SASE Implementation Guide for Australian Teams

A SASE implementation guide should start with the places your people actually work, not a vendor diagram. For many Australian organisations, that means a mix of head office, branches, warehouses, home-based staff, cloud applications, legacy systems and third parties needing controlled access. The objective is straightforward: apply consistent security wherever a user, device or application connects, without creating a network that is difficult or expensive to operate.

Secure Access Service Edge, or SASE, brings networking and security controls together around identity, application access and policy. Done well, it reduces the gaps created by backhauling traffic through a central data centre, managing separate security tools at every site, or relying on broad VPN access. Done poorly, it can simply move existing complexity into a cloud console.

The difference is planning. A successful deployment is a staged security and networking programme, built around risk, user experience and operational ownership.

Start with the business case, not the product list

SASE is often introduced as a response to remote work or cloud migration. Those are valid triggers, but the stronger business case is usually broader. Consider where security policy is inconsistent, where branch connectivity depends on ageing appliances, where VPN performance frustrates staff, and where IT teams cannot clearly see which users are accessing which applications.

Define the outcome in practical terms. A regional business may need secure, reliable access to Microsoft 365 and cloud accounting platforms without routing that traffic through head office. A mid-market organisation may need to replace unrestricted remote VPN access with application-level access for employees and contractors. An enterprise may be standardising policy across hundreds of sites while meeting compliance and audit obligations.

These objectives affect design decisions. If application performance is the priority, local internet breakout and intelligent path selection may lead the programme. If a contractor has access to only one internal application, zero-trust network access should take precedence over extending the corporate network. If branches process payment or sensitive information, inspection, segmentation and central reporting need to be designed from the outset.

Establish a clear SASE implementation baseline

Before selecting licences, appliances or service tiers, document the environment you are changing. This baseline prevents a common implementation failure: replicating old network rules in a new platform without questioning whether those rules are still justified.

Map users by role, location and access requirement. Separate employees, privileged administrators, contractors, suppliers and unmanaged-device users. Then identify the applications they use, where those applications reside, what data they handle and whether access is browser-based, client-based or requires private connectivity.

Next, map traffic flows. Identify which branch traffic currently returns to a data centre, which applications already use direct internet access, and where performance issues occur. Include dependencies that are easily missed, such as DNS, identity services, software updates, voice, video and backups. A SASE policy that protects web traffic but disrupts business-critical voice or operational technology traffic will quickly lose internal support.

The baseline should also record existing controls: next-generation firewalls, endpoint protection, multi-factor authentication, web filtering, SIEM logging, SD-WAN links and network segmentation. SASE does not always replace every control. In many organisations, the right design extends established Fortinet firewall and secure networking investments while centralising policy and improving user access.

Design around identity, segmentation and traffic paths

A SASE architecture is strongest when identity becomes a primary policy input. Instead of granting access based only on a user being connected to a VPN, decisions can account for the user role, device posture, location, application sensitivity and risk level.

This requires the identity platform, endpoint management and security controls to work together. Enforce multi-factor authentication for remote and privileged access. Define what constitutes a managed, compliant device. Decide whether personal devices can access corporate data and, if so, whether access is limited to browser sessions or isolated applications. These are governance decisions as much as technical ones.

Segmentation deserves equal attention. A branch should not gain unrestricted access to every internal network simply because it has a trusted SD-WAN connection. Likewise, a remote user who needs one private application should not receive broad network visibility. Create access groups around business functions and applications, then apply least-privilege rules that can be reviewed and maintained.

Traffic path design is where performance and cost meet security. Local breakout can improve cloud application responsiveness and reduce dependence on central links, but it needs consistent inspection and logging. Backhauling may still be appropriate for certain legacy applications, specialised security controls or regulated data flows. There is no universal answer. The right approach depends on application location, bandwidth, latency tolerance and risk.

Choose the controls that match the use case

Most SASE programmes combine several capabilities, but not every user or site needs every control in the same way. Secure web gateway functions protect internet-bound traffic through filtering, inspection and threat prevention. CASB capabilities provide visibility and policy for cloud application use. Zero-trust network access controls private application access without exposing a broad network path. SD-WAN improves branch connectivity by selecting the best available link and applying business-aware routing.

For Australian organisations, also consider data residency expectations, local service availability, internet link diversity and the support model after go-live. A lower upfront price can become poor value if the design requires excessive manual policy management or if incidents cannot be resolved quickly by people who understand the environment.

Deploy in controlled phases

A phased rollout is usually safer than a big-bang cutover. Start with a defined user group or a branch with known applications and engaged stakeholders. This creates a real-world test of identity integration, policy logic, endpoint compatibility, traffic inspection and support processes before the design is repeated at scale.

During the pilot, measure more than whether users can connect. Track application response times, authentication failures, blocked traffic, help desk requests, link utilisation and security events. Confirm that logging provides enough detail for investigation without overwhelming the team with low-value alerts.

The first phase should also test exceptions. Some users will have older devices, specialised applications or unusual travel patterns. Exceptions are not a reason to abandon a sound security model, but they must be controlled, documented and reviewed. A temporary bypass with an owner and expiry date is far safer than an informal permanent workaround.

Once the pilot is stable, standardise deployment templates for branches, user groups and policies. Consistent naming, change control and configuration standards make a material difference as the environment grows. This is particularly valuable for organisations with limited in-house security resources or multiple operational sites.

Make operations part of the design

SASE changes who owns security decisions. Network teams may manage connectivity, security teams may define inspection and access policies, while service desk teams handle user onboarding and first-line troubleshooting. If these responsibilities are not agreed before deployment, simple incidents can stall between teams.

Set clear operating procedures for onboarding, offboarding, privileged access, policy changes, incident escalation and emergency access. Review access groups regularly, especially for contractors and users with administrative privileges. Security policy should be managed as a living control set, not a one-off project deliverable.

Visibility is equally critical. Central reporting should show application usage, risky activity, blocked threats, device compliance and branch connectivity health in a form that supports both technical investigation and management reporting. The goal is not more dashboards. It is faster, better-informed decisions when something changes or fails.

A unified Fortinet approach can reduce operational overhead where FortiGate, secure SD-WAN, endpoint controls and cloud-delivered security are managed under aligned policy and visibility. For organisations assessing architecture and procurement together, FortiSecure Store can help translate business requirements into a properly sized Fortinet design, rather than a collection of disconnected licences and appliances.

Measure success after go-live

The implementation is not complete when traffic has moved. Validate whether the programme has reduced VPN dependence, improved cloud application performance, shortened access provisioning, increased visibility or reduced the number of unmanaged policy exceptions. Compare those measures with the baseline established at the start.

Review costs as well as controls. Internet links, licensing, hardware refresh cycles, managed support and internal administration all affect total value. In some cases, centralising every function is justified. In others, a hybrid model that retains selected on-premises controls offers better resilience and a more sensible commercial outcome.

The best SASE deployment is rarely the most complicated. It is the one that gives each user and site the access they need, applies defensible security policy, and remains practical for the team responsible for operating it next month and next year.

Let's keep in touch

Subscribe for practical Fortinet insights, cost‑saving strategies, and security updates delivered straight to your inbox.