Security service edge (SSE) refers to the security components of the secure access service edge (SASE) model. SSE secures access to the Internet and to applications for remote users.
After reading this article you will be able to:
Related Content
Subscribe to theNET, Cloudflare's monthly recap of the Internet's most popular insights!
Copy article link
Security service edge (SSE) is the security aspect of secure access service edge (SASE). SASE is a cloud-native IT model that combines wide area network (WAN) edge networking and security services in a way that is better suited, compared to traditional network architectures, for how modern businesses operate.
SASE can be divided into two sets of interwoven capabilities: networking services and security services.
Gartner, the research and advisory firm that first coined the term "SASE," considers wide area network (WAN) edge services, including software-defined wide area networking (SD-WAN), to be the networking capability upon which SASE is built. WANs connect local networks across vast distances. Moving those capabilities to the edge better serves branch offices, mobile users, and cloud infrastructure. Edge-delivered WAN services are also more scalable and flexible than traditional, MPLS-based WANs.
SSE includes three core components, along with some additional capabilities:
Together, these areas make up SSE — with other security capabilities like firewall-as-a-service (FWaaS) and remote browser isolation (RBI) often included as well. When cloud-centric edge WAN services and SSE are delivered from the same network architecture, an organization can fully deploy a SASE model.
| SSE component | Description | Key benefit/function |
| Zero trust network access (ZTNA) | Creates an identity- and context-based, logical access boundary around an application or set of applications | Ensures no user or device is trusted by default; grants access only to specific applications after identity verification |
| Cloud access security broker (CASB) | Includes multiple cloud security technologies for SaaS applications | Secures cloud-based software applications and prevents data loss in SaaS environments |
| Secure web gateway (SWG) | Sits between remote/office users and the Internet to enforce security policies | Applies acceptable use and security measures for threat and data protection |
| Additional SSE capabilities | Firewall-as-a-service (FWaaS) and remote browser isolation (RBI) | FWaaS filters cloud network traffic; RBI executes web browsing in contained cloud environment to prevent local malware infection |
Cloudflare has a network with over 335 locations around the world, and Cloudflare has long been a leader in security, network performance, and edge computing. The Cloudflare One platform includes all the aspects of SSE listed above, and it combines this with network-as-a-service for a full SASE deployment.
Learn more about Cloudflare One.
SSE is the specialized security component of the larger secure access service edge (SASE) framework. It is a cloud-based architecture designed to protect remote workers and branch offices. While SASE as a whole includes networking services, SSE focuses specifically on the security tools required to maintain a safe and reliable digital environment.
A standard SSE architecture is built on three primary pillars: Zero Trust Network Access (ZTNA), secure web gateway (SWG), and cloud access security broker (CASB).
Think of SASE as a complete toolkit for modern business connectivity. It is divided into two halves: the networking side (often involving SD-WAN or WAN edge services) and the security side (SSE). When an organization combines these edge-delivered networking capabilities with the security protections of SSE within a single network architecture, they have achieved a full SASE deployment.
Traditional security models often rely on a "castle-and-moat" approach that assumes anyone inside the office network is trustworthy. SSE is better suited for modern work because it is cloud-native and delivered at the edge, closer to where users actually are. This allows for more scalable, flexible protection that follows the user regardless of whether they are in a central office, at home, or traveling.
SSE is the primary vehicle for implementing a Zero Trust security model. SSE ensures that no user or device is trusted by default. Instead, access is strictly controlled through identity- and context-based policies, meaning a user only gets access to the specific applications they need to do their job, and only after their identity has been thoroughly verified.
Beyond the three main pillars, many SSE solutions include advanced security features such as firewall-as-a-service (FWaaS) and remote browser isolation (RBI). These tools provide additional layers of defense by filtering network traffic and executing web browsing in a contained cloud environment to prevent malware from reaching a user’s local device.
Cloudflare offers a comprehensive platform that delivers all the essential elements of SSE through a global network. By integrating these security services with its existing network-as-a-service capabilities, Cloudflare allows organizations to fully deploy a SASE model that optimizes both security and performance.