Network Architecture for Modern Enterprises: SD-WAN, SASE, and Zero Trust Access
Companies that operate today with distributed teams, cloud services, and hybrid work models quickly reach the limits of traditional network architectures. SD-WAN, SASE, and Zero Trust Network Access (ZTNA) are not just buzzwords, but concrete solutions to real-world demands for performance, security, and scalability. This article explains what lies behind these concepts, why network modernization is becoming a strategic necessity for midsize companies—and what the path to achieving it looks like.
Why Traditional Network Architectures Are Reaching Their Limits
Traditional corporate networks were built for a world in which employees work from a fixed location, applications run in the company’s own data center, and all data traffic flows through a central location. This architecture—often based on MPLS links—is expensive to procure, difficult to scale, and slow to adapt to change.
With the growth of cloud services such as Microsoft 365, Salesforce, and SAP S/4HANA, and the widespread adoption of remote work models, the reality has shifted fundamentally. Data traffic that used to remain internal now travels over the open Internet—and traditional perimeter security models are no longer reliable in this context.
According to Gartner, by the end of 2026, more than 60 percent of companies will be using SASE architectures in some form—up from less than 10 percent in 2020. This trend is reflected in real-world practice: IT decision-makers are increasingly reporting that traditional VPN infrastructures are no longer capable of handling the demands of remote work scenarios and cloud-first strategies.
SD-WAN: Intelligent Control of Network Traffic
SD-WAN (Software-Defined Wide Area Network) eliminates the rigid reliance on expensive dedicated lines. Instead, network control is abstracted through software—multiple connection types (MPLS, broadband Internet, LTE/5G) can be used simultaneously and intelligently distributed based on load, quality, and priority.
An Overview of the Benefits of SD-WAN
- Cost-effectiveness: More affordable Internet lines can partially or completely replace MPLS connections
- Flexibility: New locations can be connected quickly without the need for time-consuming line orders
- Reliability: Automatic failover between connections minimizes downtime
- Prioritization: Critical applications such as VoIP or ERP systems receive priority bandwidth
- Visibility: Central dashboards display the status of all locations in real time
SD-WAN thus provides the infrastructural foundation for modern, distributed enterprise networks—but on its own, it is not a comprehensive security solution.
SASE: When Networking and Security Converge
SASE (Secure Access Service Edge) takes it a step further. This concept, coined by Gartner, combines network functions (particularly SD-WAN) with comprehensive security services—and delivers both as a cloud-based platform. SASE is therefore not a single product, but an architectural principle.
The core components of a SASE architecture include:
- SD-WAN as a Network Layer
- Cloud Access Security Broker (CASB) for Managing Cloud Services
- Secure Web Gateway (SWG) for Protection Against Web-Based Threats
- Firewall as a Service (FWaaS) as a centrally managed firewall function
- Zero Trust Network Access (ZTNA) as a Modern Access Model
SASE offers significant advantages, particularly for companies with remote work networks—that is, distributed teams, work-from-home arrangements, and locations without their own IT infrastructure: Security functions are delivered not at the edge of the data center, but close to the user, regardless of where the user is located.
The axsos approach is based on the principle that security must go where the users are—not the other way around.
Zero Trust Network Access: The End of Trust Itself
The classic VPN model is based on a simple but dangerous logic: Anyone who has authenticated themselves is allowed into the network. Once inside, the user—or an attacker who has compromised the user’s credentials—can move about largely freely.
ZTNA (Zero Trust Network Access) breaks with this principle. Instead of blanket network access, each user is granted access only to the applications they actually need for their role—and only after continuous verification.
Basic Principles of ZTNA
- Never trust, always verify —Every request is re-authenticated and re-authorized
- Minimal Permission Assignment – Users are granted only the permissions necessary for their task
- Microsegmentation – The network is divided into small, isolated segments
- Context-Sensitive Access Decisions – Device status, location, and behavior patterns are factored into the decision
This model significantly reduces the attack surface. Even if an account is compromised, the potential damage is limited to the specific area of access. For more information on the zero-trust philosophy and its technical implementation, see our article on the zero-trust architectural principle.
SASE in Small and Medium-Sized Businesses: Opportunities and Realism
SASE for SMEs —at first glance, this combination sounds like enterprise technology for large corporations. In fact, the opposite is true: SMEs in particular benefit disproportionately from SASE because they generally cannot maintain a large in-house security team but still have to contend with the same threats as larger organizations.
SASE platforms are typically available on a modular basis and scale with the business. This lowers the barrier to entry. However, it is important to have a realistic understanding: Implementing SASE is not like flipping an on/off switch. It requires a thorough assessment of the existing infrastructure, clear requirements for applications and user groups, and a structured migration strategy.
Typical steps in a network modernization project for small and medium-sized businesses:
- Inventory – What locations, user groups, applications, and data streams exist?
- Prioritization – Where does the current architecture cause the most pain?
- Pilot Project – Implement SASE components (e.g., ZTNA instead of VPN) at a single location or for a specific user group
- Gradual Migration – Successively Replacing Outdated Components Without Compromising Day-to-Day Operations
- Operations & Monitoring – Continuous Monitoring of Configurations and Access Patterns
Interplay: SD-WAN SASE Network Architecture as an Overall Concept
SD-WAN, SASE, and ZTNA are not competing concepts—they complement each other. SD-WAN provides the network infrastructure, SASE provides the overarching security and control platform, and ZTNA provides the fine-grained access model.
For companies that are also adopting hybrid cloud strategies, this creates a cohesive infrastructure: locations are flexibly connected, cloud services are accessible directly and securely, remote users are granted access based on context—and the IT department retains control from a central location.
Safety as an integral part
A common mistake in network modernizations: Security is treated as an afterthought. Existing perimeters are expanded, VPN capacities are scaled up—and the underlying architecture remains untouched.
SASE and ZTNA require a different mindset: Security is not an afterthought, but an integral part of every networking decision. This also applies to related areas: Backup concepts, recovery strategies, and ransomware protection must be consistently aligned with these new architectures. For more information on these topics, see our articles on backup, immutable storage, and recovery strategies, as well as on cybersecurity and ransomware prevention for SMBs.
FAQ: SD-WAN, SASE, and Zero Trust
What is the difference between SD-WAN and SASE?
SD-WAN is a technology for the flexible management of WAN connections—it focuses primarily on network performance and efficiency. SASE is a comprehensive architectural concept that combines SD-WAN with security services (CASB, SWG, ZTNA, FWaaS) in a cloud-based platform. SD-WAN can be part of a SASE architecture, but SASE is more than just SD-WAN.
Is ZTNA a complete replacement for a VPN?
ZTNA can replace VPN in many use cases—particularly when remote employees access specific enterprise applications. However, there are scenarios where full network visibility is required (e.g., for legacy systems or certain network operations) that still necessitate the use of VPN today. The migration should therefore be carefully planned and carried out in phases.
How long does it take to implement SASE in a small-to-medium-sized business?
That depends heavily on the existing infrastructure and the scope of the migration. Initial components—such as ZTNA as a replacement for VPN—can be piloted in a matter of weeks. A full SASE migration in a company with multiple locations and complex dependencies can take six to twelve months. It is important to take a phased approach that does not disrupt ongoing operations.
This content was generated using AI, but was reviewed and edited by our editorial team before publication.