
The data center is no longer the center of the enterprise network. Applications have moved to SaaS and the cloud, employees connect from branches, homes and the field, and partners access corporate resources from outside. Yet in many organizations traffic is still hauled back to headquarters for security inspection before reaching the internet. This "hairpin" architecture both increases latency and fills expensive MPLS lines with unnecessary traffic. SASE (Secure Access Service Edge) was born to solve exactly this problem: delivering network and security functions from the cloud, at the point closest to the user, as a single service.
What Is SASE?
Defined by Gartner in 2019, SASE unifies two worlds in one architecture: on the WAN side, the application-aware intelligent routing of SD-WAN; on the security side, a cloud-delivered security stack called SSE (Security Service Edge). Wherever the user is, traffic first reaches the nearest SASE point of presence (PoP); identity verification, threat inspection and data protection are applied there, and traffic is forwarded to its destination over the shortest path. Security is delivered by a global cloud service, not by a box in the data center.
Core Components of SASE
SASE is not a single product but a set of services working together:
- SD-WAN: Connects branches and data centers intelligently over multiple links (MPLS, internet, LTE/5G) with application-based policies; continuously measures link quality and steers traffic over the best path.
- SWG (Secure Web Gateway): Inspects web traffic against malicious sites, harmful downloads and inappropriate content.
- CASB (Cloud Access Security Broker): Brings visibility into SaaS usage; detects unsanctioned applications (shadow IT) and prevents uncontrolled flow of sensitive data to the cloud.
- ZTNA (Zero Trust Network Access): Connects the user to the specific application they are authorized for, not to the network; replaces the VPN's broad access model with identity-based, per-application access.
- FWaaS (Firewall as a Service): Delivers next-generation firewall capabilities (IPS, application control, DNS security) from the cloud; removes the need for hardware stacks at branches.
Why Now?
Three trends have pushed SASE to the center of the agenda. First, the nature of traffic has changed: most enterprise traffic now flows directly to the cloud and SaaS, not to the data center. Second, hybrid work is permanent; security cannot wait for the user at the office. Third, the stack of appliances and point solutions has become unmanageable: operating a separate firewall, web filter and VPN concentrator at every branch is both costly and prone to policy inconsistency. SASE reduces this stack to one policy, one console and one cloud service.
The Path from SD-WAN to SASE
Most organizations move to SASE in stages, not in one step. A typical roadmap looks like this: first, branch connectivity is modernized with SD-WAN and dependence on expensive MPLS is reduced. Next, remote access is migrated from VPN to ZTNA, making the riskiest area — remote user access — identity-based. In the third step, web and SaaS traffic starts being inspected from the cloud through SWG and CASB. In the final step, branch security hardware is handed over to FWaaS and all policy is unified in a single console. Each stage produces measurable value on its own, freeing the project from "all or nothing" risk.
Measurable Benefits
A well-designed SASE architecture produces concrete results: user experience improves noticeably as latency to SaaS and cloud applications drops; MPLS and branch hardware costs decrease; audit and compliance become easier because policy is enforced identically everywhere; and the attack surface shrinks because applications are taken off the public internet and access is bound to identity. On the operations side, a single console replaces the separate management of dozens of boxes.
What to Watch Out For
The most common mistake in SASE projects is treating the topic as mere product selection. Success actually depends on a correct analysis of the existing network topology, application inventory and traffic flows. PoP coverage matching Türkiye and the geographies you operate in, planning of local internet breakouts, identity provider integration and preserving your existing SD-WAN investment are the critical items of migration design. Network and security teams must also work with a common policy language; SASE is an organizational convergence project as much as a technical one.
Single Vendor or Multi-Vendor?
There are two main approaches in the SASE market. Single-vendor SASE means taking the entire networking and security stack from the same manufacturer; depth of integration, a true single-console experience and a single point of support are its strongest sides. In the multi-vendor approach, the existing SD-WAN investment is preserved and another vendor's SSE layer is added on top; this softens the transition but requires policy and log integrity to be built with care. The right answer depends on the organization's existing contracts, team skills and renewal calendar. What is critical is that whichever model is chosen, identity, policy and visibility converge in one place; otherwise SASE turns into the old silo structure under a new name.
The Invisible Determinant of Performance: Backbone Quality
Two SASE services can have identical components on paper; what makes the difference is the provider's global backbone. The number and location of PoPs, use of a private backbone between PoPs, the latency of the nearest entry point for users in Türkiye and the quality of peering with SaaS providers directly determine user experience. A proof-of-concept test from real locations is a must during evaluation, and measurements should be taken over periods covering business hours, not as one-off samples.
Industry Application Examples
In retail, connecting hundreds of stores to the center over inexpensive internet lines with a uniform security policy is SASE's most mature scenario. In finance, branch transformation is handled together with strict regulation and logging requirements; which PoP processes the data and where logs are stored should be part of the contract. In manufacturing, SASE stands out with its ZTNA layer for controlled remote access of field engineers and suppliers to OT environments. In holding structures, the ability to quickly bring newly acquired companies' networks under the common policy umbrella is a little-known but powerful contribution of SASE to merger and acquisition processes.
Where to Start? A Short Checklist
As you begin a SASE evaluation, the answers to these questions will sharpen your roadmap:
- What percentage of your traffic goes to the data center versus directly to the cloud and SaaS? Is your flow map current?
- When do your MPLS and branch security hardware contracts renew? Do migration windows align with that calendar?
- Are you still using classic VPN for remote access; how many users, accessing which applications?
- Is your identity provider (directory, MFA, conditional access) ready for SASE integration?
- In which model will your network and security teams work for joint policy management?
Once this inventory is in place, which stage to start from and which model (single or multi-vendor) fits usually becomes self-evident.
At Datnes Bilişim, within Enterprise Network Solutions and Cyber Security Solutions, we plan, design and implement the journey from SD-WAN to SASE end to end while preserving your existing infrastructure.
