Managed SASE

The office moved. Your security perimeter should follow.

Most businesses still protect a building their people rarely sit in. Managed SASE moves access and inspection into a cloud service that follows the user: identity-based access to named applications, filtering that works on any network, and device conditions that are checked before anyone connects.

  • Verify

    Identity and device state, checked every time.

  • Connect

    Access to the application, not the network.

  • Prove

    Access, activity and change, on record.

Numata specialists discussing secure access with a client team.

Why remote access is the weak point.

The problem
Where it goes wrong

Four ways the network became the thing people are trusted on.

That made sense when everyone was in one building. It is now the shortest route an attacker has, and the hardest thing to evidence when someone asks who can reach what.

  • VPN trusts the whole network

    One connected device, one set of stolen credentials, and the attacker is inside everything.

  • Access nobody can evidence

    Nothing shows who can reach which system, or when a leaver's access actually stopped.

  • Traffic dragged back to the office

    Remote users route through a head office appliance that was never sized for them.

  • Unmanaged devices and third parties

    Contractors and personal devices reach business systems with no posture standard applied.

The cycle

A managed lifecycle that keeps running after go-live.

Access policy decays the moment people change roles, applications are added and projects end. The service keeps the model current, so what is written down is what is in force.

  1. Discover

    Map users, sites, applications, third parties and current remote access paths.

  2. Design

    Define who may reach what, on which devices, under what conditions.

  3. Pilot

    Prove the access model with a representative group before anyone else moves.

  4. Roll out

    Staged deployment by site and team, with VPN retired once access is proven.

  5. Operate

    Policy changes, joiners and leavers, filtering tuning and incident support.

  6. Report

    Monthly access, activity and exception reporting to leadership.

What Numata manages

What the service includes.

  • Zero trust application access
  • Secure web gateway
  • DNS and content filtering
  • Device posture checks
  • Identity-based policy
  • Site and branch connectivity
  • Third-party and contractor access
  • Access reporting and review
  • Zero trust access to applications

    People are granted access to named applications rather than to the network. Access is tied to identity, group and device state, so a person only ever sees the systems their role requires.

  • VPN replacement without the friction

    Connections are brokered through the nearest cloud point of presence instead of being backhauled to a head office firewall, so remote work stops depending on one appliance and one internet line.

  • Secure web and DNS filtering

    Web traffic and DNS requests are inspected and filtered wherever the user is working, blocking malicious destinations, phishing infrastructure and categories your policy does not allow.

  • Device posture as a condition of access

    A device must meet an agreed standard, such as encryption, patch level and endpoint protection, before access is granted, and access is withdrawn when the device drifts out of standard.

  • Controlled third-party access

    Contractors, auditors and vendors receive time-bound access to specific applications from devices you can check, without an account that lives on your internal network.

  • Managed policy and change

    Joiners, movers and leavers, new applications, new sites and exception requests are handled as part of the service, with every change recorded rather than made quietly in a console.

Users, sites and scenarios covered

Access designed around the people who need it.

Every organisation has more than one kind of user: employees, contractors, seasonal staff, auditors and directors on their own devices. Each needs a different answer, and each answer has to be written down before it can be enforced.

We design the access model against those groups, then run it as a service so it stays accurate as roles, applications and sites change.

See how this pairs with cyber resilience

Open any item for what falls in scope, the policy we design to, what it changes in practice and the evidence you receive.

  • Hybrid and remote employees

    People working from home, from client sites and while travelling, needing the same protection they would have in the office.

    Scope
    Managed laptops and desktops, the applications each role requires, and the internet traffic those devices generate.
    Policy
    Access by identity and group, conditional on device posture, with web and DNS filtering applied everywhere the device connects.
    What changes
    One consistent security position regardless of location, with no dependence on a user remembering to connect a VPN.
    Evidence
    Per-user access entitlements, connection records and filtered-request reporting.
  • Private applications and internal systems

    Line-of-business systems, file servers, finance and practice platforms that were historically reached over VPN.

    Scope
    Named internal applications published individually, with the underlying network kept unreachable.
    Policy
    Least-privilege access per application, granted to roles rather than to devices, and reviewed on a schedule.
    What changes
    Lateral movement is removed as an option: a compromised device cannot scan or reach what it was not published to.
    Evidence
    Application publication list, access matrix by role and a dated record of access reviews.
  • Branch offices and multiple sites

    Distributed operations where each site historically ran its own firewall, its own rules and its own drift.

    Scope
    Site connectivity, inter-site access, guest and operational network separation, and internet breakout per location.
    Policy
    Central policy applied to every site, with local breakout for performance and consistent inspection everywhere.
    What changes
    Standards hold across the estate instead of varying by whoever last configured the local box.
    Evidence
    Site inventory, policy consistency reporting and exception log per location.
  • Contractors, vendors and auditors

    Third parties who need a narrow slice of access for a defined period, and nothing beyond it.

    Scope
    Specific applications, defined access windows, and the device conditions the third party must meet.
    Policy
    Time-bound, application-scoped access with automatic expiry, separate from employee identity groups.
    What changes
    Third-party access stops being a standing account nobody remembers to remove after the project ends.
    Evidence
    Third-party access register, expiry dates and activity records per engagement.
  • Unmanaged and personal devices

    Directors on personal laptops, seasonal staff, and people using a device the business does not own.

    Scope
    Which applications may be reached from an unmanaged device, and which are restricted to managed hardware.
    Policy
    Tiered access: sensitive systems require a managed, compliant device, while lower-risk applications allow controlled browser access.
    What changes
    A practical answer that neither blocks the business nor pretends an unmanaged device is safe.
    Evidence
    Device posture reporting, blocked-attempt records and the agreed exception list.
  • Joiners, movers and leavers

    The everyday process where access risk is actually created, and where most estates quietly accumulate exposure.

    Scope
    Onboarding, role changes and offboarding across every application published through the service.
    Policy
    Role-based entitlement templates, so access follows the role and is removed with the identity, not per system.
    What changes
    A leaver's access ends at one point, immediately, rather than across a checklist of consoles.
    Evidence
    Change records per identity, time to revoke and a periodic entitlement review report.
  • Ransomware and credential theft

    The scenario the access model exists for: someone has valid credentials or a foothold on a device.

    Scope
    Containment through segmentation, posture enforcement and the ability to cut access centrally.
    Policy
    Explicit deny by default, per-application publication, and immediate revocation as an operational action.
    What changes
    The blast radius is what one identity could reach, not the whole network the device was sitting on.
    Evidence
    Access logs, blocked destination records and a post-incident containment timeline.
  • Regulatory and insurance requirements

    Where access control is not just good practice but an obligation you must be able to demonstrate.

    Scope
    Access control statements, review cadence, logging retention and the reporting your obligation specifies.
    Policy
    Controls mapped to the framework in play, whether ISO 27001, SOC 2, Cyber Essentials or an insurer's questionnaire.
    What changes
    The questionnaire is answered from evidence already produced, rather than assembled the week it is due.
    Evidence
    Control mapping, access review records and retained activity logs for the required period.

Scope is agreed up front, group by group, so no one is assumed to be covered who is not.

The platform

Security that travels with the person.

The service runs on an enterprise cloud networking and security platform we licence, deploy and operate on your behalf. You do not buy the appliances, the licences or the expertise to run them. What it means in practice is that the same policy applies in the office, at home and on the road, and that it is maintained rather than left to drift.

  • Cloud-delivered, close to the user

    Inspection and brokering happen at a cloud edge near the person working, so protection does not depend on the capacity of one office appliance.

  • Identity at the centre

    Policy is written against people, roles and groups in your existing directory, so access reflects the organisation rather than a list of IP addresses.

  • Applications published, networks hidden

    Internal systems are reachable only through the broker and are not exposed to the internet or discoverable from a connected device.

  • Posture-aware access

    Encryption, patch state and endpoint protection are checked as a condition of connecting, not assumed at the point a device was first issued.

  • Filtering that follows the device

    Web and DNS controls apply on any network, including hotel, home and mobile connections, without routing everything through the office.

  • Managed and monitored for you

    Policy changes, alerts, blocked-access queries and tuning are handled by our operations centre as part of the service.

Reporting

Who can reach what, answered on demand.

Access control is only as good as your ability to show it. Each cycle produces a plain report on who is covered, what they can reach, what was blocked and what needs a decision from you.

Standard documentation set
  • Application and access inventory
  • Zero trust access policy design
  • Device posture standard
  • Third-party access register
  • Monthly access and activity report
  • Periodic access review record
What we report on
  1. 01Users and sites protected
  2. 02Applications published
  3. 03Device posture compliance
  4. 04Blocked and filtered activity
  5. 05Access changes and revocations
  6. 06Open exceptions and remediation
Commercial model

A monthly subscription, priced per user.

Managed SASE is proposed on a twelve month agreement, billed monthly in advance and sized by protected users and network locations, with a one-off onboarding fee covering discovery, policy design, pilot and staged rollout. The platform, the cloud edge capacity and the ongoing policy management are part of the service.

  • One-off

    Onboarding

    Application and access discovery, policy design, device posture standard, pilot group and staged rollout.

  • Monthly

    Managed service

    Policy management, joiners and leavers, filtering tuning, monitoring, user support for access issues and reporting.

  • Included

    No hidden fees

    Platform licensing, cloud edge capacity, site connectivity policy and access reviews. VPN decommissioning is part of the rollout.

Fit

Built for hybrid, distributed and regulated teams.

  • People work from anywhere, and VPN has become the support ticket nobody enjoys.
  • Multiple sites or franchise locations run inconsistent local network security.
  • An insurer, client or regulator asks how access is granted, reviewed and removed.
Boundaries

Clear boundaries keep the position honest.

We secure access to systems inside the agreed scope. Physical network cabling, carrier circuits and third-party platform outages sit outside the service, as do application permissions owned inside a vendor's own product. Where identity itself needs work, that is scoped alongside rather than assumed.

Proof

One access model across a distributed network.

Technician reviewing device and access records at a distributed branch location
Case study
Case study · Distributed operations

A scalable technology foundation across a national franchise network.

A franchise-led group with head office, company-owned and independently operated sites moved from uneven local control to one managed, visible and consistent operating model.

Read the case study
FAQs

Managed SASE, answered.

What is SASE, in plain terms?

Secure Access Service Edge is the replacement for the old model where security lived in a box at the office. Access, filtering and inspection move into a cloud service that follows the user, so the same rules apply whether someone is in the office, at home or on a client site.

Does this replace our VPN?

In most cases, yes. Traditional VPN puts a device on the whole network and trusts it. We replace that with identity-based access to named applications, so a compromised laptop cannot reach systems the person was never meant to touch.

Will it slow people down?

It usually does the opposite. Connections are brokered to the nearest cloud point of presence rather than backhauled to a head office firewall, and there is no client to remember to switch on. Most users notice the login, not the network.

Do we still need a firewall at the office?

You still need local network protection where you have on-site infrastructure, printers and guest access. SASE changes what that firewall is doing: it stops being the single choke point for every remote user and every internet request.

How does this help with compliance?

Access becomes explicit and evidenced. You can show who can reach which application, on what conditions, when access was granted and when it was removed, plus web and DNS activity records. That is what an ISO 27001, SOC 2 or cyber-insurance assessor asks for.

Can contractors and third parties be covered?

Yes, and this is often the strongest reason to adopt it. A contractor is given time-bound access to the two applications they need, on a device that meets a posture standard, without an account on your internal network.

How long does deployment take?

A typical small or mid-sized estate runs to a few weeks: discovery and policy design, a pilot group, staged rollout by site or team, then VPN decommissioning once the access model is proven.

How is it priced?

As a monthly subscription on a twelve month agreement, priced per protected user with network locations included, plus a one-off onboarding fee covering discovery, policy design, pilot and rollout.

Find out what your remote access
actually allows.

We map who can reach what today, design the access model you should be running, then operate and evidence it.