive Strong Positive Strong Positive Strong Positive

Cloudflare Positive Strong Positive Strong Positive Strong Positive

Ericom Neutral Neutral Neutral Neutral

Lookout Strong Positive Strong Positive Positive Positive

Open Systems Neutral Weak Neutral Weak

Palo Alto Networks Strong Positive Strong Positive Strong Positive Strong Positive

Versa Networks Strong Positive Strong Positive Positive Positive

Table 2: Comparative overview of the ratings for vendors

In Tables 3 and 4, we provide a short overview of SASE functional areas provided by each

vendor. The functional areas are described above. The answer key is below:

Yes = this solution includes this functionality as part of their SASE Integration Suite

No = these features are not available in the vendor’s SASE Integration Suite

Via Partners = Though the functionality is not present in the vendor’s platform, they do have

partnerships and/or API level connectors with 3rd-party products and services that can

provide it. This is perceived to be a more substantive approach than those vendors which

state that the functionality in question could be obtained by customers coding between their

APIs and 3rd-party service APIs.

Add-on = This vendor offers another product or service within their broader portfolio that can

provide this functionality but licensed separately.

For Zero Trust Network Access (ZTNA), we indicate which SASE Integration Suites serve as

Identity Providers (IdP) and those which can act as Relying Parties (RP) to external IAM and

IDaaS solutions.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

29

© 2023 KUPPINGERCOLE ANALYSTS AG 29

Table 3: SASE functions per vendor

Product SD-WAN SWG FW EPDR UEM

Aryaka Networks Yes Yes Yes No No

Cato Networks Yes Yes Yes No No

Check Point Yes Yes Yes Yes No

Cisco Yes Yes Yes Add-on No

Cloudflare Yes Yes Yes Via partners Via partners

Ericom Yes Yes Yes No No

Lookout Yes Yes No No Via partners

Open Systems Yes Yes Yes No Via partners

Palo Alto Networks Yes Yes Yes Add-on Via partners

Versa Networks Yes Yes Yes No Via partners

Table 4: SASE Functions per vendor, continued

Product ZTNA UBA DLP CASB RBI

Aryaka Networks RP Yes Via partners Via partners No

Cato Networks RP Yes Yes Yes No

Check Point IdP / RP No Yes Yes Yes*

Cisco IdP / RP Yes Yes Yes Yes

Cloudflare RP Yes Yes Yes Yes

Ericom IdP / RP Yes Yes Yes Yes

Lookout RP Yes Yes Yes Yes

Open Systems IdP / RP Yes No Via partner No

Palo Alto Networks IdP / RP Yes Yes Yes Via partners

Versa Networks RP Yes Yes Yes Yes

*Check Point provides capabilities similar to what is described for Remote Browser Isolation

using different technology.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

30

© 2023 KUPPINGERCOLE ANALYSTS AG 30

Product/Vendor evaluation

This section contains a quick rating for every product/service we’ve included in this

KuppingerCole Leadership Compass document. For many of the products there are

additional KuppingerCole Product Reports and Executive Views available, providing more

detailed information.

Spider graphs

In addition to the ratings for our standard categories such as Product Leadership and

Innovation Leadership, we add a spider chart for every vendor we rate, looking at specific

capabilities for the market segment researched in the respective Leadership Compass. For

the LC SASE, we look at the following eight categories:

• Connectivity – this category rates the transport layer offerings available within the

solution and/or ability for customers to select SD-WAN operators; traffic capacities;

number, size, and distribution of Points of Presence (PoPs); scalability and service

level guarantees.

• ZTNA (Zero Trust Network Access) – this category evaluates the authentication and

authorization options present for end users, administrative users, devices, and

resources. Preference is given for MFA, federation, and attribute and/or policy-based

access controls. This rating also considers interoperability with IAM/IDaaS solutions

beyond identity federation, such as Privileged Access Management (PAM).

• Endpoint – this category measures the variety of endpoint OSes for which agents are

available, and EPDR and UEM features that are either available as add-ons from the

SASE vendor or tightly integrated with 3rd-party sources. As of the publication date,

no SASE vendors offer EPDR bundled with their SASE solutions.

• Network security – this dimension represents the capabilities for detecting and

responding to threats at the network level, such as DDoS, command & control traffic,

botnet traffic, reconnaissance by adversaries, lateral movement, and data exfiltration

attempts. Many of these functions are implemented in the on-premises and/or cloud-

hosted virtual appliance components of the SASE solution. These functions are

typically handled by the Next-Generation Firewall and Firewall-as-a-Service

components. However, in some vendor solutions, these functions are implemented in

the SWG components.

• Web security – distinct from the network security rubric, this heading rates the Secure

Web Gateway and Remote Browser Isolation features within each solution. In most

cases, these functions are cloud-hosted, but, depending on the vendor’s architecture,

may also be present in the on-premises gateway appliances. In a few vendor

solutions, RBI functions are outsourced but integrated.

• Data protection – this category evaluates the DLP/CASB types of functionalities

present in reviewed products, such as the ability to define access control policies

centrally, and to discover, classify, and enforce data access control policies on

endpoints and the cloud. The policy management interface can be hosted by the

vendor in the cloud or by the customer on gateways. The discovery, classification,

and enforcement functions are mostly carried out by endpoint DLP agents and cloud-

resident CASB agents.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

31

© 2023 KUPPINGERCOLE ANALYSTS AG 31

• Administration – this metric examines the features of the administrative interface,

including overall ease-of-use for deploying and managing connectivity, quality of

dashboards and various kinds of utilization and security reports, ability to investigate

performance and possible security events, and connections with customer

infrastructure such as ITSM, SIEM, and SOAR systems.

• End user support – this category rates the availability and methods for vendor-direct

support for customer end users. Preference is given for solutions that include direct

assistance for end-users via phone, email, other messaging apps, etc. This rating

also takes into account language coverage for documentation and technical support.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

32

© 2023 KUPPINGERCOLE ANALYSTS AG 32

Aryaka Networks – SASE, SD-WAN Services

Aryaka Networks was founded in 2009 and is headquartered in San Mateo, CA. The

company is a late-stage venture-backed network security specialist. Aryaka’s SASE solution

includes SD-WAN, SWG, FWaaS, ZTNA, and DLP. Aryaka Networks offers individual SASE

components separately including SD-WAN, Multi-Cloud Networking, and VPN-as-a-Service,

as well as Content Delivery Networking, WAN Optimization, bandwidth aggregation, QOS,

SaaS acceleration, and other services. Aryaka Network Access Point (ANAP) is the on-

premises gateway, with models ranging in bandwidth from 150Mbps to 3Gbps. The

enterprise console is hosted in co-location facilities. All-inclusive site connectivity is billed by

Mbps throughput, and per-user and per-SaaS app accessed. Tiered subscription models

offering volume discounts are available. Their NOC is in India. They have 32 POPs in APAC,

EMEA, and NA.

Aryaka leverages tier-1 carriers for their layer 2/3 SD-WAN overlay. They provision circuits to

ISPs for customers if needed. Aryaka uses multiple TCP optimization techniques. 4G and 5G

are supported. The SWG is SaaS-hosted, and performs URL filtering, malware scanning and

sandboxing, and supports customer configurable allow/deny lists and authentication policies.

Certificate policy enforcement is not yet present. Firewall services include DNS filtering,

Deep Packet Inspection (DPI), application traffic detection and analysis, network

segmentation, and threat detection and response actions such as session termination, host

isolation, and packet capture. Aryaka partners with a few leading NGFW vendors as well.

Agents are available for Windows 7-11, 20H2, and Server 2022; all major Linux types; and

MacOS 10+. The agents use IPsec tunneling to get to Aryaka PoPs. An agentless approach

is on the roadmap. The agents do not provide endpoint security functions. No

incompatibilities with other vendors’ EPDR agents are reported. Aryaka agents do not

provide endpoint management features, nor do they integrate directly with UEM solutions.

For ZTNA, Aryaka acts as an IAM relying party, integrating with Microsoft Active Directory

(AD) and Azure AD, Okta, Ping, and any SAML-enabled Identity Provider (IdP).

Authentication services are handled by these external identity services. Aryaka employs

Machine Learning (ML)-based User Behavioral Analysis (UBA). Connectors are available for

many SaaS apps.

DLP and CASB are not built-in, but Aryaka does have partnering arrangements with leading

vendors. They are planning to build these toolsets into their SASE solution.

Aryaka does not support Remote Browser Isolation at present. IPaaS, SNMP, and syslog

enable connectivity with customers’ other security solutions. No connectors for customer

SOARs are available.

The Aryaka console has site and link dashboards, SLA metrics, and billing reports. The

customer admin interface is easy to use and extensible as needed. It supports the full range

of functions including access control and QoS policy creation and investigative drill-downs.

The SWG dashboard is currently separate from the main interface, but Aryaka plans to

merge them; for now, SSO is enabled between them. Aryaka provides technical support for

both customer admins via phone, email, and website, but not for customer end users.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

33

© 2023 KUPPINGERCOLE ANALYSTS AG 33

Aryaka Networks is both ISO 27001 and SOC 2 Type 2 certified. Their strengths are in the

SD-WAN, traffic acceleration, SWG, and firewall aspects of SASE. Zero Trust Networking

and IAM integration are also present. Other components are in work. DLP/CASB can be

added on via 3rd-party vendor relationships. Organizations that already have EPDR and UEM

but that need better connectivity for remote workers and field locations will want to consider

Aryaka’s solution.

Security Positive

Functionality Neutral

Deployment Neutral

Interoperability Neutral

Usability Positive

Strengths

• SD-WAN plus circuit provisioning for customers if needed

• Dual private layers 2 and 3 backbone

• High availability SLA: 99.999%

• High-speed gateways

• Multiple traffic acceleration methods used

• WAN, app, and SaaS optimization

• IPaaS for integration with ITSM

• Excellent admin interface

Challenges

• Does not have browser isolation

• DLP/CASB optionally provided through 3rd-party vendors; own DLP/CASB planned

• No agentless connectivity options yet

• ZTNA enhancements are in work

• ABAC model not supported

• No direct support for end users

LEADERSHIP COMPASS: 81112

SASE Integration Suites

34

© 2023 KUPPINGERCOLE ANALYSTS AG 34

LEADERSHIP COMPASS: 81112

SASE Integration Suites

35

© 2023 KUPPINGERCOLE ANALYSTS AG 35

Cato Networks – SASE Cloud

Cato Networks, based in Tel Aviv, was founded in 2015. They are a well-funded venture-

backed specialist in SD-WAN and security. Cato offers a wide range of SASE components,

individual products, and the SASE subset called Secure Service Edge. For SASE, Cato

Network has SD-WAN, SWG, NGFW, ZTNA, and CASB features. Cato Socket is the

physical or virtual gateway appliance, with bandwidth ranges between 500Mbps and 5Gbps.

The Cato Management Console is hosted in IaaS in Ireland. Pricing is based on numbers of

users and bandwidth. Cato has 80+ PoPs covering APAC, EMEA, LatAm, and NA.

Cato uses multiple tier-1 backbone providers upon which they construct their global

backbone service and leverages multiple techniques for TCP acceleration. Cato SASE Cloud

is SaaS, providing SWG and firewall services including URL filtering, ML-powered malware

detection, customer configurable access control and certificate policies and allow/deny lists.

In terms of firewall-type services, Cato SASE Cloud offers DNS filtering, Deep Packet

Inspection, advanced malware detection, and network zone enforcement.

Cato has agents for Windows 8-11, CentOS, Ubuntu, MacOS, Android, and iOS. TLS 1.2/1.3

is used for remote client to PoPs. The agents have limited endpoint security features. Cato’s

SPACE product does Device Posture Checks (DPC) and can initiate patching or other

remediations. There are no connectors for UEM products, but customers can configure

connections over APIs if needed. Agents are not needed for clients behind Cato Socket

devices.

Cato acts as an identity relying party, and has integrations with Microsoft AD, Azure AD,

Google, and OneLogin. However, SAML is not supported. Built-in MFA is limited to OTP.

Cato performs ML-enhanced UBA, evaluating multiple risk factors. Many integrations for

SaaS apps are available.

For DLP and CASB, Cato performs data discovery and classification on 360+ pre-defined

data types. Customers cannot create their own data labels. Disk/file encryption and Data

Access Governance interoperability are not present yet. A few common DLP/CASB

enforcement actions are not supported. The CASB component enables cloud usage

discovery. Their NGFW and CASB functions recognize nearly 6,000 application types.

User/group entitlements and RBAC models are available, working in concert with customer

IAM/IDaaS.

Cato does not have Browser Isolation currently, but it is planned. Customers can access log

data via GraphQL, the Cato Cloud API, or csv export. Syslog and SNMP are not supported.

There are no connectors for SIEM, SOAR, or ITSM.

Cato’s customer admin dashboard includes many out-of-the-box reports covering a wide

variety of common regulatory compliance metrics. Customer admin support is unlimited via

email, phone, and website, but support is not directly provided for customer end users.

Cato Networks has obtained ISO 27001 and SOC 2 Type 2 certifications. Though the service

is missing some SASE features, Cato SASE includes a global backbone with traffic

acceleration, SWG, firewall services, and DLP/CASB. Their DLP/CASB recognizes an

above-average number of data types. Cato needs to support additional standards for

LEADERSHIP COMPASS: 81112

SASE Integration Suites

36

© 2023 KUPPINGERCOLE ANALYSTS AG 36

interoperability with customer IAM and security components. Organizations looking for the

networking enhancement side of SASE, and that have other security tools in place to provide

endpoint security and management, will want to consider Cato Networks.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

37

© 2023 KUPPINGERCOLE ANALYSTS AG 37

Security Strong Positive

Functionality Positive

Deployment Neutral

Interoperability Weak

Usability Strong Positive

Strengths

• High availability SLA: 99.999%

• High-speed gateways

• Multiple, converged Tier 1 network providers form their global private backbone

• Cato SPACE performs DPCs, routing decisions, traffic optimization, and has endpoint

remediation capabilities

• Supports Encrypted Traffic Analysis and User Behavioral Analysis

• Excellent admin dashboard with many reports available, including regulatory and

security policy compliance

Challenges

• Lacks Remote Browser Isolation functions

• Does not support SAML for IdP interoperability

• DLP/CASB has a good subset of expected enforcement actions available; ABAC not

supported

• Only GraphQL is supported for API

• Lacks connectors for ITSM, SIEM, and SOAR

Leader in

LEADERSHIP COMPASS: 81112

SASE Integration Suites

38

© 2023 KUPPINGERCOLE ANALYSTS AG 38

LEADERSHIP COMPASS: 81112

SASE Integration Suites

39

© 2023 KUPPINGERCOLE ANALYSTS AG 39

Check Point – Harmony Connect

Check Point is a global cybersecurity leader, founded in 1993 in Tel Aviv. Check Point

Harmony Connect is the primary SASE product. Check Point Harmony Total is a bundling of

endpoint, browser, mobile, and SASE products. Check Point also offers next-gen firewalls,

edge security solutions, IoT security gateways, VPNs, cloud security solutions, and complete

SOC management solutions. In terms of SASE components, Check Point has SD-WAN,

SWG, NGFW, EPDR, ZTNA, and DLP. Gateways are Docker-based containers with up to

850Mbps bandwidth each. The enterprise management console is SaaS-hosted across

multiple IaaS providers. Licensing costs are calculated per user, with two different packages:

one for internet access and one for remote access plus ZTNA. Check Point has 80+ PoPs

around the world.

Customers typically add Check Point security services over their existing SD-WAN

connections. Check Point recently launched their own SD-WAN service. Check Point hosts

their SWG, but customers can choose to install it on-prem or in IaaS. SWG features include

URL and SNI filtering, and advanced Content Disarm & Reconstruction (CDR) technology,

which removes executable code from email and web sessions allowing safe delivery of

previously infected content. Their SWG supports customer configurable web access and

certificate policies and allow/deny lists. Firewall functions include DNS filtering, Deep Packet

Inspection, sandboxing, and network segmentation. Other functions include application

control, C2 protection, and integrated IPS.

Agents are available for Windows 8-11 and MacOS; Linux agents are in work. Agents use

TLS 1.3 for comms to PoPs. Check Point supports agentless reverse proxy access to their

PoPs as well. Check Point Harmony Endpoint provides full EPDR functionality and can

collect device information for access controls. Agents can be deployed via InTune. No

incompatibilities with other vendors’ EPDR products are reported.

Check Point can serve as an IdP, offering username/password and mobile push

authentication. CheckPoint can be a relying party to Microsoft AD, Azure AD, Duo, Google,

Okta, Ping, or any SAML issuing IdP. OIDC is not supported. UBA is on their product

roadmap. There are no pre-built connectors for SaaS apps.

For DLP and CASB, Check Point performs data discovery and classification, drawing up on

more than 800 pre-defined data types. Customers can create their own data types to search

on as well. Integration with Data Access Governance and file encryption management is not

supported. The endpoint agent can prevent unauthorized copying of files to removable

media, uploading data to sites, downloading files, and attaching to email. Check Point’s DLP

extends to messaging apps such as Slack and Teams, and SaaS apps such as Box,

Dropbox, OneDrive, etc., allowing granular control over what users can share over those

channels.

Check Point Harmony Browse provides a “nano agent” in users’ browsers to prevent

phishing, corporate credential reuse, and known and zero-day malware. The most common

browsers are supported. This add-on solution is an alternative to Browser Isolation, which

Check Point believes performs better.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

40

© 2023 KUPPINGERCOLE ANALYSTS AG 40

Check Point products use REST API, SNMP, and syslog for communicating with other

security components. There are no specific connectors for ITSM or 3rd-party SOAR solutions,

however. The admin interface is intuitive, allowing customers to easily manage access rules

and check status and security of connections. Many reports are available. Check Point

provides support for both customer admins and end users over phone, web, and email.

Check Point has certifications in ICSA, ISO 27001/27017/27018, NIAPC, SOC 2 Type 2, UK

Cyber Essentials, and for multiple relevant products in Common Criteria. As a long-

established global security vendor in many product categories, it is not surprising that Check

Point emphasizes the security aspects of SASE: firewall, secure remote access VPN, EPDR,

SWG, and ZTNA. Check Point was an Overall, Product, Innovation, and Market Leader in the

Leadership Compass on Network Detection & Response. SD-WAN is in early availability and

will be GA in early 2023. The DLP capabilities in Check Point Harmony Connect and the

Harmony Browse add-on (the Browser Isolation alternative) are innovative. Organizations

looking for rigorous security in a SASE solution should put Check Point on their evaluation

list.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

41

© 2023 KUPPINGERCOLE ANALYSTS AG 41

Security Strong Positive

Functionality Positive

Deployment Positive

Interoperability Positive

Usability Strong Positive

Strengths

• Strong DLP features that prevent data exfiltration via messaging and collaboration

platforms

• Content Disarm & Reconstruction increases protection and user productivity

• TLS 1.3 support

• Can serve as IdP or RP for Zero Trust Network Access

• Harmony Browse add-on is an innovative Browser Isolation alternative

• Harmony Total has EPDR

• Excellent customer admin interface

Challenges

• SASE and endpoint security agents are distinct but can be managed from central

console

• Does not currently perform UBA

• OIDC not supported for ZTNA

• ABAC model is not supported

Leader in

LEADERSHIP COMPASS: 81112

SASE Integration Suites

42

© 2023 KUPPINGERCOLE ANALYSTS AG 42

LEADERSHIP COMPASS: 81112

SASE Integration Suites

43

© 2023 KUPPINGERCOLE ANALYSTS AG 43

Cisco – Secure Connect

Cisco is a global network and security leader, founded in 1984, and headquartered in the

Bay Area of California. Cisco is well-known for networking products, and has solutions for

mobile, cloud, and IoT. Cisco has products addressing all aspects of SASE. Any Cisco

networking device that supports IPsec termination can serve as a gateway. Cisco offers

gateways for clientless ZTNA, which can be delivered as containers or VMs. Enterprise

management consoles are SaaS-hosted in IaaS and Cisco facilities. Licensing costs are

determined on a per-user basis. Cisco has four NOCs and 26 PoPs distributed globally.

Customers can provision Cisco SD-WAN on top of their existing ISP connections. Multiple

traffic acceleration techniques are employed. Cisco hosts SWG for clients. It performs URL

filtering, malware detection and sandboxing, DNS security, web access control and certificate

policy enforcement, and allows customers to maintain their own allow/deny lists. The firewall

includes DNS filtering, Deep Packet Inspection, IDS/IPS, malware detection, and security

analysis integration. Cisco XDR enables thorough detection and detailed responses including

process termination, session termination, host isolation, and automatic firewall rule updates.

Agents are available for Windows 8-11, Ubuntu, MacOS 10.14+, Android, and iOS. Reverse

proxy architecture for agentless access is supported. Agents use IPsec and TLS 1.2 for PoP

communications. Cisco Secure Endpoint (sold separately) contains full EPDR functionality.

No incompatibilities with other EPDR tools have been discovered. Cisco Secure Connect

interoperates with many UEM platforms.

Cisco can act as a relying party to any OIDC or SAML enabled identity provider. Cisco

Secure Connect includes Duo identity provider services with multiple MFA options including

username/password, mobile push, SMS OTP, Duo authenticator app, CAC/PIV card, FIDO

2.0 & WebAuthn, OIDC, RADIUS, and SAML. Cisco integrates with Identity Governance and

Privileged Access Management services. The solution performs ML-enhanced UBA. Many

connectors for SaaS apps are present.

Cisco’s DLP and CASB do data discovery and can classify hundreds of pre-defined data

types, and customers can create their own. File encryption management is not supported,

and there are no integrations with Data Access Governance systems. Enforcement actions

are limited. CASB is implemented in the firewall and SWG components, and additional

functions can be obtained in Cisco Umbrella and Cloudlock. Cloud resource usage can be

detected. Access controls are constrained to user/group entitlements. Customer key

management is not addressed.

Cisco offers Browser Isolation as SaaS, which intercepts and protects all covered users’ web

traffic using the DOM rewriting approach. Email can also be protected if clients use web

email interfaces.

Cisco leverages their Cisco Secure Malware Analytics for threat intelligence. All relevant

communication protocols are supported, enabling facile connections with other parts of

customer IAM and security architectures such as SIEM and SOAR. ServiceNow ITSM can be

integrated. The Cisco Defense Orchestrator Console presents much information but is easy

to navigate and use. Moreover, it can be customized as needed. Cisco handles technical

LEADERSHIP COMPASS: 81112

SASE Integration Suites

44

© 2023 KUPPINGERCOLE ANALYSTS AG 44

support for their customer admins as well as end users over phone, email, chat, and their

website.

Cisco is planning US FedRAMP Moderate certification for Secure Connect, but no other

certifications have been completed yet. Cisco is an Overall, Product, Innovation, and Market

leader in the Leadership Compass on Zero Trust Network Access and Leadership Compass

on Network Detection & Response. Though there are just a few areas of improvement

possible, Cisco’s Secure Connect is a very comprehensive solution that should be on the

short list of any organization looking for SASE.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

45

© 2023 KUPPINGERCOLE ANALYSTS AG 45

Security Strong Positive

Functionality Strong Positive

Deployment Positive

Interoperability Positive

Usability Strong Positive

Strengths

• Good array of SASE components and services

• High-speed gateways

• Cisco XDR is bundled, which enables real-time response to incidents

• Full featured firewall, SWG, and secure VPN

• Complete IDaaS with wide range of MFA options available in Duo, packaged with

Secure Connect

• Many pre-defined data types for DLP

• Excellent standards support facilitates interoperability with many 3rd-party products in

IAM and security

Challenges

• Secure Endpoint is sold separately

• DLP and CASB enforcement actions are limited; full CASB requires Cloudlock add-on

• No integration with Data Access Governance

• File encryption at the endpoint and key management in the cloud are not addressed

Leader in

LEADERSHIP COMPASS: 81112

SASE Integration Suites

46

© 2023 KUPPINGERCOLE ANALYSTS AG 46

LEADERSHIP COMPASS: 81112

SASE Integration Suites

47

© 2023 KUPPINGERCOLE ANALYSTS AG 47

Cloudflare – Cloudflare One

Cloudflare was founded in 2009 and is headquartered in San Francisco, CA. Cloudflare is a

leading Content Delivery Network (CDN) and provider of network security services such as

API gateway, WAF, DDoS protection, and bot management. For SASE components,

Cloudflare has SD-WAN, SWG, FWaaS, Layer 7 DDoS protection, ZTNA, DLP, CASB, and

RBI. Gateways are delivered as software agents or Docker containers, with bandwidth only

limited by customer equipment. The enterprise management console is hosted by Cloudflare

in their facilities. Service pricing is determined by numbers of users and bandwidth.

Cloudflare has edge computing facilities in 275 cities in 100 countries.

Cloudflare offers Network-as-a-Service (NaaS), Magic WAN, and integrates with leading SD-

WAN vendors like HP, Aruba, and Cisco, and leverages multiple IP and TCP optimization

methods. All their SASE components are delivered via their global network. Cloudflare One

performs URL filtering and signature-based malware scanning. Customers can write their

own allow/deny lists and web access and certificate rules. Firewall functions include DNS

filtering, application awareness, Deep Packet Inspection, and network segmentation;

Encrypted Traffic Analysis and Intrusion Detection are on the roadmap.

Cloudflare has agents for Windows 8-11 and Server 20H2/2022, most major Linux types,

MacOS 10+, Android, and iOS. Agentless reverse proxy architecture is supported. Agents

use WireGuard for communicating with PoPs. Cloudflare does not provide EPDR

functionality, but partners with some major vendors. The Cloudflare agents do have some

incompatibilities with 3rd-party security software: check the latest Cloudflare documentation

for updates. Cloudflare performs Device Posture Checks for compliance with customer

access control policies. A number of UEM integrations are available.

In the context of ZTNA, Cloudflare acts as an identity proxy and relying party. Any OIDC or

SAML issuing IdP can be used. Authentication policies can leverage any authenticator

supported by these IdPs. As an identity proxy, Cloudflare supports secure token exchange.

Cloudflare performs basic UBA, evaluating many risk factors surrounding each session, and

can optionally consider some 3rd-party intelligence sources. Advanced UBA with ML

detection models is on their roadmap.

Agent-based DLP is on Cloudflare’s roadmap. Cloudflare One can detect US SSNs and

credit card numbers and enforce policies on those data types via their gateway and SWG.

CASB is limited to cloud resource usage and data security policy violation detection.

Cloudflare has integrations for some popular SaaS apps such as Microsoft O365, Google

Workspace, Box, Salesforce, Slack, and GitHub. Data discovery and classification are limited

at present, but the Remote Browser Isolation function can prevent upload/download of data

by file types. Encryption management and Data Access Governance interoperability are not

present. User/group to resource entitlement and RBAC methods are supported.

Cloudflare uses its patented Network Vector Rendering (NVR) technology for Remote

Browser Isolation. NVR streams draw commands instead of pixels to deliver remote

browsers to users without introducing the latency of the more common, bandwidth-intensive

pixel rendering method. Cloudflare believes this approach is safer because it removes the

LEADERSHIP COMPASS: 81112

SASE Integration Suites

48

© 2023 KUPPINGERCOLE ANALYSTS AG 48

risk of the transport layer becoming an attack vector. Their NVR runs in the SWG and CASB

components or purely as SaaS by Cloudflare.

The primary response action available is to initiate packet capture for analysis and action by

other security tools. Cloudflare has REST APIs and supports Terraform for security tool

integration, including ITSM, SIEM, and SOAR. Syslog and SNMP have not been requested

much by their customers and are therefore not currently supported. Cloudflare has setup

wizards to quickly enable customers to create web access control rules. The admin interface

is straightforward to use and contains basic dashboards, analytics, and reports. Their

customers generally use the API to push logs to 3rd-party SIEM tools for in-depth analysis.

Customers cannot at present create new report types. Support for customer admins is

unlimited, and both standard and premium options are available. Admin support channels

include phone, email, website, and Slack. Direct end user support is not available.

Cloudflare is ISO 27001, PCI-DSS, and HIPAA/HITRUST certified. SOC 2 Type 2

certification has not been achieved. US FedRAMP certification is in progress. Cloudflare

offers maximum scalability in their SASE solution. Cloudflare has some innovative features,

such as the NVR Remote Browser Isolation method and WireGuard protocol for VPN. It

needs to extend the solution with full DLP/CASB, UBA, and to support more standard

communications protocols to increase interoperability. Organizations that have scalability as

a primary requirement for SASE and that want to leverage their existing EPDR and

DLP/CASB tools will want to closely evaluate Cloudflare’s SASE services.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

49

© 2023 KUPPINGERCOLE ANALYSTS AG 49

Security Positive

Functionality Positive

Deployment Strong Positive

Interoperability Positive

Usability Strong Positive

Strengths

• Large globally distributed edge presence, sophisticated traffic acceleration

• Massive backbone capacity

• 100% uptime guarantee

• Encrypted Traffic Analysis for security

• WireGuard for VPN

• Innovative Remote Browser Isolation built on Network Vector Rendering technology

• HIPAA/HITRUST certification

• Freemium model for SMBs under 50 seats

Challenges

• Signature-based malware scanning only; no sandboxing

• Does not perform Encrypted Traffic Analysis

• UBA is in work, but 3rd-party solutions can be harnessed currently

• Agent-based DLP is in development, DLP and CASB functions are limited

• No direct support for end users

Leader in

LEADERSHIP COMPASS: 81112

SASE Integration Suites

50

© 2023 KUPPINGERCOLE ANALYSTS AG 50

LEADERSHIP COMPASS: 81112

SASE Integration Suites

51

© 2023 KUPPINGERCOLE ANALYSTS AG 51

Ericom – ZTEdge Cloud Security Platform

Ericom Software was founded in 1993 and is headquartered in New Jersey and has R&D in

and Israel. Ericom had been primarily focused on remote access and web security solutions

but moved into SASE last year when it introduced its ZTEdge platform targeted at midsize

enterprises and small businesses. Ericom’s SASE offerings include SD-WAN, SWG, NGFW,

ZTNA, DLP, CASB, RBI, and basic IAM with MFA. Additional functions include Content

Disarm & Reconstruction (CDR) via integration, virtual meeting security and web application

isolation. All gateways are cloud-hosted with up to 10Gbps bandwidth. Pricing is per-user

per-year. ZTEdge is managed by Ericom in three NOCs in a follow-the-sun support system.

Ericom has 51 PoPs deployed in public IaaS providers across APAC, EMEA, LatAm, and

NA.

ZTEdge uses a private backbone (with full mesh options) for their SD-WAN service, which

they term “Cloud Area Network”. Routing optimization is used, but traffic acceleration is not.

The SWG performs URL filtering and malware scanning but omits some other security

analysis functions. Customers can elect to use the built-in CDR services as an alternative to

traditional sandboxing technology (which is not available in the solution). Customers can

create web access and certificate policies and customized allow/deny lists. ZTEdge firewall

services perform DNS filtering, Deep Packet Inspection, and Encrypted Traffic Analysis;

however, application detection is not supported.

Agents are available for Windows 10/11, Windows Server 2016+, all major Linux types,

MacOS 10+, and Android. Their Web Application Isolation feature, which is a reverse proxy

architecture, provides agentless connection options. Agents communicate with PoPs over

WireGuard. ZTEdge does not perform endpoint security functions such as malware

prevention and detection. There are no known incompatibilities with other vendors’ EPDR

solutions. Their agent does collect device info for posture checks but there are no

integrations with third-party UEM platforms.

For ZTNA, Ericom can act as an IdP, accepting username/password, hardware tokens,

OAuth, OIDC, RADIUS, and SAML authentication; it can be a relying party to any OIDC or

SAML issuing IdP. No connectors for SaaS apps are available. ZTEdge’s ZTNA component

does basic UBA, examining multiple risk factors but does not accept external sources of

intelligence.

In terms of DLP and CASB, ZTEdge does not do data discovery but can provide limited

enforcement for a large list of common data types. DLP rules must be edited using RegExp.

Encryption management and Data Access Governance integration are not part of the feature

set. It can detect cloud usage. Only user/group to resource entitlements are supported as

access controls.

ZTEdge has full Remote Browser Isolation features, leveraging multiple rendering

approaches. ZTEdge emphasizes their Virtual Meeting Isolation solution, which protects end

user meeting hardware interfaces (microphones and cameras) within Zoom, Google Meet,

Microsoft Teams, and Cisco WebEx.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

52

© 2023 KUPPINGERCOLE ANALYSTS AG 52

ZTEdge only alerts customers about incidents via syslog to their SIEMs. No connectors for

ITSM or SOAR are available yet. It can capture packets for analysis, terminate sessions,

isolate hosts, and block comms by IP and port. The customer admin dashboard shows all the

relevant status items and allows drill-down for further investigations. An automatic policy

builder is being refined which should make access control authoring and maintenance easier.

Technical support for customer admins is available in either business day or 24/7 packages,

over phone, email, web, and Slack. Direct end user support is offered by Ericom, and is also

provided through some MSSP relationships.

ZTEdge is not ISO 27001 certified, but SOC 2 Type 2 has been achieved. ZTEdge has high

uptime guarantees. ZTEdge also has some innovative features, such as the use of

WireGuard and its use of isolation technology to secure not just web browsing, but also

virtual meetings, instant messaging, and unmanaged device access to cloud applications.

ZTEdge is missing some aspects of full SASE as outlined above, but customers can choose

3rd-party products to address those gaps as needed. Enterprises, especially mid-size

businesses and mid-market organizations, looking for a solution that covers the functional

components addressed by this solution (including specialties in secure video conferencing)

should consider ZTEdge.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

53

© 2023 KUPPINGERCOLE ANALYSTS AG 53

Security Positive

Functionality Positive

Deployment Neutral

Interoperability Neutral

Usability Positive

Strengths

• High availability SLA: 99.999%

• WireGuard for VPN

• Can act as RP or IdP with MFA for ZTNA

• Includes integrated 3rd-party CDR service

• DLP enforcement functions leverage long list of pre-defined data types

• Multiple Remote Browser Isolation technologies included as standard in SWG

• Virtual Meeting Isolation for optimal security in Zoom, Teams, Meet, and WebEx

Challenges

• No traffic acceleration

• Sandboxing, network segmentation, and advanced network traffic analysis are not

supported

• Does not do data discovery/classification; limited DLP/CASB features

• Some security certifications are still in progress

LEADERSHIP COMPASS: 81112

SASE Integration Suites

54

© 2023 KUPPINGERCOLE ANALYSTS AG 54

LEADERSHIP COMPASS: 81112

SASE Integration Suites

55

© 2023 KUPPINGERCOLE ANALYSTS AG 55

Lookout – SWG, CASB, and ZTNA

Lookout was founded in 2002 and is headquartered in San Francisco, CA. Lookout started

as a mobile security vendor but has evolved into an endpoint-to-cloud security vendor.

Lookout addresses most aspects of SASE: SD-WAN, FWaaS, SWG, ZTNA, DLP, CASB,

and RBI. On-premises concentrators are delivered as physical appliances with 120 Mbps

bandwidth capabilities. The enterprise console is hosted in AWS. Lookout did not disclose

the number and distribution of PoPs, although it states that the APAC, EMEA, and NA

regions are covered.

Lookout partners with a single large SD-WAN provider and add security services for

customers. Traffic acceleration is not offered. Lookout’s SWG is SaaS-hosted, and MSSPs

operate it as well. Their SWG does URL filtering, malware scanning, and sandboxing.

Customers can edit web access and certificate policies and allow/deny lists. Firewall services

allow creation of simple rules based on source, destination, traffic type, and group attributes.

Lookout has agents for Windows 10/11 and Windows Server 2016+. MacOS, iOS, and

Android agents are on their roadmap. Agents use IPsec for communicating with their PoPs.

Reverse proxies enable agentless access. Lookout performs malware scanning in the cloud,

and has mobile security agents, but endpoint security functions are not present in the

deployed agents. There are no known incompatibilities with other vendors’ EPDR tools.

Lookout has integrations with IBM MaaS 360, Ivanti, Microsoft Endpoint Manager, and

VMware Workspace One for UEM.

Lookout can act as an identity relying party to Microsoft AD, Azure AD, Duo, Google, Okta, or

any SAML-enabled IdP; thus, MFA to Lookout SASE is mediated by the customer’s IdP.

OIDC is not supported. Many connectors for SaaS apps are available and customers can

create their own for HTTPS, SSH, and RDP protocols. Lookout performs UBA powered by

ML detection models.

DLP and CASB features include data discovery and classification. The solution understands

Boldon James, Microsoft AIP, and Titus classification systems. Many data types and rule

templates are present out-of-the-box, and customers can create and edit more extensively.

Lookout handles policy-based encryption. Integration with Data Access Governance

solutions is not available. The full range of DLP enforcement actions is present. The CASB

side detects cloud resource usage and supports cloud security posture assessments for IaaS

and SaaS. Customers are provided with multiple key management options. User/group

entitlement, RBAC, and ABAC models are supported.

SaaS-based Remote Browser Isolation encompassing the major methods is offered. All

covered end users’ web and email traffic can be scanned and scrubbed. Lookout leverages

their own plus 3rd-party threat intelligence.

Customers can be alerted via email, Slack, or ServiceNow. In terms of response actions,

Lookout can regulate downloads/uploads, terminate sessions, block comms by IP and port,

and isolate hosts. Additional capabilities are available via their platform’s interoperability with

multiple ITSM, SIEM, and SOAR platforms over REST APIs. The administrative interfaces

present information clearly, facilitate traffic analysis through their dedicated engine, enable

LEADERSHIP COMPASS: 81112

SASE Integration Suites

56

© 2023 KUPPINGERCOLE ANALYSTS AG 56

forensic investigations, and can be extended if needed. Technical support for both admins

and end users is available in tiered options for business day or 24/7 coverage, over phone,

email, web, and Zoom.

Lookout is ISO 27001, SOC 2 Type 2, and US FedRAMP Moderate certified. The only major

functional omission, a firewall service, is due to be addressed soon. Higher capacity

gateways would be beneficial. Lookout has strengths in DLP/CASB, Remote Browser

Isolation, and fine-grained authorization. Organizations that are seeking SASE solutions with

innovative data security features should closely evaluate Lookout’s platform.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

57

© 2023 KUPPINGERCOLE ANALYSTS AG 57

Security Strong Positive

Functionality Strong Positive

Deployment Positive

Interoperability Strong Positive

Usability Positive

Strengths

• Advanced UBA and risk-based authentication for ZTNA

• DLP and CASB work with 3rd-party data classification solutions

• Full range of DLP enforcement actions and policy-based encryption available

• Many SaaS apps supported

• RBAC and ABAC allow granular authorization

• Thorough Remote Browser Isolation methods employed

• ITSM, SIEM, and SOAR interoperability

• Customer admin interface is comprehensive, easy to navigate, and supports forensic

investigations

Challenges

• Limited endpoint agents available, though more are planned

• NGFW on their roadmap for the near term

• Gateways do not come in virtualized or containerized deployments; with typical max

throughput of 120Mbps each

• No traffic acceleration

• OIDC is not supported for ZTNA

Leader in

LEADERSHIP COMPASS: 81112

SASE Integration Suites

58

© 2023 KUPPINGERCOLE ANALYSTS AG 58

LEADERSHIP COMPASS: 81112

SASE Integration Suites

59

© 2023 KUPPINGERCOLE ANALYSTS AG 59

Open Systems – SASE +

Open Systems was founded in 1990. They are headquartered in Zurich, Switzerland. For

SASE, they have SD-WAN, SWG, NGFW, ZTNA, and CASB. Some functions are provided

through partnerships. Gateways are deployed as physical or virtual appliances with between

5-10Gbps throughput. The enterprise management console is jointly hosted in their facilities

and Azure PaaS in Switzerland. Pricing is based on the numbers of users and includes the

managed service fee for 24x7 support and customer success team. Open Systems

leverages hundreds of Unitas Global, Neterra, Equinix, and Microsoft facilities across six

continents as PoPs.

Open Systems partners with a networking provider for transport. Open Systems offers traffic

shaping/compression and application caching for acceleration. Their SWG can be run on-

premises, in IaaS, and Open Systems hosts it as SaaS. The SWG performs URL filtering,

malware scanning and blocking, and enables access control and certificate policy

enforcement. Sandboxing and Advanced Threat Protection (ATP) are add-ons. CASB

functions integrate with the SWG. Open Systems’ firewall services include DNS filtering,

ATP, NDR with Encrypted Traffic Analysis and Deep Packet Inspection, and application

detection and routing.

Open Systems has agents for Windows 7-11, Windows Server 2016+, all major Linux

variants, MacOS 10+, Android, and iOS. Agentless options are available through a reverse

proxy architecture. Open Systems does not provide built-in EPDR features but recommends

use of Microsoft Defender for endpoint security functions. No UEM capabilities or integrations

are available.

For ZTNA, Open Systems can serve as a relying party to Google, Microsoft AD & Azure AD,

Okta, Ping, or any IdP/IDaaS that supports LDAP, OIDC, RADIUS, or SAML. Directory

synchronization is available out-of-the-box. Open Systems can also act as an IdP and

authentication service, accepting username/password, SMS OTP, CAC/PIV, and FIDO 2.0

methods. Open Systems has some connectors for popular SaaS apps.

The DLP functions that are available are blocking up/downloads, controlling clipboard

capabilities, and controlling access to network drives and printers. CASB functions are

provided with the base product license through partnership with a prominent CASB vendor.

Remote Browser Isolation is not part of the solution yet.

Customers can be alerted via email, SMS, SNMP, and through their ticketing API.

Interoperability with ITSM, SIEM, and SOAR platforms can be achieved through their REST

API. Open Systems NOC can take remedial actions including terminating connections,

isolating endpoints, and blocking traffic by IP or domain. The customer admin dashboards

show most of the common statistics. The interface could use some modernization. Open

Systems’ technical account managers must make changes to report information and

structures if customers desire. As an MSSP, Open Systems provides 24/7 support for

customers over phone, email, web, or Microsoft Teams, for both customer admin users and

end users.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

60

© 2023 KUPPINGERCOLE ANALYSTS AG 60

Open Systems is ISO 27001 and SOC 2 Type 2 certified. Their solution is missing some

expected features as listed above. Their strengths are in the firewall, SWG, and agent

support areas. They also emphasize services and have a relatively long history in the MSSP

business, which they leverage to help operationalize SASE for their multi-national enterprise

customers. Organizations that are looking for the subset of SASE functions available should

consider Open Systems SASE +.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

61

© 2023 KUPPINGERCOLE ANALYSTS AG 61

Security Positive

Functionality Neutral

Deployment Neutral

Interoperability Neutral

Usability Positive

Strengths

• High-speed gateways

• Advanced firewall capabilities include ETA and application aware routing

• Support for wide variety of OSes

• Multiple traffic acceleration techniques used

• Can act as both IdP and relying party for ZTNA functions

• Syslog support for SIEM interoperability; API integration with ServiceNow ITSM

Challenges

• Does not have agent-based DLP, or RBI built-in; EPDR and CASB functions are

available via partnerships

• SWG policy authoring and report customization requires vendor support

• No IGA or PAM support

• CTI and SOAR integrations require some coding

• Admin interface needs improvement

LEADERSHIP COMPASS: 81112

SASE Integration Suites

62

© 2023 KUPPINGERCOLE ANALYSTS AG 62

LEADERSHIP COMPASS: 81112

SASE Integration Suites

63

© 2023 KUPPINGERCOLE ANALYSTS AG 63

Palo Alto Networks – SASE, Prisma Access, and Prisma SD-WAN

Palo Alto Networks, founded in 2005 in Santa Clara, CA, is the pioneer in Next Generation

Firewall (NGFW) technology. Palo Alto Networks also offers endpoint security, SOAR, XDR,

threat intelligence feeds, Cloud Native Application Protection Platform (CNAPP), and other

security products. For SASE, Palo Alto Networks has SD-WAN, SWG, NGFW & FWaaS,

EDPR, and ZTNA. Additional services include DLP, CASB, sandboxing, DNS security, IoT

security, and Advanced Threat Protection. Remote Browser Isolation is available through

partners. Gateways are available as physical or virtual appliances, and VM instances that

can run in IaaS, with throughput up to 635 Gbps. The enterprise management console is

hosted as SaaS running in data centers in North America and Europe. There are four

editions of their SASE services, with options for local or global PoP access, and options for

standard or premium support. Subscriptions are based on measures of numbers of users or

network bandwidth required. More than one hundred Prisma Access PoPs are available

across six continents.

Palo Alto Networks partners with multiple global Tier 1 telecom and cloud service providers

for connectivity. Their SASE solution relies on connection quality monitoring for optimization;

TCP acceleration techniques are not used. The SWG can run on-prem or as a SaaS in the

cloud. MSSPs also operate the product using Palo Alto Networks’ multitenancy capabilities.

Prisma Access does advanced URL filtering and malware detection/prevention and

sandboxing. Customers can write access control and certificate policies and allow/deny lists.

CASB functions are integrated into Prisma Access and support SSPM capabilities. The

NGFW performs DNS filtering, Deep Packet Inspection, application-aware routing, and

network segmentation.

Palo Alto Networks has agents for Windows 7-11, most major Linux distributions, MacOS

10+, iOS, and Android. Clientless mode is supported via reverse proxy architecture. Agents

can use IPsec and TLS 1.2/1.3 for tunneling. Full endpoint security is provided by Palo Alto

Networks’ Cortex XDR product (not included as part of the base SASE license). The agents

collect detailed device information for security posture checks. Palo Alto has integrations with

Ivanti/MobileIron, JAMF, Microsoft Endpoint Manager, and VMware Workspace One for

UEM.

Palo Alto Networks can act as an IdP or as a relying party to SAML-based IdPs such as

Microsoft AD, Azure AD, Duo, Google, Okta, and Ping Identity. Directory sync over APIs or

SCIM is permitted. OIDC is not supported. In cases where Palo Alto Networks is acting as

IdP, MFA options include username/password, mobile push, SMS OTP, mobile app,

CAC/PIV cards, FIDO 2.0, hardware tokens, and RADIUS. Many SaaS app connectors are

present. Palo Alto Networks provides some UBA within the SASE product, and advanced

UBA capabilities available as an add-on through Palo Alto Networks’ Cortex XDR.

For DLP and CASB, data discovery and classification features are present. Prisma Access

recognizes many file and non-file data types. Customers can extend these as needed.

Endpoint encryption management and Data Access Governance integrations are not

present. A few expected DLP/CASB enforcement action types are not available. Customers

can manage cloud instance encryption keys via the console. User/group entitlements, RBAC,

and ABAC models are supported.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

64

© 2023 KUPPINGERCOLE ANALYSTS AG 64

Palo Alto Networks does not have RBI built-in, but does partner with Authentic8, Ericom

ZTEdge, Menlo Security, and Proofpoint.

A full range of alerting mechanisms are used, including Microsoft Teams and Slack. Palo Alto

Networks has excellent automated response capabilities covering all expected actions. CEF,

syslog, and REST APIs facilitate interoperability with any SIEM. ServiceNow ITSM

integrations and Palo Alto Networks’ XSOAR integrations are available. The customer admin

interface starts with well-designed but customizable dashboards and allows drill downs for

detailed analyses. Many reports are available and more can be created if needed. Customer

support for both admins and end users is available via phone, email, or web.

Palo Alto Networks has obtained many security certifications, including ISO 27001/27018,

SOC 2 Type 2, Common Criteria, French ANSSI, German C5, ICSA Labs, UK NSCS, and

US FedRAMP. Palo Alto Networks is an Overall, Product, Innovation and Market Leader in

the Leadership Compass Zero Trust Network Access and Leadership Security Orchestration

Automation & Response. Their solutions are scalable, innovative, and focused on security

and interoperability. Palo Alto Networks Prisma SASE should be near the top of the

consideration list for any organization looking for these services.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

65

© 2023 KUPPINGERCOLE ANALYSTS AG 65

Security Strong Positive

Functionality Strong Positive

Deployment Strong Positive

Interoperability Positive

Usability Strong Positive

Strengths

• Deeply configurable management interface well-suited for experts, and professional

services available

• 99.999% uptime for Prisma Access

• Extremely scalable, high-speed gateways

• Broad OS support

• Excellent firewall services

• Can act as IdP or IAM relying party

• CASB key management

• Connectors to 3rd-party UEMs present

• Many file types discoverable and schema can be extended by customers as needed

in DLP implementation

• ABAC for granular authorization in DLP & CASB (add-on)

Challenges

• Complex subscription model

• Remote Browser Isolation not built-in but available through partners

• TCP acceleration techniques not used

• OIDC is not supported for ZTNA

• Bundling Cortex XDR would be advantageous for customers

Leader in

LEADERSHIP COMPASS: 81112

SASE Integration Suites

66

© 2023 KUPPINGERCOLE ANALYSTS AG 66

LEADERSHIP COMPASS: 81112

SASE Integration Suites

67

© 2023 KUPPINGERCOLE ANALYSTS AG 67

Versa Networks – SASE

San Jose, CA based Versa Networks was launched in 2012. Versa is a SASE specialist. In

terms of SASE components, Versa has SD-WAN, SWG, NGFW, ZTNA, DLP, CASB, Unified

Threat Management (UTM) and Remote Browser Isolation. Gateways can be delivered as

physical or virtual appliances (VNF). The enterprise management console can be hosted by

customers and Versa has SaaS-hosted options available. Versa also offers full SOC-as-a-

Service. Pricing is based on numbers of users and deployed gateways. Versa has multiple

NOCs and more than 90 PoPs worldwide and can add PoPs on demand for customer

coverage and capacity needs.

Customers can use their existing ISPs with the Versa SD-WAN overlay. Versa employs a

complete range of traffic acceleration techniques. Versa SWG can be deployed on-prem or in

IaaS, and they operate it as SaaS. Versa leverages multiple tunnels per endpoint, resulting in

a mesh-like network architecture for all nodes which provides automatic failover and

improved connectivity and performance. The SWG does URL filtering, malware detection

and sandboxing. Customers can provide their own certificates for decryption and can

manage their own web access control polices. The firewall does DNS filtering, Deep Packet

Inspection, application-aware routing, network/application segmentation, anti-malware

scanning, and intrusion prevention.

Versa has agents for Windows 7-11, Windows Server 2016+, all major Linux types, MacOS

10+, iOS, Chromebook, and Android. Reverse proxies and PAC files enable agentless

access. IPsec, SSH, and TLS 1.2/1.3 are supported. Versa does not have built-in EPDR

functions, but it does scan for malware at its cloud ingress/egress points, and it integrates

with 3rd-party endpoint security solutions to gather information for device posture checks.

Versa also has connectors for Citrix and Microsoft Endpoint Manager UEM platforms.

For ZTNA, Versa is an identity relying party, and can work with any OIDC or SAML issuing

IdP. Kerberos, RADIUS, and SAML can also be used. Authentication policies are therefore

constrained by customers’ IdPs. SaaS app connectors are available. Versa does UBA,

leveraging ML-powered detection models: Versa’s UBA supports geo-fencing, new device

detection, auto-logout of SaaS during suspicious events, and many other access control

features. Versa’s Identity Engine can facilitate on-premises IAM to IDaaS migrations.

For DLP and CASB, Versa does data discovery and classification. It understands the most

common file types and interoperates with Microsoft AIP. All expected enforcement actions

are available within policies. Advanced functions include the ability to redact sensitive

portions of files, encrypt sensitive files, and adding/removing an AIP labels. The CASB

component can detect cloud resource usage. Their CASB can prevent unauthorized data

disclosure in modern messaging and collaboration solutions such as Slack and Microsoft

Teams. Their DLP/CASB supports policy-based encryption and user/group entitlement,

RBAC, and ABAC methodologies. Versa can distinguish work vs. personal accounts in some

SaaS apps and enforce controls appropriately.

Versa offers Remote Browser Isolation using DOM rewrite methods. Customers can create

complex policies as needed leveraging multiple user, device, and environmental attributes.

This can protect client email only if viewed in web email interfaces.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

68

© 2023 KUPPINGERCOLE ANALYSTS AG 68

Versa utilizes multiple CTI sources. CEF and syslog support enable log transfers to SIEMs;

REST and Webhooks are also supported for application integration. For incident response,

Versa alerts customers over email, SMS, and SNMP. The expected range of remedial

actions is available: session termination, traffic blocking by IP or port, node isolation, etc.

Versa has a connector for ServiceNow ITSM; and integrations for Elastic, LogRhythm, Palo

Alto XSOAR, Securonix, and ServiceNow SOAR platforms. Versa Concerto is the single-

entry point for managing all SASE functions. The console is well-designed and intuitive for

customer admins to set policies, get status, and start investigations if needed. Technical

support for both customer admins and end users is available over phone, email, and web

channels, with no limits on case numbers.

Versa Networks is ISO 27001 and PCI-DSS v3 certified. Versa Networks’ solution covers all

major functions of SASE. More connectors for 3rd-party ITSM platforms would be useful for

some customers. Versa has multiple strengths in SASE: SD-WAN connectivity,

authentication context examination, broad OS support, and DLP/CASB being some of the

most noteworthy. Any organization looking for the full range of SASE features should have

Versa on their shortlist for RFP evaluation.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

69

© 2023 KUPPINGERCOLE ANALYSTS AG 69

Security Strong Positive

Functionality Strong Positive

Deployment Positive

Interoperability Strong Positive

Usability Strong Positive

Strengths

• Full array of traffic acceleration techniques

• Multiple tunnels connect each endpoint

• Agents for a wide range of OSes

• High-speed gateways

• Interoperability with 3rd-party UEM tools

• Sophisticated ML-based UBA and DPC for lowering authentication risks

• Excellent DLP and CASB features

• RBAC and ABAC for granular authorization

• More performant Remote Browser Isolation technique used, which can be selectively

applied by policies

• SIEM and SOAR interoperability

Challenges

• No network partnerships but customers use their own ISPs

• RBI does not quarantine email clients

• More ITSM connectors would be beneficial for some customers

Leader in

LEADERSHIP COMPASS: 81112

SASE Integration Suites

70

© 2023 KUPPINGERCOLE ANALYSTS AG 70

LEADERSHIP COMPASS: 81112

SASE Integration Suites

71

© 2023 KUPPINGERCOLE ANALYSTS AG 71

Vendors to Watch

Besides the vendors covered in detail in this document, we observe some other vendors in

the market that readers should be aware of. These vendors may not fully fit the market

definition but offer a significant contribution to the market space. This may be for their

supportive capabilities to the solutions reviewed in this document, for their unique methods of

addressing the challenges of this segment or may be a fast-growing startup that may be a

strong competitor in the future. Other companies listed here are considered SASE vendors

but did not participate in this report.

• Fortinet – Fortinet is a global security company serving organizations both large and

small. They have a SASE offering, along with their own SD-WAN, NOC management.

Other security products include NGFW, IPS, Zero Trust Network Access, IAM, WAF,

Cloud Workload Protection and Cloud Security Posture Management, CASB,

EDR/NDR, Distributed Deception Platforms, SIEM, SOAR, sandbox and threat intel

services, and email security. Fortinet was unable to participate in this report.

• Juniper Networks – Juniper is a network and cloud security stack vendor,

headquartered in Sunnyvale. Their SASE offering includes SD-WAN, Security

Director (policy creation and management), Secure Edge (FWaaS, SWG, DLP/CASB,

and malware prevention/detection), and SmartSession Router. In addition to SASE,

Juniper offers a wide range of networking hardware and software for customer data

centers, including enterprises, telcos, MNOs, and cloud service providers. Juniper

was unable to participate in this report.

• Perimeter 81 - Perimeter 81 was launched in 2018 and is headquartered in Tel Aviv.

Perimeter 81 is a network security specialist. For SASE, their services include SWG,

NGFW, and ZTNA. They emphasize Software Defined Perimeters (SDP) as a modern

alternative to VPN. More than 40 PoPs are available, with most in the US and EU.

Perimeter 81 offers some innovative components of SASE, and they are actively

adding features. They provide extended support for both customer administrators and

end users. KuppingerCole will track Perimeter 81 and include them in future reports.

• Systancia – Systancia was founded in 1998 and originally focused on technologies

such as virtual desktops. They are headquartered in France. In terms of SASE

functionality, Systancia offers UEM, ZTNA with passive biometric authentication,

AI/ML enhanced detection models for UBA, and innovative VDI-based Remote

Browser Isolation; EPDR and firewall services are available through a technical

partnership. Systancia was a Product Leader in the Leadership Compass on Zero

Trust Network Access.

• VMware (Broadcom) – VMware is an international cloud computing, virtualization,

development tool, container application lifecycle, container operational management,

container and endpoint security and software defined network, load balancer and API

ingress vendor headquartered in Palo Alto, California. Founded in 1998, the company

was an early pioneer in hardware virtualization technology. VMware offers a broad

portfolio of security tools, including products for both running and securing cloud

workloads. VMware has SASE solutions that include both site connectivity and WFA

capabilities. VMware was acquired by Broadcom in May 2022. VMware was not able

to participate in this report.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

72

© 2023 KUPPINGERCOLE ANALYSTS AG 72

• Zscaler – Zscaler is a global information security company that provides an

integrated cloud-based platform for Internet security, compliance, advanced threat

protection, and other information security services. Founded in 2008, the company is

headquartered in San Jose, California. Zscaler offers full SASE services but was not

able to participate in this report.

Methodology

KuppingerCole Leadership Compass is a tool which provides an overview of a particular IT

market segment and identifies the leaders within that market segment. It is the compass

which assists you in identifying the vendors and products/services in that market which you

should consider for product decisions. It should be noted that it is inadequate to pick vendors

based only on the information provided within this report.

Customers must always define their specific requirements and analyze in greater detail what

they need. This report doesn’t provide any recommendations for picking a vendor for a

specific customer scenario. This can be done only based on a more thorough and

comprehensive analysis of customer requirements and a more detailed mapping of these

requirements to product features, i.e., a complete assessment.

Types of Leadership

We look at four types of leaders:

• Product Leaders: Product Leaders identify the leading-edge products in the particular

market. These products deliver most of the capabilities we expect from products in

that market segment. They are mature.

• Market Leaders: Market Leaders are vendors which have a large, global customer

base and a strong partner network to support their customers. A lack in global

presence or breadth of partners can prevent a vendor from becoming a Market

Leader.

• Innovation Leaders: Innovation Leaders are those vendors which are driving

innovation in the market segment. They provide several of the most innovative and

upcoming features we hope to see in the market segment.

• Overall Leaders: Overall Leaders are identified based on a combined rating, looking

at the strength of products, the market presence, and the innovation of vendors.

Overall Leaders might have slight weaknesses in some areas, but they become

Overall Leaders by being above average in all areas.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

73

© 2023 KUPPINGERCOLE ANALYSTS AG 73

For every area, we distinguish between three levels of products:

• Leaders: This identifies the Leaders as defined above. Leaders are products which

are exceptionally strong in certain areas.

• Challengers: This level identifies products which are not yet Leaders but have specific

strengths which might make them Leaders. Typically, these products are also mature

and might be leading-edge when looking at specific use cases and customer

requirements.

• Followers: This group contains vendors whose products lag in some areas, such as

having a limited feature set or only a regional presence. The best of these products

might have specific strengths, making them a good or even best choice for specific

use cases and customer requirements but are of limited value in other situations.

Our rating is based on a broad range of input and long experience in that market segment.

Input consists of experience from KuppingerCole advisory projects, feedback from customers

using the products, product documentation, and a questionnaire sent out before creating the

KuppingerCole Leadership Compass, and other sources.

Product rating

KuppingerCole Analysts AG as an analyst company regularly evaluates products/services

and vendors. The results are, among other types of publications and services, published in

the KuppingerCole Leadership Compass Reports, KuppingerCole Executive Views,

KuppingerCole Product Reports, and KuppingerCole Vendor Reports. KuppingerCole uses a

standardized rating to provide a quick overview on our perception of the products or vendors.

Providing a quick overview of the KuppingerCole rating of products requires an approach

combining clarity, accuracy, and completeness of information at a glance.

KuppingerCole uses the following categories to rate products:

• Security

• Functionality

• Deployment

• Interoperability

• Usability

Security is a measure of the degree of security within the product / service. This is a key

requirement and evidence of a well-defined approach to internal security as well as

capabilities to enable its secure use by the customer are key factors we look for. The rating

includes our assessment of security vulnerabilities and the way the vendor deals with them.

Functionality is a measure of three factors: what the vendor promises to deliver, the state of

the art and what KuppingerCole expects vendors to deliver to meet customer requirements.

To score well there must be evidence that the product / service delivers on all of these.

Deployment is measured by how easy or difficult it is to deploy and operate the product or

service. This considers the degree in which the vendor has integrated the relevant individual

LEADERSHIP COMPASS: 81112

SASE Integration Suites

74

© 2023 KUPPINGERCOLE ANALYSTS AG 74

technologies or products. It also looks at what is needed to deploy, operate, manage, and

discontinue the product / service.

Interoperability refers to the ability of the product / service to work with other vendors’

products, standards, or technologies. It considers the extent to which the product / service

supports industry standards as well as widely deployed technologies. We also expect the

product to support programmatic access through a well-documented and secure set of APIs.

Usability is a measure of how easy the product / service is to use and to administer. We

look for user interfaces that are logically and intuitive as well as a high degree of consistency

across user interfaces across the different products / services from the vendor.

We focus on security, functionality, ease of delivery, interoperability, and usability for the

following key reasons:

• Increased People Participation—Human participation in systems at any level is the

highest area of cost and the highest potential for failure of IT projects.

• Lack of excellence in Security, Functionality, Ease of Delivery, Interoperability, and

Usability results in the need for increased human participation in the deployment and

maintenance of IT services.

• Increased need for manual intervention and lack of Security, Functionality, Ease of

Delivery, Interoperability, and Usability not only significantly increase costs, but

inevitably lead to mistakes that can create opportunities for attack to succeed and

services to fail.

KuppingerCole’s evaluation of products / services from a given vendor considers the degree

of product Security, Functionality, Ease of Delivery, Interoperability, and Usability which to be

of the highest importance. This is because lack of excellence in any of these areas can result

in weak, costly, and ineffective IT infrastructure.

Vendor rating

We also rate vendors on the following characteristics

• Innovativeness

• Market position

• Financial strength

• Ecosystem

Innovativeness is measured as the capability to add technical capabilities in a direction

which aligns with the KuppingerCole understanding of the market segment(s). Innovation has

no value by itself but needs to provide clear benefits to the customer. However, being

innovative is an important factor for trust in vendors because innovative vendors are more

likely to remain leading-edge. Vendors must support technical standardization initiatives.

Driving innovation without standardization frequently leads to lock-in scenarios. Thus, active

participation in standardization initiatives adds to the positive rating of innovativeness.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

75

© 2023 KUPPINGERCOLE ANALYSTS AG 75

Market position measures the position the vendor has in the market or the relevant market

segments. This is an average rating over all markets in which a vendor is active. Therefore,

being weak in one segment doesn’t lead to a very low overall rating. This factor considers the

vendor’s presence in major markets.

Financial strength even while KuppingerCole doesn’t consider size to be a value by itself,

financial strength is an important factor for customers when making decisions. In general,

publicly available financial information is an important factor therein. Companies which are

venture-financed are in general more likely to either fold or become an acquisition target,

which present risks to customers considering implementing their products.

Ecosystem is a measure of the support network vendors have in terms of resellers, system

integrators, and knowledgeable consultants. It focuses mainly on the partner base of a

vendor and the approach the vendor takes to act as a “good citizen” in heterogeneous IT

environments.

Again, please note that in KuppingerCole Leadership Compass documents, most of these

ratings apply to the specific product and market segment covered in the analysis, not to the

overall rating of the vendor.

Rating scale for products and vendors

For vendors and product feature areas, we use a separate rating with five different levels,

beyond the Leadership rating in the various categories. These levels are

Strong positive Outstanding support for the subject area, e.g., product functionality, or

outstanding position of the company for financial stability.

Positive Strong support for a feature area or strong position of the company, but

with some minor gaps or shortcomings. Using Security as an example, this

can indicate some gaps in fine-grained access controls of administrative

entitlements. For market reach, it can indicate the global reach of a partner

network, but a rather small number of partners.

Neutral Acceptable support for feature areas or acceptable position of the

company, but with several requirements we set for these areas not being

met. Using functionality as an example, this can indicate that some of the

major feature areas we are looking for aren’t met, while others are well

served. For Market Position, it could indicate a regional-only presence.

Weak Below-average capabilities in the product ratings or significant challenges

in the company ratings, such as very small partner ecosystem.

Critical Major weaknesses in various areas. This rating most commonly applies to

company ratings for market position or financial strength, indicating that

vendors are very small and have a very low number of customers.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

76

© 2023 KUPPINGERCOLE ANALYSTS AG 76

Inclusion and exclusion of vendors

KuppingerCole tries to include all vendors within a specific market segment in their

Leadership Compass documents. The scope of the document is global coverage, including

vendors which are only active in regional markets such as Germany, Israel, or the US.

However, there might be vendors which don’t appear in a Leadership Compass document

due to various reasons:

• Limited market visibility: There might be vendors and products which are not on our

radar yet, despite our continuous market research and work with advisory customers.

This usually is a clear indicator of a lack in Market Leadership.

• Declined to participate: Vendors might decide to not participate in our evaluation and

refuse to become part of the Leadership Compass document. KuppingerCole tends to

include their products anyway if sufficient information for evaluation is available, thus

providing a comprehensive overview of leaders in the market segment.

• Lack of information supply: Products of vendors which don’t provide the information

we have requested for the Leadership Compass document will not appear in the

document unless we have access to sufficient information from other sources.

• Borderline classification: Some products might have only small overlap with the

market segment we are analyzing. In these cases, we might decide not to include the

product in that KuppingerCole Leadership Compass.

The target is providing a comprehensive view of the products in a market segment.

KuppingerCole will provide regular updates on their Leadership Compass documents.

We provide a quick overview about vendors not covered and their offerings in chapter

Vendors to Watch. In that chapter, we also look at some other interesting offerings around

the market and in related market segments.

LEADERSHIP COMPASS: 81112

SASE Integration Suites

77

© 2023 KUPPINGERCOLE ANALYSTS AG 77

Related Research

Leadership Compass Endpoint Protection Detection & ResponseLeadership Compass

Network Detection & ResponseLeadership Compass Zero Trust Network Access

Leadership Compass Unified Endpoint Management

Market Compass Cloud Delivered Security

Advisory Note Implementing SASE

Whitepaper Security Operations in the Age of Zero Trust

Whitepaper The Role of Identity for Zero Trust

Copyright

©2023 KuppingerCole Analysts AG all rights reserved. Reproduction and distribution of this publication in any form is forbidden

unless prior written permission. All conclusions, recommendations and predictions in this document represent KuppingerCole´s

initial view. Through gathering more information and performing deep analysis, positions presented in this document will be

subject to refinements or even major changes. KuppingerCole disclaim all warranties as to the completeness, accuracy and/or

adequacy of this information. Even if KuppingerCole research documents may discuss legal issues related to information

security and technology, KuppingerCole do not provide any legal services or advice and its publications shall not be used as

such. KuppingerCole shall have no liability for errors or inadequacies in the information contained in this document. Any opinion

expressed may be subject to change without notice. All product and company names are trademarks or registered® trademarks

of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

KuppingerCole Analysts support IT professionals with outstanding expertise in defining IT strategies and in relevant decision-

making processes. As a leading analyst company, KuppingerCole provides first-hand vendor-neutral information. Our services

allow you to feel comfortable and secure in taking decisions essential to your business.

KuppingerCole, founded in 2004, is a global, independent analyst organization headquartered in Europe. We specialize in

providing vendor-neutral advice, expertise, thought leadership, and practical relevance in Cybersecurity, Digital Identity & IAM

(Identity and Access Management), Cloud Risk and Security, and Artificial Intelligence, as well as for all technologies fostering

Digital Transformation. We support companies, corporate users, integrators, and software manufacturers in meeting both

tactical and strategic challenges and make better decisions for the success of their business. Maintaining a balance between

immediate implementation and long-term viability is at the heart of our philosophy.

For further information, please contact clients@kuppingercole.com.

Contents Figures Introduction / Executive Summary Highlights Market Segment Delivery Models Required Capabilities Optional Capabilities

Leadership Overall Leadership Product Leadership Innovation Leadership Market Leadership

Correlated View The Market/Product Matrix The Product/Innovation Matrix The Innovation/Market Matrix

Products and Vendors at a Glance Product/Vendor evaluation Aryaka Networks – SASE, SD-WAN Services Cato Networks – SASE Cloud Check Point – Harmony Connect Cisco – Secure Connect Cloudflare – Cloudflare One Ericom – ZTEdge Cloud Security Platform Lookout – SWG, CASB, and ZTNA Open Systems – SASE + Palo Alto Networks – SASE, Prisma Access, and Prisma SD-WAN Versa Networks – SASE

Vendors to Watch Methodology Types of Leadership Product rating Vendor rating Rating scale for products and vendors Inclusion and exclusion of vendors


Item Type: pdf