SASE is now standard. So why is it not delivering?
Secure Access Service Edge has moved quickly from concept to standard practice. Hybrid working, cloud adoption, and distributed users have made traditional perimeter-based security difficult to sustain, and SASE provides a clear direction for addressing that shift.
Most organisations have already taken steps in that direction. Investment has been made, platforms have been selected, and programmes are underway to consolidate networking and security into a more unified model.
Even so, the experience after deployment is often less straightforward than expected. Environments remain complex. Policy enforcement varies between users and locations. Visibility improves in some areas but remains incomplete in others.
Understanding SASE is not the issue. The difficulty lies in translating that strategy into an architecture that performs reliably in a live environment.
Where SASE rollouts go off track
The challenges organisations encounter with SASE are usually not caused by the technology itself. They tend to arise from how SASE is designed, delivered, and managed over time. Several patterns appear consistently in underperforming deployments.
SASE is sometimes approached as a combination of capabilities that need to be assembled. In practice, this often leads to separate systems being deployed for access control, web security, and cloud applications.
This typically results in:
- Policies that need to be replicated across multiple systems
- Differences in how controls are applied depending on the connection path
- An increase in operational effort despite consolidation objectives
The environment may meet the definition of SASE, but it does not behave as a unified system.
Architectures are often based on simplified assumptions. Once deployed, they must operate across legacy systems, varied access patterns, and changing user behaviour.
In practice, this results in:
- Gaps in visibility across parts of the estate
- Workarounds that sit outside intended controls
- Platforms that are technically in place but not aligned to daily operations
This is where the gap between expectation and performance becomes visible.
SASE environments require ongoing refinement. Policies need to evolve, new applications need to be accommodated, and performance needs to be monitored continuously.
Where this is not addressed, organisations often experience:
- Policy drift over time
- Reduced effectiveness as environments change
- Increasing effort to maintain stability
A static deployment cannot support a dynamic environment.
A large proportion of modern work now takes place in the browser, yet this is not always reflected in SASE design decisions.
As a result:
- Critical activity happens outside consistent inspection
- Encrypted traffic limits visibility
- Key risks remain only partially managed
This creates a structural gap in coverage that affects overall security outcomes.
Understand what is missing
For organisations already on this path, it can be difficult to pinpoint exactly where performance is being lost. The underlying issues are rarely isolated. More often, they build gradually across architecture, deployment decisions, and operational gaps.
The SASE Advantage guide explores this in detail, including:
- What a well-deployed SASE architecture looks like in practice
- Where deployments tend to lose effectiveness
- How to create a unified model from fragmented environments
- How modern usage patterns, particularly browser-based activity, should shape design decisions
It also examines how platforms such as Prisma Access are intended to operate, and what is required to translate platform capability into consistent real-world performance.

What the SASE Advantage Looks Like
When SASE is implemented well, the impact is reflected in how the environment operates day to day.
Security, visibility, and user experience become more predictable, and the effort required to manage the environment reduces.
Consistent Enforcement
- Policies are applied centrally and enforced consistently across all users, devices, and locations, removing the gaps that appear when controls are managed across multiple systems.
Complete Visibility
- User activity, application access, and traffic are visible through a single framework, making it easier to understand what is happening across the environment and identify issues early.
Reduced Complexity
- Consolidation removes overlapping tools and integrations, reducing operational overhead and making the environment easier to manage and adapt over time.
Predictable Experience
- Users can access applications securely without disruption, regardless of where they connect from, supporting productivity without introducing friction.
Why Nomios and Palo Alto Networks
Delivering SASE successfully depends on more than choosing a platform. The way that platform is designed, deployed, and managed determines the outcome.
Nomios focuses of the practical aspects of delivery, ensuring that architectures reflect real environments and can evolve over time. This includes phased deployment approaches, clear validation at each stage, and ongoing optimisation once the platform is in place.
Palo Alto Networks Prisma Access supports this model by bringing together key SASE capabilities - including ZTNA, secure web gateway, CASB, firewall-as-a-service, and SD-WAN - within a single cloud-delivered platform.
A shared policy framework sits at the centre of this architecture, allowing controls to be applied consistently across all users and traffic without needing to manage separate systems independently.
This combination of platform design and delivery approach provides a foundation that can perform consistently over time, rather than only at the point of implementation.


