Ask an IT team how their network is built and the answer is rarely 'to a plan'. It is usually the sum of decisions made across different years: a firewall here, an SD-WAN contract there, a VPN that was added in a hurry in 2020. Each piece solved a real problem at the time. Together they form something nobody would have designed on purpose.
In short. A fragmented network costs more than the invoices show: in patching, blind spots, policy that quietly drifts apart, and specialists switching between separate screens. SASE brings networking, security and remote access together on one platform. And you do not have to replace everything to get there. It can happen step by step.
Nobody designs a fragmented network. It just grows.
There was a time when it all still fit together. MPLS circuits matched a world of offices and datacenters. A firewall at the edge of the network made sense, because there was a clear edge. Then came the branches, the cloud, remote work. And with every shift the market bought a new tool: SD-WAN against the cost and rigidity of MPLS, remote access solutions that had to scale at speed in 2020, cloud security tools that followed the workloads.
Each tool is fine on its own. The problem is that they share nothing with each other: no data, no context, no common management. The network, security and remote access teams each look at their own system, without one shared picture of reality. And it is precisely in the space between those tools that the gaps appear.
The bill nobody budgets for
The licence costs are on the invoice. The real costs are not. They hide in the day-to-day work:
- Patching. Every device wants its own firmware updates. In an environment with dozens of sites and mixed versions, maintenance becomes a puzzle of its own.
- Blind spots. Separate tools each see only a slice. Following a problem from start to finish becomes guesswork the moment the tools do not know each other's data.
- Policy that drifts apart. Enforcing the same security rules everywhere takes manual work. That policy drifts unnoticed until an incident makes it visible.
- Knowledge in islands. Separate tools demand separate expertise. When an outage touches several systems, the fix too often depends on the one colleague who still knows it all.
- MPLS that keeps ticking. Legacy circuits do not get cheaper, while they fit cloud and distributed teams poorly. Traffic that first has to travel to a central point costs time and money.
None of these items appears as such in the budget. Together they are often larger than the visible vendor costs.
You are not paying for the tools you can see. You are paying for the space between them.
What SASE actually is
SASE (Secure Access Service Edge) brings SD-WAN, security and remote access together on one cloud-native platform. Not as a collection that happens to run side by side, but as a single whole that shares the same data layer, the same policy and the same management console.
That distinction matters. Some "SASE" platforms have been stitched together over the years through acquisitions, and only integrate at the management level. A platform brought together from the drawing board shares everything at the layer underneath. You only really notice that difference at the moment it counts.
Why one platform responds faster
Take a vulnerability like Log4Shell, which had half the world patching at the end of 2021. If your security is built from separate products, you then have to check each product for exposure and intervene everywhere separately. On a converged platform, the threat is recognised in one place, one detection is built for it, and it rolls out across every environment at once within days. That is the difference between security per device and security as a platform.
The path: no big bang, but step by step
The biggest misconception about SASE is that you have to replace your entire infrastructure for it. You do not. In practice, organisations grow into it in phases, usually along four steps that line up with moments that are already coming anyway.
- Start with remote access (ZTNA). Zero Trust Network Access is often the most tangible pain: slow VPNs, awkward management of external staff. It runs alongside your existing network, without changing anything about your current SD-WAN. Momentum itself runs Juniper SD-WAN at locations with Cato ZTNA for remote access.
- Refresh your SD-WAN at a natural moment. Is your SD-WAN contract up for renewal? Bring your branch connectivity onto the same platform as your remote access. A configuration change, not a rebuild.
- Consolidate your firewalls. When hardware is due for replacement anyway, move threat prevention into the platform and retire the separate on-site firewalls. Switched on through configuration.
- Full convergence. Networking, security, remote access and threat prevention under one policy engine, one management console, one data layer. The time that used to go into stitching tools together now goes to work that actually matters.
What to look for in a SASE platform
Not every platform called "SASE" also delivers its benefits. Watch for these points:
- One data plane. Networking, security and remote access share the same foundation, not just a shared dashboard.
- One policy engine. A rule you write once applies everywhere: sites, remote workers, cloud.
- One management console. The console reflects the real state of your network, and you resolve issues end to end in one place.
- Automatic updates. The platform updates everywhere at once. You are no longer responsible for patching individual appliances.
- Zero-touch rollout. A new location comes online remotely: preconfigured hardware connects and inherits the policy automatically.
The blind spot of the moment: AI
A new risk has appeared that most security tools do not yet see: the everyday use of AI. It plays out on two fronts. Employees paste sensitive information, contracts, figures, internal documents, into public AI tools, often through a personal account that bypasses corporate security entirely. And organisations deploy AI agents that act on their own and talk to other systems, with data flows that stay invisible to classic tools.
This is not a theoretical risk. The Cyberhaven 2026 AI Adoption and Risk Report finds that nearly 40% of all AI interactions inside organisations involve sensitive data. Classic DLP tools were simply not made for this. A converged platform can sit between the user and the AI tool: it reads the content of a prompt, recognises sensitive data and redacts it or blocks the request, with a notification to the user. We wrote earlier about why shadow AI is the new shadow IT.
The numbers behind the business case
A move to SASE is not a matter of comparing line item against line item, but of looking at the whole. The evidence is there. A Total Economic Impact study by Forrester Consulting (2026, commissioned by Cato Networks) lands at 235% ROI over three years and a payback period of less than six months. And the market is moving with it: Gartner expects the SASE market to grow around 26% a year to $28.5 billion by 2028, and that by then 70% of SD-WAN purchases will be part of a single-vendor SASE platform, up from 25% in 2025.
Where Momentum stands
Momentum is one of Cato Networks' most experienced global implementation partners. We deliver managed SASE, from a first ZTNA rollout to full consolidation, with an emphasis on distributed and international environments. The goal is simple: to let IT teams spend less time managing infrastructure and more on what moves the business forward.
A fragmented network is not a choice anyone made on purpose. Clearing it up is.
Sources: Forrester Consulting Total Economic Impact study (2026, commissioned by Cato Networks); Gartner SASE market forecasts; Cyberhaven 2026 AI Adoption and Risk Report.