Network Security and SASE
Network security is the oldest product pool in cybersecurity, anchored by the firewall, and is being re-platformed into a cloud-delivered edge (SASE). The central question in the category is whether the incumbents that own the on-premise appliance can carry that franchise into the cloud ahead of the cloud-native challengers.
What network security and SASE cover
Network security controls traffic between users, applications, and the internet. It spans three layers that are converging into one:
- Firewall / NGFW (the appliance): the hardware (and increasingly virtual) box at the network perimeter that inspects and filters traffic. The original cyber product category and still the largest single hardware-plus-software pool. Refresh-cycle and footprint-driven; high gross margin on the software/subscription attach.
- Secure Web Gateway, ZTNA, CASB, FWaaS (the cloud controls): the four cloud-delivered functions — web filtering, zero-trust application access, cloud-app control, and firewall-as-a-service — that replace the appliance for a remote-first workforce.
- SD-WAN + the security stack = SASE: Gartner's 2019 coinage for the convergence of software-defined WAN (networking) with the cloud security stack (SSE) into a single cloud-delivered edge. SASE = SD-WAN + SSE. When sold as security only (no WAN), the same stack is SSE.
SASE is the category where networking and security converge, and where the buyer consolidates four-to-six vendors into one. That makes it the largest consolidation opportunity in infrastructure security, and the reason every platform vendor (Palo Alto, Cisco, Fortinet, Zscaler) competes for it. The vendor that owns the edge owns the inline choke point through which all traffic — and therefore all future inspection, DLP, and AI-traffic governance — must pass.
How the vendors make money and how they differ
| Vendor | Owner | Posture | Differentiation / economics |
|---|---|---|---|
| Palo Alto Networks | PANW | Platform leader | NGFW franchise (Strata) + Prisma SASE; #1 unified-SASE share (~9%+); appliance cash funding the cloud transition; the platformization benchmark |
| Zscaler | ZS | Cloud-native pure-play | Proxy-architecture SSE built cloud-first; no appliance legacy; the "born-in-the-cloud" leader — high-growth, high-multiple |
| Cisco | CSCO | Bundler / incumbent | Firewall + Umbrella + Duo + Splunk telemetry; distribution and install-base gravity; networking-led SASE bundle |
| Fortinet | FTNT | Vertically integrated | Custom ASIC (security-processing silicon) → best price/performance in hardware; SD-WAN-led SASE; margin advantage from owning the chip |
| Netskope | NTSK (IPO'd 2025) | Cloud-native challenger | CASB heritage → full SSE/SASE; data-centric; went public 2025 — a scaled independent |
| Cato Networks | Private (~$4B+) | Single-vendor SASE | Purpose-built single-pass cloud backbone; a prominent one-vendor SASE example; recurring IPO/strategic candidate |
| Cloudflare | NET | Edge-network disruptor | Global edge network → Zero Trust / SSE attach; competes on the network footprint it already owns |
| Check Point | CHKP | Incumbent consolidator | Firewall heritage + Harmony/Infinity; acquired Perimeter 81 for SASE; bought Veriti (2025) — acquiring cloud-edge capability |
| Versa Networks | Private | SD-WAN-led SASE | Unified SASE share leader by some measures; SD-WAN-first; IPO candidate |
| Broadcom (Symantec) | AVGO | Harvester | Symantec SWG/CASB inside Broadcom; managed for the enterprise base, not growth |
The primary fault line is appliance incumbents versus cloud-native challengers. Palo Alto, Cisco, Fortinet, and Check Point own the firewall install base and the renewal stream, but must re-platform a hardware franchise into a cloud-delivered service without cannibalizing their own appliance margin. Zscaler, Netskope, Cato, and Cloudflare carry no appliance legacy — their architecture is the product — so they grow into the transition rather than defend against it. Fortinet's specific advantage is silicon: by designing its own security ASIC it undercuts software-only competitors on price/performance, which matters in a hardware-anchored category. The distinction that separates the two groups is whether a given asset sits on the growing side of the appliance-to-cloud migration or depends on declining hardware-refresh revenue.
SASE and SSE market share
Signature deals & events
- Palo Alto Networks platformization — Strata (firewall) + Prisma SASE positioned as one platform; the appliance cash flow funds the cloud transition. PANW's broader 2026 platform push (CyberArk close Feb 2026) signals it intends to be the consolidator across domains, not just network.
- Cisco → Splunk (~$28B, closed Mar 18 2024) — not a SASE deal per se, but it gives Cisco the SIEM/telemetry layer to feed a networking-led security platform (see SecOps/SIEM).
- Check Point → Perimeter 81, then Veriti (2025) — an appliance incumbent buying cloud-native SASE and exposure-management capability to close the architecture gap.
- Zscaler → Avalor, Airgap, then SquareX (Feb 2026) — extending the SSE leader into data security, segmentation, and browser security; the browser-security arms race with CrowdStrike (Seraphic) and Palo Alto.
- Netskope IPO (2025) — a cloud-native SSE pure-play reaching public markets; a read on how the market values born-in-the-cloud edge vs. appliance incumbents.
The bear case
The SASE bull case is that buyers consolidate four-to-six edge vendors into one platform and the winners compound. The bear case has two components. First, the appliance incumbents may be defending a declining asset: if the firewall refresh cycle slows faster than the cloud SASE attach ramps, PANW, Fortinet, and Check Point face a revenue gap that the cloud-native players never have to cross. Second, the hyperscalers and Cloudflare own the network the edge runs on — Microsoft (Entra/Global Secure Access), AWS, and Cloudflare can deliver good-enough SSE as a near-zero-marginal-cost attach to infrastructure the customer already buys, compressing the standalone premium. A falsifiable test is the ratio of cloud-SASE ARR growth to appliance/product revenue decline at PANW, Fortinet, and Check Point. If appliance revenue rolls over while SASE ARR growth decelerates, and Microsoft's Global Secure Access attach climbs, the thesis that the incumbent carries the franchise to the cloud is failing.
→ Cross-references: Vendors, Cloud Security, SecOps/SIEM, Deals & Comps, Bear Case.
Adjacent market: the networking and edge-infrastructure industry on the other side of the SASE convergence is mapped on Networking & Edge Infrastructure.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.