Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - High Assurance Delivers SD-WANs For All
Articles

High Assurance Delivers SD-WANs For All

Paul GermanBy Paul GermanMarch 3, 2022Updated:March 3, 20225 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
30-Day Cybersecurity Sprint
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The prohibitive cost of WAN technology has become a major concern for businesses and governments and driven the explosion in adoption of Software-Defined Wide Area Networks (SD-WAN) in recent years. Yet a gap is beginning to emerge between those businesses able to explore the flexibility and low cost offered by SD-WAN and those, typically regulated, organisations that have serious concerns about data security.

Without access to the agility, flexibility and support for cloud based transformation provided by SD-WAN, these organisations will struggle to keep pace with the innovations enjoyed by 80% of the market. Yet if SD-WAN cannot support the specific security demands of regulated, data sensitive environments, what are the options?

Paul German, CEO, Certes Networks, explains how High Assurance SD-WAN uses crypto-segmentation to enable organisations in all industries to exploit the benefits of SD-WAN, while ensuring data integrity and confidentiality.

Missed Opportunity 

The upsides of SD-WAN are significant, especially given the growth of IoT and need for unlimited connections from multiple locations. The software-defined networking approach offers agility and flexibility. It is cost effective – massively so when compared to the MPLS connectivity alternative. For the vast majority of organisations, the ability to create a virtual network over the Internet delivers the same user experience at a lower cost point while also supporting innovation and enabling the rapid evolution of cloud transformation strategies. It’s a win:win.

For a significant minority, however, the benefits of SD-WAN are tempered by security concerns. Regulation is affecting an increasing number of industries as well as public organisations – and it is estimated that for around 20% of the market additional protection is required to achieve regulatory compliant SD-WAN adoption.

Regulated organisations are compelled to ensure the integrity of sensitive data as it travels across a network environment and that demands a number of key security principles that basic SD-WAN deployments do not offer. Not only are government bodies, financial institutions and healthcare operators compelled to invest heavily in additional security resources, but they are also missing out on the significant operational benefits SD-WAN can offer. 

Overcoming the Stand Off

The frustration of network teams keen to explore and exploit the value of SD-WAN is tangible but standard SD-WAN deployments do not meet the more stringent security demands associated with handling sensitive data. Data Protection Officers (DPOs) and Chief Security Officers (CSOs) will continue to resist the business’ drive to exploit the cost and agility benefits of the internet for fear of compromising sensitive or confidential data.

And for good reason. While a SD-WAN overlay looks private, ultimately there is still a public internet connection plugged in to a business that holds both sensitive and non-sensitive data. There is a very real risk that a regulated business could inadvertently end up with sensitive data on the public internet, through configuration errors or software bugs, and incur a significant regulatory breach in the process.

Furthermore, the sheer flexibility in cloud deployment enabled by SD-WAN adds to the risk – especially for organisations with multiple branch locations. Using break out, the data created in SaaS tools such as Office365, Salesforce, and so on, is pushed directly onto the internet rather than directed to the corporate data centre. However, while this fire and forget model is hugely efficient, is it also risky: what happens if the break out policy accidentally includes sensitive data?

It is no wonder there is a stand-off between network teams pushing the benefits of SD-WAN and security teams insisting the risks are too high. If organisations are to maximise the financial and operational benefits offered by SD-WAN while still meeting their regulatory security requirements a more robust approach to data assurance is required.  

High Data Assurance

Enter High Assurance SD-WAN, which introduces another overlay technology that specifically targets the protection of sensitive data within regulated organisations by using crypto-segmentation to ensure the integrity and confidentiality of sensitive data. The overlay approach supports the regulatory demand for separation of duties: the network team can configure the SD-WAN, while the data security team uses fine grained policies to define the way different data categories are handled across the network with ownership linked to specific encryption keys. The underlying network has no visibility of either the data or its classification.

This also reinforces the essential Zero Trust approach to the underlying network infrastructure – with High Assurance SD-WAN organisations no longer have to entrust the network carrier with responsibility for data security. Whether the network is public or private, trusted or untrusted, is irrelevant: the data security team simply needs to define the policy and, with ownership of the cryptography keys, can be confident that data is protected at all times wherever it goes. 

In addition, visibility of key security metrics provides real-time insight into the cyber assurance posture, while integration between key cyber security functions uses this visibility to enable the organisation to efficiently react and remediate out-of-compliance events. 

Conclusion

Regulation is increasing globally, and growing numbers of organisations are now facing up to demands to add new layers of protection for sensitive data. Without high data assurance, these organisations will not be able to maximise the value and flexibility of SD-WAN; indeed for those who have already made the move to SD-WAN, additional compliance demands could create huge concerns within security teams.  

The availability of a simple to define and deploy high data assurance solution for SD-WAN totally changes the situation for those within regulated industries, de-risking the adoption of a low cost, flexible technology that can transform cloud-based and digital transformation strategies.

Paul German

Paul German, CEO at Certes Networks

  • Paul German
    SASE – The Risk Of Over-rationalising
  • Paul German
    Government Cloud On-Ramping
  • Paul German
    Harvest Now, Decrypt Later
  • Paul German
    Zero Trust Architecture – No Longer A ‘Nice To Have’

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}