I have sat in a lot of SASE conversations over my time at Nomios, and they nearly all follow the same shape. Architecture diagrams, licence counts, a migration plan, a go-live date. All necessary. All fine. And all focused on a single moment in time: getting the product deployed.
Here is the part that does not get talked about enough. When customers come to this market, they often have fewer real options than they realise. Many end up procuring the platform through a partner who simply resells the vendor's own professional services. Those teams come in, apply the out of the box templates, connect a feed, report the stats back to show the product is working, and leave. It works, in the narrow sense. But all of the knowledge built during that first phase, the reasoning behind each policy decision, the context of why something was configured a certain way, walks out the door the moment the implementation team does.
Go-live is not the finish line. It is the start line.
And here is the uncomfortable truth underneath it. Getting SASE live is the easy bit. Keeping it relevant is the hard part.
The technology is mature, the vendor templates are good, and there are plenty of capable engineers out there. If your success criteria is "users can reach their applications and the VPN concentrator has been switched off", you have a wide choice of partners.
The harder question is what happens months later.
By then the business has moved. You have acquired something, opened two new sites, or migrated a core application to SaaS. Someone has adopted an AI tool that nobody in security has assessed. Three of the policies written during migration are technically live but functionally pointless, and one of them is quietly creating risk. Meanwhile the vendor has shipped new capabilities you are already paying for and not using.
None of that is a technology problem. It is an operating problem.
Why "it's live" was never the finish line
Treating go-live as the end of the engagement sets the wrong expectation from day one. It tells the customer that success is a snapshot: a working connection, a dashboard that shows green. It says nothing about the decisions that will need to be made every month after that, as the business changes shape around a platform configured for how things looked six months ago.
A feed and a report is not operations. It is proof of life. Real operations means someone is asking why a policy exists, whether it still matches the business it was written for, and what the platform can now do that it could not do at launch.
SASE is an operational journey, not a project
The way I think about it is a cycle rather than a line, with the customer in the middle rather than the platform. Seven stages, then round again.
The first three are the ones everyone competes on:
- Assess - where we understand the current state and risk profile before touching anything.
- Design - where the target architecture is one the customer's own team understands and signs off.
- Deploy - in controlled phases with rollback available at every step. No big bang cutovers. That discipline matters, and we are good at it.
But the value is generated in the four stages that follow:

- Operate - with a single partner holding both the network and the security context, rather than passing tickets between two functions and letting the problem live in the gap.
- Optimise - where policy tuning, cost and performance work happens continuously, not during an annual panic.
- Govern - through risk reviews, service reviews and an improvement roadmap as a standing commitment, not a slide someone builds the night before.
- Mature - helping you take on the next capability, whether that is DLP, deeper ZTNA coverage, or working out how to handle the AI traffic that appeared in the estate without anyone asking permission.
Then it starts again, because the business will have changed again.
What this looks like in practice
I am wary of writing anything that sounds like a brochure, so let me be concrete about what we actually commit to.
A structured maturity cycle
- Across the in-scope modules: policy review, health and performance review, coverage review, risk review and vendor lifecycle review. Documented outputs, prioritised by impact and risk, that flow into the change process rather than into a folder.
A quarterly optimisation report
- With remediation recommendations, an improvement roadmap and a risk register. Reviewed in person, with real conversation, not emailed with a summary line.
Named people
- A service delivery manager and a focal engineer who know the environment, because continuity of understanding is the thing customers tell us they lose most often when they move to a managed service.
Reporting with written commentary
- From the people who did the work: what changed, what we learned, what we have already fixed and what we think you should prioritise next. A dashboard tells you what happened. A person tells you what it means.
Problem management as an improvement engine
- Not administration or firefighting. Recurring patterns get root caused and preventative actions tracked to closure, which is how incident volume comes down over time rather than staying flat forever.
Why I think we are credible on this
Two things give me confidence saying it out loud, and I recognise the irony of a Nomios COO marking his own homework.
The first is the Palo Alto Networks relationship. Nomios is a Palo Alto Networks Centre of Excellence, holding Authorised Professional Services status and delivering to the Palo Alto standard through our own certified engineers, across Strata, Prisma and Cortex. We are a Diamond Reseller and hold MSSP Advanced Specialisations in Prisma Access, Prisma SD-WAN and Next Generation Firewall, a combination held by very few partners across EMEA, with an Authorised Support Centre and a 24x7 UK based operation behind it. Those designations are not won with a certification count. They require demonstrable depth across sales, engineering and architecture, and evidence that you can design, deploy and operate the full portfolio yourself. Which is the point. When you buy this from us, we deliver it. We are not reselling someone else's professional services and waving them goodbye at go-live.
The second is simply the volume of real work. In 2025 our customers raised 7,700 Palo Alto tickets with us and we executed 3,856 change requests, at a 96.1 percent service level and a customer satisfaction score of 9.47 out of 10. We do this across a lot of industries and environments, which is the only honest way to know what good actually looks like.
The bit I care about most
We will not hide behind a portal.
A portal is useful. Ours is good. But a portal cannot tell you that the policy exception you granted for a project in 2024 is still live and now sits on your risk register. It cannot sit across the table from your security lead and argue, constructively, about priorities. It cannot notice that the pattern you are seeing has already been solved for three other customers in your sector.
That combination of consultancy, managed service, operational governance and risk-based optimisation, delivered by people who will get on a train to see you, is what we have been building. Not because it scales beautifully in a slide deck, but because it is what makes the platform worth what you paid for it.
SASE go-live is not the finish line. It is the point at which the interesting work begins.
If you are somewhere on that journey, whether you are assessing, mid-migration, or eighteen months in and wondering why the value has plateaued, I would genuinely enjoy the conversation. Together we can get the most out of your SASE.
The SASE Advantage
If you’re scoping a SASE design, mid-way through an evaluation, or reassessing a deployment that has underdelivered, The SASE Advantage whitepaper sets out exactly how a certified, managed approach to Prisma Access is architected, sequenced, and operated. It’s a practical guide to what good looks like, written for the people who have to make the decision and live with it.








