SASE has always been sold as convergence. Networking, security and monitoring, three stacks that used to sit in different parts of the business, pulled together into a single cloud-delivered platform with zero trust running through all of it. That part is real, and it is genuinely powerful.
What converged, though, was the tooling. Not the expertise. The technology now sits behind one console, but the disciplines underneath it never merged. Someone still has to understand identity. Someone still has to understand routing. In most organisations, those are never the same person. If that was true inside your own function, why would it suddenly stop being true of the provider selling you a managed SASE service?
That is worth thinking about before you choose one.
Do you want fries with that connectivity?
There is no shortage of SASE offers in the market right now. Most large networking providers have one, most security resellers have one, and a good number of telcos have quietly attached one to their connectivity portfolio. On paper they look similar. In practice they are not, and the differences only surface once you are eighteen months in and reliant on them.
The pattern I would encourage buyers to look at closely is where the SASE offer sits in the partner's own model. If it arrived as an attachment to a connectivity or SD-WAN sale, there is a reasonable chance it is being treated as a box at the end of a circuit. A bit like ordering a side of fries with your burger.
I want to be fair about this, because that logic is not inherently wrong and the commercial motivation behind it is perfectly legitimate. Connectivity margins are under pressure, the space is changing, and diversifying into adjacent services is a sensible response. SASE does terminate connectivity, the bundling is neat, and if your driver is genuinely branch consolidation then a network-led partner may serve you perfectly well.
But it does carry a specific risk. SASE is not the security appliance at the edge of a WAN. It is identity, policy, data protection, threat prevention, user experience and operational governance. None of those behave like routing, and none of them are solved by understanding the underlay.
The related thing I would be cautious about is any partner telling you they can do all of it, to depth, on their own. That claim usually survives right up until the first hard question.
The five layers you are actually buying
Think about the vertical layers of what a SASE service is made of. There are five, and each one is a specialism.
Security Enforcement
- Secure web gateway, CASB, data loss prevention, threat prevention and DNS security. Secure web gateway on its own is a specialism that takes years to do well, and that is before you reach DLP, which demands an understanding of the customer's data as much as the product, CASB, or threat policy. Five products, five bodies of knowledge, and none of them are solved with a template.
Identity and Access
- Identity provider integration, conditional access, device posture and ZTNA. This is where zero trust is actually enforced, and it is unforgiving. Get the policy logic wrong and you either lock out a business unit or quietly grant access you never intended. The people who are excellent at conditional access design are rarely the same people who are excellent at BGP.
Transport and Connectivity
- SD-WAN, direct internet access, cloud on-ramps, routing and path selection. Mature, well understood, and the layer most partners are genuinely strong in.
Visibility and Digital Experience
- Telemetry, logging, digital experience monitoring and reporting. The layer that tells you whether any of the above is working as intended, and the one most often left on default settings.
Service Operations and Governance
- Running all of it as a live service. Incident and problem management, change control, policy tuning, risk review and continual improvement. A discipline in its own right, and a far bigger challenge than it usually gets credit for.
Zero Trust
Zero trust deserves a separate word here, because it is not one of the five layers. It is a principle that has to be enforced consistently across all of them, which is precisely why a partner who is strong in one layer and thin in the others will struggle to deliver it. Zero trust fails at the seams.
You want the best of each layer. More importantly, you want a partner who is honest about which layers they hold themselves, which they deliver with a third party, and which they simply resell from the vendor.
Which brings me to why we built the service the way we did at Nomios
I am conscious that we operate in the same market I am asking people to scrutinise, so it is only fair to say plainly what we hold and why I think it matters.
Nomios is a security company first.
We run a 24x7 SOC, and the work in it is detection, investigation, containment and response, with analysts working through logs rather than watching a dashboard change colour. Around it sits real security depth. Compliance and assurance, security engineering, and analysts working across a wide range of customer environments every day, defending and improving them rather than reviewing them once a year.
We also run a 24x7 NOC, and it has a long history behind it.
Not just enterprise networks, but service provider environments, large optical estates, data centres, street cabinets and exchanges. That heritage matters more than it sounds. Operating at that scale teaches you a discipline around monitoring, restoration and handover that you cannot pick up from a small managed estate, and it is exactly the discipline a global SASE fabric needs.
And we run a Technical Assistance Centre supporting enterprise customers directly.
Edge device management, wireless, user experience and application behaviour, with deep practical knowledge of how modern businesses actually run across a lot of different operating models.
That is three distinct centres of expertise, built up over years, each one strong in its own right.
This is the point. A SASE service is not one function. It is a collective of expertise coming together to build and then support you. Security operations, network operations and enterprise technical support, working from shared context rather than passing tickets between each other.
It is also why we invest as heavily as we do in vendor certification and training, and why we hold Palo Alto Networks Centre of Excellence status alongside Authorised Support Centre accreditation. Certifications on their own are wallpaper. What they buy you is the ability to fix the problem on the platform yourself, at two in the morning, rather than raising a case and waiting. There is a meaningful difference between a partner who resolves and a partner who forwards, and you will only find out which one you bought during your first serious incident.
We do not treat SASE as an attachment to connectivity because we did not arrive at it from connectivity. We arrived from all three directions at once. If what you want is better user experience, better use of the platform you are already paying for, and genuine control over how it adapts as your business changes, that is where the difference shows up.
What to ask a prospective SASE partner
If you are evaluating SASE partners, and I recognise the irony of a Nomios COO handing you a scoring framework, these are the questions I would put on the table.
- Which of the five layers do you deliver yourselves, and which do you subcontract or resell?
- Who owns policy tuning after go-live, and at what cadence?
- Do you run your own Security Operations Centre and Network Operations Centre? Are they different teams, and can I meet the people in them?
- Who holds accountability when the problem sits between the network and the security policy? - This is where most SASE incidents actually live.
- How often will you sit down with me to review the risk register, and will that be in person?
- When something breaks on the platform, do you fix it or do you raise a vendor case?
- Are you backing off the implementation to the vendor or are you doing it yourself?
- What more can you give us than just out the box configuration?
- And what are you seeing across your other customers right now, particularly around AI tooling appearing in the traffic, and what are you doing about it?
If those answers come back specific, you are probably talking to the right sort of partner. If they come back vague, or if everything is answered with a reference to a portal, that tells you more than any capability matrix will.
A final comment from me - please do scrutinise us on the same questions.
The SASE Advantage
If you’re scoping a SASE design, mid-way through an evaluation, or reassessing a deployment that has underdelivered, The SASE Advantage whitepaper sets out exactly how a certified, managed approach to Prisma Access is architected, sequenced, and operated. It’s a practical guide to what good looks like, written for the people who have to make the decision and live with it.






