Network Architecture for Modern Enterprises: SD-WAN, SASE, and Zero Trust Access

Table of Contents

Network Architecture for Modern Enterprises: SD-WAN, SASE, and Zero Trust Access

Companies that operate today with distributed teams, cloud services, and hybrid work models quickly reach the limits of traditional network architectures. SD-WAN, SASE, and Zero Trust Network Access (ZTNA) are not just buzzwords, but concrete solutions to real-world demands for performance, security, and scalability. This article explains what lies behind these concepts, why network modernization is becoming a strategic necessity for midsize companies—and what the path to achieving it looks like.


Why Traditional Network Architectures Are Reaching Their Limits

Traditional corporate networks were built for a world in which employees work from a fixed location, applications run in the company’s own data center, and all data traffic flows through a central location. This architecture—often based on MPLS links—is expensive to procure, difficult to scale, and slow to adapt to change.

With the growth of cloud services such as Microsoft 365, Salesforce, and SAP S/4HANA, and the widespread adoption of remote work models, the reality has shifted fundamentally. Data traffic that used to remain internal now travels over the open Internet—and traditional perimeter security models are no longer reliable in this context.

According to Gartner, by the end of 2026, more than 60 percent of companies will be using SASE architectures in some form—up from less than 10 percent in 2020. This trend is reflected in real-world practice: IT decision-makers are increasingly reporting that traditional VPN infrastructures are no longer capable of handling the demands of remote work scenarios and cloud-first strategies.


SD-WAN: Intelligent Control of Network Traffic

SD-WAN (Software-Defined Wide Area Network) eliminates the rigid reliance on expensive dedicated lines. Instead, network control is abstracted through software—multiple connection types (MPLS, broadband Internet, LTE/5G) can be used simultaneously and intelligently distributed based on load, quality, and priority.

An Overview of the Benefits of SD-WAN

  • Cost-effectiveness: More affordable Internet lines can partially or completely replace MPLS connections
  • Flexibility: New locations can be connected quickly without the need for time-consuming line orders
  • Reliability: Automatic failover between connections minimizes downtime
  • Prioritization: Critical applications such as VoIP or ERP systems receive priority bandwidth
  • Visibility: Central dashboards display the status of all locations in real time

SD-WAN thus provides the infrastructural foundation for modern, distributed enterprise networks—but on its own, it is not a comprehensive security solution.


SASE: When Networking and Security Converge

SASE (Secure Access Service Edge) takes it a step further. This concept, coined by Gartner, combines network functions (particularly SD-WAN) with comprehensive security services—and delivers both as a cloud-based platform. SASE is therefore not a single product, but an architectural principle.

The core components of a SASE architecture include:

  • SD-WAN as a Network Layer
  • Cloud Access Security Broker (CASB) for Managing Cloud Services
  • Secure Web Gateway (SWG) for Protection Against Web-Based Threats
  • Firewall as a Service (FWaaS) as a centrally managed firewall function
  • Zero Trust Network Access (ZTNA) as a Modern Access Model

SASE offers significant advantages, particularly for companies with remote work networks—that is, distributed teams, work-from-home arrangements, and locations without their own IT infrastructure: Security functions are delivered not at the edge of the data center, but close to the user, regardless of where the user is located.

The axsos approach is based on the principle that security must go where the users are—not the other way around.


Zero Trust Network Access: The End of Trust Itself

The classic VPN model is based on a simple but dangerous logic: Anyone who has authenticated themselves is allowed into the network. Once inside, the user—or an attacker who has compromised the user’s credentials—can move about largely freely.

ZTNA (Zero Trust Network Access) breaks with this principle. Instead of blanket network access, each user is granted access only to the applications they actually need for their role—and only after continuous verification.

Basic Principles of ZTNA

  1. Never trust, always verify —Every request is re-authenticated and re-authorized
  2. Minimal Permission Assignment – Users are granted only the permissions necessary for their task
  3. Microsegmentation – The network is divided into small, isolated segments
  4. Context-Sensitive Access Decisions – Device status, location, and behavior patterns are factored into the decision

This model significantly reduces the attack surface. Even if an account is compromised, the potential damage is limited to the specific area of access. For more information on the zero-trust philosophy and its technical implementation, see our article on the zero-trust architectural principle.


SASE in Small and Medium-Sized Businesses: Opportunities and Realism

SASE for SMEs —at first glance, this combination sounds like enterprise technology for large corporations. In fact, the opposite is true: SMEs in particular benefit disproportionately from SASE because they generally cannot maintain a large in-house security team but still have to contend with the same threats as larger organizations.

SASE platforms are typically available on a modular basis and scale with the business. This lowers the barrier to entry. However, it is important to have a realistic understanding: Implementing SASE is not like flipping an on/off switch. It requires a thorough assessment of the existing infrastructure, clear requirements for applications and user groups, and a structured migration strategy.

Typical steps in a network modernization project for small and medium-sized businesses:

  1. Inventory – What locations, user groups, applications, and data streams exist?
  2. Prioritization – Where does the current architecture cause the most pain?
  3. Pilot Project – Implement SASE components (e.g., ZTNA instead of VPN) at a single location or for a specific user group
  4. Gradual Migration – Successively Replacing Outdated Components Without Compromising Day-to-Day Operations
  5. Operations & Monitoring – Continuous Monitoring of Configurations and Access Patterns

Interplay: SD-WAN SASE Network Architecture as an Overall Concept

SD-WAN, SASE, and ZTNA are not competing concepts—they complement each other. SD-WAN provides the network infrastructure, SASE provides the overarching security and control platform, and ZTNA provides the fine-grained access model.

For companies that are also adopting hybrid cloud strategies, this creates a cohesive infrastructure: locations are flexibly connected, cloud services are accessible directly and securely, remote users are granted access based on context—and the IT department retains control from a central location.


Safety as an integral part

A common mistake in network modernizations: Security is treated as an afterthought. Existing perimeters are expanded, VPN capacities are scaled up—and the underlying architecture remains untouched.

SASE and ZTNA require a different mindset: Security is not an afterthought, but an integral part of every networking decision. This also applies to related areas: Backup concepts, recovery strategies, and ransomware protection must be consistently aligned with these new architectures. For more information on these topics, see our articles on backup, immutable storage, and recovery strategies, as well as on cybersecurity and ransomware prevention for SMBs.


FAQ: SD-WAN, SASE, and Zero Trust

What is the difference between SD-WAN and SASE?

SD-WAN is a technology for the flexible management of WAN connections—it focuses primarily on network performance and efficiency. SASE is a comprehensive architectural concept that combines SD-WAN with security services (CASB, SWG, ZTNA, FWaaS) in a cloud-based platform. SD-WAN can be part of a SASE architecture, but SASE is more than just SD-WAN.

Is ZTNA a complete replacement for a VPN?

ZTNA can replace VPN in many use cases—particularly when remote employees access specific enterprise applications. However, there are scenarios where full network visibility is required (e.g., for legacy systems or certain network operations) that still necessitate the use of VPN today. The migration should therefore be carefully planned and carried out in phases.

How long does it take to implement SASE in a small-to-medium-sized business?

That depends heavily on the existing infrastructure and the scope of the migration. Initial components—such as ZTNA as a replacement for VPN—can be piloted in a matter of weeks. A full SASE migration in a company with multiple locations and complex dependencies can take six to twelve months. It is important to take a phased approach that does not disrupt ongoing operations.


This content was generated using AI, but was reviewed and edited by our editorial team before publication.

Share:

Scroll up

Jamil Isayyed

Jamil is an experienced digital process professional, has a rich international background in the information technology and services industry spanning Germany, Greece and Palestine. He holds a Bachelor's degree in Computer Science and a Scrum Master certification from the Scrum Alliance with a focus on Computer Software Engineering. Jamil is passionate about leading and building high-performance teams that deliver exceptional experiences and create valuable opportunities for clients. In addition to his main role, he is the Director of Axsos Academy GmbH. In this role, he leads a dynamic German-Palestinian bootcamp designed to help young people enter the IT market and build a successful career.

Bernd Length

Bernd Länge has been working in the IT industry for over 20 years and advises clients and interested parties on cyber security issues as well as on the development and implementation of information security management and data protection. In this role, he acts as an external data protection and information security officer for clients. It is important to him to take a pragmatic approach and work closely with clients, partners and vendors to ensure that clients' enterprise security is up to date.

Martin Müller

As a technology enthusiast and committed leader, he has been helping companies in the IT sector to shape the future of work for over 20 years. Thanks to his quick thinking and ability to develop effective solutions, he is able to formulate a clear vision of what our future way of working will look like. Step by step, he overcomes challenges and drives us forward into the future. However, he does not accomplish these tasks alone. He has a competent team that he trusts completely and can rely on. Together they overcome every hurdle! Through positive, critical thinking, the second-best solution often leads to incremental success - after all, even an empire wasn't built in a day. This approach makes him unique in his role and he looks forward to working with you on the path to the future.

Rolf Stephan

His enthusiasm for information technology led Rolf to study computer science and graduate from the University of Karlsruhe, now the KIT / Karlsruhe Institute of Technology. Rolf has been working in the IT sector ever since and knows the industry inside out - both nationally and internationally. For more than 25 years, he has focused on international cooperation between experts across all cultures. He also pursued this approach in the first company he founded, AD Solutions AG, which quickly developed into a renowned international IT service provider with several branches in Germany, Switzerland, Austria and the USA. Rolf Stephan has been General Manager since 2010 and CEO of AXON IVY AG, headquartered in Switzerland, since 2021. He has been an investor, shareholder and Chairman of the Supervisory Board of Axsos AG since 2009.

Frank Müller

Frank is a passionate IT expert and visionary entrepreneur. He loves and believes in peace and freedom. For him, these values are more than just words. They are the result of great awareness, responsibility and a solid foundation. His foundation is his faith in Jesus and his unconditional love for people. Frank builds his great visions on this foundation, such as his commitment to peace in the Holy Land. He is not afraid to realize creative and unconventional ideas, such as founding a medium-sized company that spans four countries and cultures and offers its employees a great deal of freedom. Founding a bootcamp academy in the midst of the coronavirus pandemic is certainly one of these ventures. Through these efforts, Frank creates new innovations and added value for his customers and the people who travel with him. With more than 32 years of IT experience and 15 years as an entrepreneur, Frank helps other entrepreneurs focus on their core business and translate their needs into technology opportunities and implementations. His team and he can translate these requirements into a customized IT strategy, processes and technologies. Frank always has a heart for the people he supports and wants to encourage them to break new ground and develop their potential. Frank is open to exchanging ideas with people who see values not as CSR or marketing chatter, but as the basis of their actions. He seeks contact with people who want to change the world for the better. He also welcomes those who are looking for support from him or his team on their journey into the cloud, digitalization or the use of AI.