Skip to main content
Cybersecurity

The Origin of Workspace Protection: From MPLS and VPN Concentrators to SSE and Single-Vendor SASE

For thirty years, the corporate network was a fortress and the firewall was its drawbridge. Then the apps moved to SaaS, the workforce went home, and the entire model fell apart in 2020. The full story of how workspace protection grew from MPLS hub-and-spoke and VPN concentrators into the cloud-delivered Secure Service Edge and SASE architectures that defend the hybrid, SaaS-first enterprise today.

Artiflex IT Engineering·Cybersecurity & Cloud Engineering Team
··12 min read
The Origin of Workspace Protection: From MPLS and VPN Concentrators to SSE and Single-Vendor SASE

For thirty years, the corporate network was a fortress. Inside the fortress lived the applications, the file servers, the databases, the email and the user. Outside lived everything else. The firewall sat at the gate, the VPN concentrator extended the gate to remote workers, and the assumption underneath the entire architecture was that being inside the network was equivalent to being trusted. The whole industry was built on that assumption. Network security, endpoint security, identity, even the way Active Directory issued Kerberos tickets, all of it depended on the network having a clear boundary that meant something.

On March 11, 2020, the World Health Organization declared Covid-19 a pandemic, and within roughly forty-eight hours the assumption collapsed. Tens of millions of corporate employees suddenly worked from home over residential broadband. The applications they used were already half-migrated to SaaS. The VPN concentrators that had been sized for 10% of the workforce were asked to handle 100%, and most of them crashed within a week. The fortress model, already creaking, broke openly. Everything that has happened in workspace protection since then has been the response.

But the response did not start in 2020. The architectural shift had been underway for more than a decade, gathering speed every year, named successively as cloud-delivered web security, CASB, ZTNA, SASE and finally SSE. The pandemic just made it impossible to delay any longer. This is how Workspace Protection actually evolved.

Phase 1 (Pre-2008): MPLS, VPN Concentrators and the Hub-and-Spoke Era

From the late 1990s through the late 2000s, the dominant enterprise network architecture was MPLS hub-and-spoke. Branch offices connected to a central data centre over expensive carrier MPLS circuits. Every packet from every branch travelled to the central hub, was inspected by central security infrastructure, and was forwarded to its destination. Internet-bound traffic from a branch went to the hub, out through the central firewall, and back. It was inefficient and expensive, but it gave the security team a single chokepoint at which to enforce policy.

Remote workers were handled by hardware VPN concentrators (Cisco ASA, Juniper SA Series, Check Point Connectra, Pulse Secure SA Series, F5 BIG-IP APM). Users authenticated to the concentrator with a username, password and often a hardware OTP token, and were placed onto the corporate network as if they were sitting at a desk inside a branch office. The same chokepoint model held: all traffic terminated centrally, was inspected by central infrastructure, and was forwarded inwards.

The model worked while the applications all lived in the central data centre. When the applications started moving to SaaS, the model fell apart. Every Salesforce, Office 365 or ServiceNow request from a branch had to be tromboned through the central hub, inspected, sent back out to the SaaS provider, returned through the hub and then forwarded back to the branch. Latency was awful, MPLS bandwidth was expensive, and the security team's central chokepoint was paying the architectural price for every cloud application the business adopted.

Phase 2 (2008-2014): Cloud-Delivered Secure Web Gateway and the Zscaler Disruption

The disruptor came from a single company. In 2008, Jay Chaudhry founded Zscaler in San Jose with a thesis that was widely dismissed at the time and obvious in retrospect: if applications and users were both moving to the internet, the security inspection layer should also live on the internet. Zscaler delivered a cloud-native Secure Web Gateway (SWG) that ran in over a hundred data centres globally. Branches sent their internet traffic directly out through Zscaler instead of tromboning through the central hub. Remote users connected to the nearest Zscaler point of presence over the public internet.

The architectural insight was that the security inspection layer no longer needed to be at the corporate network boundary, because the corporate network boundary was no longer where the threats lived. Zscaler's growth through the early 2010s was extraordinary. By 2014, the cloud-SWG category was real, and the incumbent on-premise SWG vendors (Blue Coat, McAfee Web Gateway, Cisco IronPort, Websense) were all scrambling to deliver their own cloud equivalents. Cisco's response was the 2015 acquisition of OpenDNS for USD 635M, rebranded Cisco Umbrella. Symantec acquired Blue Coat in 2016 for USD 4.65B partly to gain a credible cloud-SWG story. Forcepoint and others followed.

Phase 3 (2012-2018): CASB, the SaaS Visibility Crisis and the Skyhigh-Netskope Wave

In parallel with cloud-SWG, the SaaS visibility crisis (covered in more detail in our Data Loss Prevention origin story) created a new category. The Cloud Access Security Broker, formalised by Gartner in 2012, addressed a problem that the SWG could not: visibility and control inside SaaS applications themselves, including data flowing into and out of SaaS via APIs and the actions users took once inside.

Four startups launched in 2012 to compete in this space: Skyhigh Networks, Netskope, Adallom and CipherCloud. By 2018, Microsoft had acquired Adallom (rebranding it Microsoft Cloud App Security and now Microsoft Defender for Cloud Apps), McAfee had acquired Skyhigh Networks (later spun back out as Skyhigh Security in 2022), and Netskope had emerged as the strongest independent CASB pure-play. Bitglass and Symantec CloudSOC competed in the same segment. Throughout the same period, the lines between SWG, CASB and DLP began to blur, with each category absorbing capabilities from the others.

Phase 4 (2014-2019): BeyondCorp, ZTNA and the Death of the VPN

The third architectural shift came from Google. In 2014, Google published the first BeyondCorp paper, describing the production zero-trust access architecture it had been operating internally since 2011. The BeyondCorp model rejected the VPN entirely. Instead of placing remote users "onto the corporate network", BeyondCorp authenticated every user and device to every individual application directly, evaluated context (user identity, device posture, network location, application sensitivity) at every request, and granted or denied access dynamically without any concept of a perimeter.

Within five years, BeyondCorp had inspired an entire commercial category: Zero Trust Network Access (ZTNA). Pioneers included Google's commercial BeyondCorp Enterprise (now part of Chrome Enterprise Premium), Akamai Enterprise Application Access (acquired from Soha Systems in 2016), Zscaler Private Access, Symantec Secure Access Cloud, Perimeter 81, Cloudflare Access, Twingate and Banyan Security. By 2019, ZTNA was a mainstream Gartner category, and analysts were openly predicting the gradual displacement of traditional VPN concentrators.

What made ZTNA different from VPN was twofold. First, it was application-specific: a user authorised to access the HR system was authorised only for that system, not for any other internal asset, eliminating the lateral-movement blast radius that legacy VPNs had created. Second, it was identity-and-context-aware: every access decision incorporated MFA, device posture, geographic risk and application sensitivity, evaluated continuously, not just at session start.

Phase 5 (2019-2024): Gartner Coins SASE, Then SSE

By 2019, the workspace protection category had four overlapping product types (SWG, CASB, ZTNA, FWaaS) and at least a dozen serious vendors competing across them, plus an SD-WAN networking layer that was increasingly being bundled with security. The market needed a unifying framework, and Gartner provided one. In August 2019, analysts Neil MacDonald, Lawrence Orans and Joe Skorupa published the original SASE paper introducing the Secure Access Service Edge as a single converged architecture combining cloud-delivered network (SD-WAN) and cloud-delivered security (SWG, CASB, ZTNA, FWaaS) under one platform.

SASE was an aspirational architecture more than an immediately shippable product, and the major vendors split into three camps. Single-vendor SASE leaders (Palo Alto Networks Prisma SASE, Cisco Umbrella + Catalyst SD-WAN, Cato Networks, Versa Networks) committed to delivering both networking and security from a unified platform. Security-only vendors (Zscaler, Netskope) declined to enter SD-WAN and lobbied Gartner for a security-only sub-category. SD-WAN incumbents (Aryaka, VeloCloud, Silver Peak) came at SASE from the networking side.

In March 2021, Gartner conceded the point and introduced a new sub-category: the Security Service Edge (SSE), comprising the security half of SASE (SWG, CASB, ZTNA, FWaaS, plus often DLP and RBI) without requiring the networking layer. SSE allowed Zscaler and Netskope to remain category-defining without committing to SD-WAN. Zscaler's Zero Trust Exchange and Netskope's Intelligent Security Service Edge became the leading SSE platforms. Cloudflare entered with Cloudflare One. Microsoft entered with Entra Internet Access (SWG-equivalent) and Entra Private Access (ZTNA-equivalent), positioning Microsoft as a credible SSE player for organisations standardised on Entra ID.

Phase 6 (2024 onwards): Single-Vendor SASE and AI-Augmented Edge

The most recent phase is the consolidation toward single-vendor SASE for enterprises that want one platform and one operating model. Gartner's 2024 Magic Quadrant for Single-Vendor SASE positioned Palo Alto Networks (Prisma SASE), Netskope (One platform with Borderless WAN), Cato Networks and Versa Networks as Leaders. Cisco, Fortinet, HPE/Aruba (with the Silver Peak acquisition) and Cloudflare follow as challengers and visionaries.

Two architectural shifts characterise this newest generation. First, AI is being embedded across the platform: AI-powered threat prevention in the SWG layer, AI-driven user and entity behaviour analytics in the ZTNA layer, AI-assisted incident investigation across the integrated platform. Second, the security layer is increasingly identity-aware in a deep way, integrating directly with Microsoft Entra Conditional Access, Okta Adaptive Authentication and Ping Risk Engine to make per-request decisions that combine network signals (location, IP reputation), device posture, identity risk and application sensitivity.

The 2026 state of the art for UAE workspace protection is: a cloud-delivered SSE platform (Zscaler Zero Trust Exchange, Netskope ISSE, Microsoft Entra Internet/Private Access, Cloudflare One, Palo Alto Prisma Access, or one of the single-vendor SASE leaders if the SD-WAN layer is also being modernised); ZTNA replacing or supplementing the legacy VPN concentrator; CASB integrated for SaaS visibility and control; identity-aware DLP at the cloud egress; and tight integration with Microsoft Defender XDR or another XDR platform for end-to-end incident response. We deliver this stack in detail under Workspace Protection (SSE & SASE).

2008
Zscaler founded
Cloud-SWG era begins
2014
Google BeyondCorp paper
ZTNA architecture defined
2019
Gartner coins SASE
MacDonald et al.
2021
Gartner introduces SSE
Security half of SASE
2024+
Single-vendor SASE Magic Quadrant
Consolidation phase

What This History Tells UAE Businesses Today

If you are running, replacing or scaling workspace protection in 2026, the six-phase arc above is not academic. Three things follow directly.

The first is that the legacy VPN concentrator is end-of-life as an architectural choice. Every major ransomware incident in the GCC over the past three years that started with remote-access compromise has involved a legacy VPN with a stolen credential, a missing MFA, or both. ZTNA replacement is no longer an architectural opinion; it is a security floor. NESA and NCA ECC compliance now references zero-trust principles explicitly.

The second is that the right SSE/SASE choice depends heavily on what is already in the environment. For organisations standardised on Microsoft 365 E5 with Entra ID Governance and Defender XDR, Microsoft Entra Internet Access and Entra Private Access are the most cost-effective starting point. For organisations with a heavy Cisco network footprint, Cisco Secure Access (the rebranded Umbrella + ZTNA stack) is usually the better integration story. For organisations with no strong vendor anchor, Zscaler, Netskope, Palo Alto Prisma and Cato Networks are the most credible standalone choices.

The third is that SSE/SASE is not a project; it is a multi-year migration. Most UAE enterprises will run a hybrid for years: cloud SSE for SaaS and internet egress, ZTNA for new application access, legacy VPN still terminating for some long-tail systems, and SD-WAN modernising the branch network in parallel. Plan for the migration explicitly, not as a forklift.

Where Artiflex IT Comes In

Artiflex IT designs, deploys and operates Workspace Protection programmes across the UAE, Oman and Saudi Arabia. We deliver Microsoft Entra Internet Access and Entra Private Access for Microsoft-first environments, alongside Zscaler Zero Trust Exchange, Netskope Intelligent SSE, Palo Alto Prisma Access, Cisco Secure Access, Cato Networks SASE Cloud, Cloudflare One and Fortinet SASE depending on the existing network and security stack. We assess the current VPN, SWG, CASB and SD-WAN posture, design a phased SSE or SASE rollout, and integrate the result with IAM, Endpoint Security and SIEM/SOAR/MDR for end-to-end visibility.

If your VPN is the only remote access path, your SaaS traffic still tromboned through a central firewall, your ZTNA pilot has stalled, or your SSE platform is delivering some controls and not others, we will tell you exactly where you are exposed and what an honest re-design looks like. No upselling, no theatre.

Talk to our Consultant

30-minute review of your current workspace protection architecture against modern SSE and SASE benchmarks. We will surface the three highest-impact gaps to fix first, with no commitment.

Book Consultation

Share this article

Need help applying any of this?

Our engineering team works with UAE businesses on the exact problems we write about. Real conversations, no sales theatre.