Distributed and hybrid working broke the classic perimeter. What was the first, cautious reaction — and what does it cost?
Expand the inside: give the network virtual overlays and add-ons so the perimeter is restored at large scale (a "macro-perimeter") — from a simple VPN up to routing all traffic through a cloud provider's edge (SASE). The price is being locked into the private network, with public services unable to take part.
* The border is rebuilt at scale — and everything public stays outside it. *
The pressure came from the business: remote access, every IT thing needing to reach the web, services, cloud services, digitalisation in general. Cyber systems stretch out, there is more interaction, and the business demands distributed environments. The consequence for the border is severe — inside and outside mix, good and bad interactions look more and more alike, and setting up a perimeter becomes ever more complex, to the point of not being definable at all.
Reaction 1 keeps the paradigm and enlarges its scope:
- The network receives virtual overlays and add-ons, and still plays an important role in defining the system boundary.
- The range runs from a simple VPN — a remote laptop pulled logically inside — through decentralised data centres and private cloud, up to SASE (Secure Access Service Edge), where any traffic is routed through a cloud provider's virtual macro-perimeter.
What you gain and what you pay:
| Gain | The perimeter is restored on a large scale; the familiar model keeps working for a distributed estate |
| Cost 1 | Finding suitable smart security tools can be hard — especially for on-premises, since the cloud world is young and still moving |
| Cost 2 | You take part in the new cloud world only partly: locked in to the private network, and public services cannot participate |
That last row is the structural limit. A macro-perimeter can absorb your own remote users and your own data centres; it cannot absorb a public SaaS product that the outside world also uses. When the business wants exactly that, this approach has reached its edge — which is what forces the next one.
Go deeper:
Wikipedia — Secure access service edge — the cloud-delivered version of this idea, and where the term came from.