The top rated SSE vendors are:
Gartner created a new market category called Security Service Edge (SSE) which refers to the security capabilities required to implement a SASE architecture, unifying CASB, ZTNA, and SWG into a single-vendor, cloud-delivered solution.
Supported Solutions | SSE Features | Cybersecurity | Cloud App Access | Differentiator | Gartner Status | |
Zscaler | Zscaler Security Platform comprising Zscaler Private Access (ZPA), Zscaler Internet Access (ZIA), and Zscaler Digital Experience | CASB, ZTNA, SWG | Threat prevention, DLP, FWaaS, RBI, inline cloud sandbox, IPS, DNS security, SSL inspection, web content filtering, SSPM/CSPM, and malware protection. | API, forward proxy, device agent (Zapp client), PAC files, and direct connections with the major public cloud providers via co-location facilities | Zscaler is one of the few vendors offering a cloud-native and cloud-first SSE architecture that secures all users and applications regardless of the location, access device, and data. Furthermore, Zscaler offers Zscaler Digital Experience, a subscription service designed to predict user experience and application performance issues, focusing on Microsoft 365 productivity applications. | Zscaler appears as a Leader in Gartner's 2022 Magic Quadrant for Security Service Edge |
Palo Alto Networks | Prisma Access | CASB, ZTNA, SWG | Bi-directional SSL inspection, policy management, DLP, VPN, threat prevention, Shadow IT visibility, IoT security, DNS security, FWaaS, web content filtering, and sandboxing. | API, SD-WAN, IPSec tunnels, reverse proxy (via SAML), forward proxy, and device agent (Global Protect) | Prisma Access offers proactive user experience remediation via Autonomous Digital Experience Management (ADEM), allowing customers to identify and remediate performance issues before impacting users. | Palo Alto Networks appears as a Challenger in Gartner's 2022 Magic Quadrant for Security Service Edge |
Cisco | Cisco Umbrella | CASB, ZTNA, SWG | DNS-layer security, SSL inspection, web content filtering, DLP, interactive threat intelligence via Talos Intelligence Group, FWaaS, XDR via Cisco SecureX, RBI, and malware protection. | Forward proxy, device agent (Cisco Anyconnect), DNS-based redirection, IPSec tunnels, API, PAC files, and proxy chaining. | Cisco Umbrella is a cloud-native security platform delivered globally across thirty-seven (37) PoPs. While the solution offers a single-vendor, feature-rich SSE solution, as of March 2022, it lacks cloud DLP and IPS, which Cisco is currently developing. | Cisco appears as a Challenger in Gartner's 2022 Magic Quadrant for Security Service Edge |
Cato Networks | Cato SASE | CASB, ZTNA, SWG | Application-aware nextgen FWaaS, web content filtering, SSL inspection, standard and nextgen malware protection, IPS, and MDR. | Forward proxy, device agent (Cato client), reverse proxy, and direct cloud DC integrations (IPsec and Cato vSocket) | Cato SASE is a cloud-native security platform delivered globally across more than sixty (60) PoPs, converging networking and security capabilities. While the solution offers single-vendor, feature-rich networking and security capabilities, as of March 2022, it lacks cloud DLP. Cato Networks, however, plans to integrate this capability in H1 2022. | Gartner excluded Cato Networks from the 2022 Magic Quadrant for Security Service Edge because it does not offer a complete CASB solution. |
Netskope | Netskope Security Service Edge (SSE) | CASB, ZTNA, SWG | DLP, advanced threat prevention, FWaaS, RBI, UEBA, and advanced analytics. | Forward proxy, device agent (Netskope client), SD-WAN, PAC files, and APIs | Netskope adds artificial intelligence and machine learning technology to its SSE offering for more accurate web and cloud app categorization and malicious document analysis. Additionally, the solution can detect sensitive data contained in screenshots and images. | Netskope appears as a Leader in Gartner's 2022 Magic Quadrant for Security Service Edge |
Proofpoint | Proofpoint Information and Cloud Security Platform | CASB, ZTNA, SWG | Endpoint and email DLP, email encryption, RBI, advanced threat protection with UEBA, micro-segmentation, and threat intelligence via Threat Graph. | Forward proxy, device agent, API, and reverse proxy. | Proofpoint has an extensible DLP capability extending endpoint, email, cloud, and web offered as part of the Proofpoint Information and Cloud Security Platform, with the ability to store data locally to help customers meet data compliance and regulations. | Gartner excluded Proofpoint from the 2022 Magic Quadrant for Security Service Edge because it retired its ZTNA offering in Q4 2021. |
Barracuda Networks | CloudGen WAN and CloudGen Access | SWG and ZTNA | NextGen FWaaS, web content filtering, advanced threat prevention with cloud sandboxing, SSL inspection, IPS/IDS, malware protection, conditional access policies, RBAC and ABAC, and on-device phishing and threat protection. | Device agent (CloudGen Access App), IPsec tunnels, SD-WAN, and direct connections to Microsoft Azure | Barracuda has a close partnership with Microsoft Azure, leveraging the Microsoft Global Network to deliver direct access to Microsoft 365 productivity apps with greater performance levels. Unlike other vendors in the SSE space, Barracuda does not offer a complete CASB solution covering all cloud service models. | Barracuda does not appear in Gartner's 2022 Magic Quadrant for Security Service Edge |
Menlo Security | Menlo Cloud Security Platform | CASB, ZTNA, SWG | DLP, RBI with zero-day protection, email link isolation, malware detection and prevention, phishing prevention, SSL inspection, and web content filtering. | Device agent (Menlo Connect), forward proxy, SD-WAN, reverse proxy, PAC files, and IP tunnels (IPSec and GRE) | Menlo built its Cloud Security Platform on Elastic Isolation Core technology designed to transfer the web browsing process from the endpoint to the cloud to enable complete isolation of breaches and attacks away from the users. The isolation technology brings document isolation and read-only web access. The solution also provides flexible and extensible integration with third-party tools through open APIs, allowing the customers to leverage existing investments in security. | Gartner excluded Menlo Security from the 2022 Magic Quadrant for Security Service Edge because it did not meet the minimum financial inclusion criteria. |
Cloudflare | Cloudflare One | ZTNA and SWG, with CASB controls built into the ZTNA service | Web content filtering, app control, DNS security, RBI, SSL inspection, inline cloud DLP, identity and device posture, FWaaS, and DDoS mitigation | Device agent, forward proxy, reverse proxy, IP tunnels, and direct connections | Cloudflare One is built on the Cloudflare Global Network, extending to 250 cities worldwide with 9,800 interconnects across over 1,600 co-location facilities, 121 TB capacity, and a 100% uptime SLA. Cloudflare also offers native DDoS mitigation, traffic acceleration, and DNS rewrite in its web security services. | Gartner excluded Cloudflare from the 2022 Magic Quadrant for Security Service Edge because it does not offer API integration as part of its CASB solution. |
Forcepoint | Forcepoint ONE | CASB, ZTNA, SWG | DLP, web content filtering, SSL inspection, malware protection, threat protection, RBI, CDR, and zero-day sandboxing via Deep Secure. | API, reverse proxy, and forward proxy | Forcepoint ONE uses an agent-based architecture to extend the core SSE capabilities to the endpoint. Instead of forwarding all end-user traffic to the nearest PoP for inspection and policy enforcement, the Forcepoint ONE unified agent performs intelligent routing to enable on-device traffic encryption, decryption, inspection, and control, significantly improving performance and latency. Furthermore, Forcepoint is also one of the few vendors offering an enterprise DLP solution managed from a central console with a single policy set, covering cloud, endpoint, Internet, and email. | Forcepoint with Bitglass appears as a Visionary in Gartner's 2022 Magic Quadrant for Security Service Edge |
Gartner's decision to create the SSE market was driven mainly by:
IT teams should consider the following factors when evaluating SSE vendors and MSPs: