Secure

From a fragmented network to one SASE platform

Most networks were not designed, they accumulated. What that fragmentation really costs, and how to unwind it step by step.

  • Jan Marsman
  • 26 August 2026
  • 7 min read

Ask an IT team how their network is built and the answer is rarely 'to a plan'. It is usually the sum of decisions made across different years: a firewall here, an SD-WAN contract there, a VPN that was added in a hurry in 2020. Each piece solved a real problem at the time. Together they form something nobody would have designed on purpose.

In short. A fragmented network costs more than the invoices show: in patching, blind spots, policy that quietly drifts apart, and specialists switching between separate screens. SASE brings networking, security and remote access together on one platform. And you do not have to replace everything to get there. It can happen step by step.

Nobody designs a fragmented network. It just grows.

There was a time when it all still fit together. MPLS circuits matched a world of offices and datacenters. A firewall at the edge of the network made sense, because there was a clear edge. Then came the branches, the cloud, remote work. And with every shift the market bought a new tool: SD-WAN against the cost and rigidity of MPLS, remote access solutions that had to scale at speed in 2020, cloud security tools that followed the workloads.

Each tool is fine on its own. The problem is that they share nothing with each other: no data, no context, no common management. The network, security and remote access teams each look at their own system, without one shared picture of reality. And it is precisely in the space between those tools that the gaps appear.

The bill nobody budgets for

The licence costs are on the invoice. The real costs are not. They hide in the day-to-day work:

  • Patching. Every device wants its own firmware updates. In an environment with dozens of sites and mixed versions, maintenance becomes a puzzle of its own.
  • Blind spots. Separate tools each see only a slice. Following a problem from start to finish becomes guesswork the moment the tools do not know each other's data.
  • Policy that drifts apart. Enforcing the same security rules everywhere takes manual work. That policy drifts unnoticed until an incident makes it visible.
  • Knowledge in islands. Separate tools demand separate expertise. When an outage touches several systems, the fix too often depends on the one colleague who still knows it all.
  • MPLS that keeps ticking. Legacy circuits do not get cheaper, while they fit cloud and distributed teams poorly. Traffic that first has to travel to a central point costs time and money.

None of these items appears as such in the budget. Together they are often larger than the visible vendor costs.

You are not paying for the tools you can see. You are paying for the space between them.

Jan MarsmanJan Marsman, Senior Solution Architect Cyber Security EMEA

What SASE actually is

SASE (Secure Access Service Edge) brings SD-WAN, security and remote access together on one cloud-native platform. Not as a collection that happens to run side by side, but as a single whole that shares the same data layer, the same policy and the same management console.

That distinction matters. Some "SASE" platforms have been stitched together over the years through acquisitions, and only integrate at the management level. A platform brought together from the drawing board shares everything at the layer underneath. You only really notice that difference at the moment it counts.

Why one platform responds faster

Take a vulnerability like Log4Shell, which had half the world patching at the end of 2021. If your security is built from separate products, you then have to check each product for exposure and intervene everywhere separately. On a converged platform, the threat is recognised in one place, one detection is built for it, and it rolls out across every environment at once within days. That is the difference between security per device and security as a platform.

The path: no big bang, but step by step

The biggest misconception about SASE is that you have to replace your entire infrastructure for it. You do not. In practice, organisations grow into it in phases, usually along four steps that line up with moments that are already coming anyway.

  1. Start with remote access (ZTNA). Zero Trust Network Access is often the most tangible pain: slow VPNs, awkward management of external staff. It runs alongside your existing network, without changing anything about your current SD-WAN. Momentum itself runs Juniper SD-WAN at locations with Cato ZTNA for remote access.
  2. Refresh your SD-WAN at a natural moment. Is your SD-WAN contract up for renewal? Bring your branch connectivity onto the same platform as your remote access. A configuration change, not a rebuild.
  3. Consolidate your firewalls. When hardware is due for replacement anyway, move threat prevention into the platform and retire the separate on-site firewalls. Switched on through configuration.
  4. Full convergence. Networking, security, remote access and threat prevention under one policy engine, one management console, one data layer. The time that used to go into stitching tools together now goes to work that actually matters.

What to look for in a SASE platform

Not every platform called "SASE" also delivers its benefits. Watch for these points:

  • One data plane. Networking, security and remote access share the same foundation, not just a shared dashboard.
  • One policy engine. A rule you write once applies everywhere: sites, remote workers, cloud.
  • One management console. The console reflects the real state of your network, and you resolve issues end to end in one place.
  • Automatic updates. The platform updates everywhere at once. You are no longer responsible for patching individual appliances.
  • Zero-touch rollout. A new location comes online remotely: preconfigured hardware connects and inherits the policy automatically.

The blind spot of the moment: AI

A new risk has appeared that most security tools do not yet see: the everyday use of AI. It plays out on two fronts. Employees paste sensitive information, contracts, figures, internal documents, into public AI tools, often through a personal account that bypasses corporate security entirely. And organisations deploy AI agents that act on their own and talk to other systems, with data flows that stay invisible to classic tools.

This is not a theoretical risk. The Cyberhaven 2026 AI Adoption and Risk Report finds that nearly 40% of all AI interactions inside organisations involve sensitive data. Classic DLP tools were simply not made for this. A converged platform can sit between the user and the AI tool: it reads the content of a prompt, recognises sensitive data and redacts it or blocks the request, with a notification to the user. We wrote earlier about why shadow AI is the new shadow IT.

The numbers behind the business case

A move to SASE is not a matter of comparing line item against line item, but of looking at the whole. The evidence is there. A Total Economic Impact study by Forrester Consulting (2026, commissioned by Cato Networks) lands at 235% ROI over three years and a payback period of less than six months. And the market is moving with it: Gartner expects the SASE market to grow around 26% a year to $28.5 billion by 2028, and that by then 70% of SD-WAN purchases will be part of a single-vendor SASE platform, up from 25% in 2025.

Where Momentum stands

Momentum is one of Cato Networks' most experienced global implementation partners. We deliver managed SASE, from a first ZTNA rollout to full consolidation, with an emphasis on distributed and international environments. The goal is simple: to let IT teams spend less time managing infrastructure and more on what moves the business forward.

A fragmented network is not a choice anyone made on purpose. Clearing it up is.

Sources: Forrester Consulting Total Economic Impact study (2026, commissioned by Cato Networks); Gartner SASE market forecasts; Cyberhaven 2026 AI Adoption and Risk Report.

FAQ

Questions we get asked

What is SASE?

SASE (Secure Access Service Edge) brings SD-WAN, security and remote access together on one cloud-native platform that shares the same data layer, the same policy and the same management console, instead of separate tools running side by side.

Do I have to replace my whole network at once for SASE?

No. Most organisations grow into it in phases: first remote access (ZTNA) alongside the existing network, then SD-WAN at contract renewal, then firewall consolidation at hardware replacement, and finally full convergence.

What are the hidden costs of a fragmented network?

Among others: recurring per-device patching, blind spots when tracing problems, security policy that drifts apart unnoticed, knowledge stuck in islands, and MPLS costs that keep climbing. Together often larger than the visible licence costs.

Does SASE help against AI-related risks?

Yes. A converged platform can sit between the user and an AI tool, inspect the content of a prompt and redact or block sensitive data, something classic DLP tools were not built for.

Talk to us

A practical path to SASE for your network

Curious what a phased move looks like for your organisation? Book a call with a Momentum network specialist and we will map out the first step together.