Nearly three in four ransomware attacks in 2025 — 73% — started with a VPN, a share that has almost doubled in just two years. Combined with RDP, remote access tools now account for 87% of all ransomware claims. Edge devices and VPN concentrators went from 3% to 22% of breach-related exploitation in a single year — roughly an eightfold increase — and only 54% of vulnerable edge devices get fully remediated, with a median remediation time of 32 days. The device enterprises built to secure remote access has become one of the most common ways attackers get in.

This post continues Phase 4 after 4.0's overview and 4.1's Zero Trust foundation. Zero Trust said never trust, always verify. SASE — Secure Access Service Edge — is the network architecture that makes that principle operationally real at the edge, converging networking and security into a single cloud-delivered service rather than a rack of appliances in a data centre and a VPN client on every laptop.


What SASE Actually Replaces

The traditional enterprise network was built hub-and-spoke: branch offices and remote users connect back over MPLS or VPN to a central data centre, where a stack of firewalls, web gateways, and inspection appliances does the security work before traffic is allowed out to the internet or on to its destination. That model assumed most users sat in an office and most applications sat in a data centre the company owned. Neither assumption holds anymore — workloads run across multiple clouds, users connect from anywhere, and backhauling every request through a central hub adds latency for a workforce that increasingly has no central office to backhaul to.

The security consequence is what the VPN statistics above describe directly: a small number of internet-facing devices — VPN concentrators, firewalls, remote access gateways — became both the single point of entry for legitimate remote work and the single most attractive target for attackers, because compromising one device grants a path past the entire perimeter at once. SonicWall alone accounted for roughly a third of ransomware claims tied to VPN appliances in the most recent measurement, with a single ransomware group achieving dominance largely by systematically exploiting one vendor's appliances.

SASE's answer is to stop routing everything through a central hardware stack at all. Security and networking functions move to the cloud, delivered from points of presence close to wherever the user actually is, with policy enforced consistently regardless of whether that user is in a branch office, at home, or on a plane.


The Five Components SASE Converges

SASE is not a single product — it's the convergence of five previously separate functions into one cloud-delivered architecture:

SD-WAN. Software-defined wide-area networking replaces static MPLS circuits with intelligent, application-aware routing across whatever connections are available — broadband, LTE, or MPLS where it still makes sense — instead of paying premium prices to backhaul all traffic through a private circuit.

Secure Web Gateway (SWG). Inspects and filters internet-bound traffic for malware, policy violations, and data loss, wherever the user connects from — the cloud-delivered equivalent of the appliance that used to sit at the data centre edge.

Cloud Access Security Broker (CASB). Extends visibility and policy enforcement into SaaS and cloud application usage — the layer that answers "what is actually happening inside Salesforce, Microsoft 365, and the dozens of other SaaS tools employees use" rather than just what crosses the network edge.

Zero Trust Network Access (ZTNA). The direct architectural link back to Post 4.1 — replacing full network-level VPN access with per-application, identity-verified access that never puts a remote user directly on the internal network at all. This is arguably the single component most responsible for closing the VPN-as-attack-vector problem, because there is no longer a flat network to gain a foothold on.

Firewall as a Service (FWaaS). Delivers firewall inspection and policy enforcement from the cloud rather than physical or virtual appliances at every location, so policy is defined once and applied everywhere consistently.

Gartner projects that 45% of enterprises will adopt managed SASE services by 2026, with spending on the category growing at roughly 36% annually between 2020 and 2025 — far outpacing growth in information security spending overall. That gap between SASE's growth rate and the broader security market's growth rate is itself a signal: organisations are not simply adding SASE as one more tool, they are actively replacing the hub-and-spoke architecture underneath it.


Why the Convergence Is Harder Than It Sounds

The technology exists, largely mature, from a genuinely crowded field of vendors. The harder part is organisational, not technical. Networking and security have historically been separate teams with separate budgets, separate KPIs, and often separate reporting lines — a networking team measured on uptime and latency, a security team measured on risk reduction and incident response. SASE forces those two functions to converge architecturally, which means it also forces the two teams responsible for them to converge operationally, and most enterprises have not restructured around that reality yet.

There is also a genuine single-vendor-versus-best-of-breed decision underneath the adoption numbers. A single-vendor SASE platform is simpler to deploy and manage, with one policy engine and one support relationship — but it means betting the entire converged stack on one vendor's execution across five previously distinct product categories, several of which that vendor may not have originally built in-house. A best-of-breed approach preserves optionality in each layer but reintroduces the integration overhead SASE was supposed to eliminate in the first place. Neither answer is universally correct — it depends on how much organisational appetite exists for vendor consolidation risk versus integration complexity.


What This Means for Every IT Leader

1. If your VPN concentrator were compromised tomorrow, what would an attacker actually be able to reach? If the honest answer is "the internal network," you have a flat-network problem that ZTNA is specifically designed to solve — per-application access, not network-level access, closes exactly the gap that made VPNs the leading ransomware entry point in 2025.

2. Who owns the SASE decision in your organisation — networking, security, or neither yet? If no one has clear ownership, that's the real blocker, not the vendor selection. The technology decision is usually easier than the organisational one underneath it.

3. Are you evaluating SASE vendors on the full five-component convergence, or on whichever single component your last RFP happened to be about? A vendor that's genuinely strong at SD-WAN and weak at ZTNA is not a SASE platform — it's a networking vendor with a security feature bolted on, which is close to the same problem SASE was meant to solve in the first place.


The Bottom Line

The VPN statistics in this post aren't a coincidence sitting next to the SASE adoption numbers — they're cause and effect. A flat network reachable through one internet-facing device was always going to be the path of least resistance for attackers, and 2025's numbers confirm it decisively. SASE isn't a rebrand of existing network security tools; it's the architectural response to the same problem Zero Trust addresses at the identity layer, applied to the network itself.

The organisations getting real value from it are the ones treating the networking-and-security team convergence as seriously as the technology convergence — because a fully deployed SASE platform managed by two teams that still don't talk to each other is just an expensive way to keep the old organisational problem.

Sources: Verizon 2025 Data Breach Investigations Report, At-Bay VPN Ransomware Risk Report, 2026, Gartner SASE market and adoption forecasts.