By Jaye Tillson, Field CTO, Distinguished Technologist, HPE Aruba Networking
The traditional castle-and-moat approach to network security which relies solely on a fortified perimeter to keep intruders at bay is crumbling in the face of a modern digital landscape. Cloud adoption, the explosion of the hybrid workforce, and the ever-growing number of Internet of Things (IoT) devices have rendered the static perimeter obsolete.
This necessitates a more comprehensive security strategy, one that can adapt to the dynamic nature of today’s IT environment. Enter Secure Access Service Edge (SASE) and its potential evolution into Universal ZTNA, offering a more robust and holistic approach to securing our digital assets.
SASE: A Strong Foundation
SASE emerged as a revolutionary concept, converging critical networking and security functions like SD-WAN, ZTNA, SWG, CASB, and DEM into a single, cloud-delivered service. This approach undoubtedly simplifies security for remote users by providing a centralized platform for managing access and enforcing policies.
However, SASE has limitations. Its primary focus lies in securing access for users outside the traditional network perimeter. This leaves on-premises users, devices, and the ever-expanding universe of IoT endpoints potentially exposed, creating security vulnerabilities within the very walls of the digital castle.
Universal ZTNA: Extending the Secure Umbrella
Universal ZTNA builds upon the core principles of SASE, particularly ZTNA (Zero Trust Network Access). ZTNA enforces the principle of least privilege access, granting temporary connections only to authorized users and applications, regardless of location. This approach fundamentally breaks away from the outdated assumption of implicit trust within the network perimeter.
Universal ZTNA takes this philosophy a step further. It extends the zero-trust principles beyond just securing remote access, applying them to all users, devices, and IoT endpoints attempting to access the network, on-premises or otherwise.
This holistic approach significantly shrinks the attack surface by eliminating the concept of implicit trust. Every connection, regardless of its origin, requires continuous verification and authorization. Imagine a world where every visitor to the castle, from a trusted knight to a visiting merchant, undergoes the same rigorous identity check before being granted access.
The Inevitable Transformation: From SASE to Universal ZTNA
While SASE offers a robust architecture, its primary focus remains securing user access from outside the network. Here’s how SASE can potentially evolve towards a more comprehensive Universal ZTNA model:
- Unified Policy Management: Universal ZTNA goes beyond SASE by extending its centralized policy engine to manage access control for all users and devices across the entire IT landscape. This includes both on-premises and cloud-based resources, ensuring consistent and comprehensive security enforcement regardless of location. Imagine a single set of security protocols governing everyone within the castle walls, from the highest-ranking official to the newest recruit.
- Zero Trust Everywhere: The core ZTNA principle of “never trust, always verify” becomes the guiding principle for all access attempts. This eliminates the inherent risk associated with assuming trust based solely on a user’s location or device type. In a Universal ZTNA environment, every attempt to access the castle, from the main gate to a hidden passage, requires proper identification and authorization.
- Identity as the Anchor: Strong and centralized identity and access management (IAM) becomes even more critical in a Universal ZTNA environment. SASE’s existing IAM capabilities can be leveraged as a foundation upon which to build a more robust and comprehensive identity verification system. Just as a strong gatekeeper protects the castle, a robust IAM system serves as the first line of defense in a Universal ZTNA environment, ensuring only authorized individuals with the proper credentials gain access.
The Road Ahead: A Future Secured by Ubiquitous Zero Trust
The security industry is still refining the exact parameters of Universal ZTNA. However, its unwavering focus on zero-trust principles positions it as a potential successor, or at least a significant evolution, of SASE. Organizations can leverage SASE as a stepping stone, adopting its ZTNA features and strengthening their IAM capabilities to prepare for a future secured by Universal ZTNA.
One thing remains certain: the days of relying solely on a secure network perimeter are over. The move towards Universal ZTNA signifies a shift towards a more comprehensive security posture, one that extends its protective umbrella to encompass users, devices, and IoT endpoints wherever they reside.
This is not about building higher castle walls, but about implementing a system of constant vigilance and verification, ensuring only authorized individuals gain access to our digital treasures.
##
ABOUT THE AUTHOR

Jaye Tillson, Field CTO and Distinguished Technologist – Security at HPE brings over 25 years of invaluable expertise in successfully implementing strategic global technology programs. With a keen focus on digital transformation, Jaye has been pivotal in guiding numerous organizations through their zero-trust journey, enabling them to flourish in today’s dynamic digital landscape. His passion lies in collaborating with enterprises, aiding them in their strategic pursuit of zero trust. Jaye takes pride in applying his real-world experience to tackle critical issues and challenges faced by these businesses.
As a renowned expert in the field, Jaye has showcased his thought leadership at prestigious industry conferences such as Gartner, VMWorld, Evanta, IDC, and .Next. Further validating his expertise, he participates on advisor boards for leading companies including VMware, Nutanix, CIOnet, and Proofpoint.
Jaye is also the co-founder of the SSE Forum and co-host of its popular podcast, ‘The Edge,’ where he delves into topics such as cybersecurity, the role of the CISO, SASE, SSE, and Zero Trust. This platform allows him to engage with a wider audience, fostering meaningful discussions on industry trends and innovations.
Additionally, Jaye actively contributes as a member of the CSA Zero Trust Working Group, serves as a board member of the CSA UK Chapter, and acts as an Advisor for Infosec.live.
During his leisure time, Jaye indulges in his passions for motor racing, relishing delectable cuisine, and exploring the wonders of the world through travel.
For more information, visit his website at https://jayetillson.tech/.





