The office moved. Your security perimeter should follow.
Most businesses still protect a building their people rarely sit in. Managed SASE moves access and inspection into a cloud service that follows the user: identity-based access to named applications, filtering that works on any network, and device conditions that are checked before anyone connects.
- Verify
Identity and device state, checked every time.
- Connect
Access to the application, not the network.
- Prove
Access, activity and change, on record.

Why remote access is the weak point.
Four ways the network became the thing people are trusted on.
That made sense when everyone was in one building. It is now the shortest route an attacker has, and the hardest thing to evidence when someone asks who can reach what.
VPN trusts the whole network
One connected device, one set of stolen credentials, and the attacker is inside everything.
Access nobody can evidence
Nothing shows who can reach which system, or when a leaver's access actually stopped.
Traffic dragged back to the office
Remote users route through a head office appliance that was never sized for them.
Unmanaged devices and third parties
Contractors and personal devices reach business systems with no posture standard applied.
A managed lifecycle that keeps running after go-live.
Access policy decays the moment people change roles, applications are added and projects end. The service keeps the model current, so what is written down is what is in force.
Discover
Map users, sites, applications, third parties and current remote access paths.
Design
Define who may reach what, on which devices, under what conditions.
Pilot
Prove the access model with a representative group before anyone else moves.
Roll out
Staged deployment by site and team, with VPN retired once access is proven.
Operate
Policy changes, joiners and leavers, filtering tuning and incident support.
Report
Monthly access, activity and exception reporting to leadership.
What the service includes.
- Zero trust application access
- Secure web gateway
- DNS and content filtering
- Device posture checks
- Identity-based policy
- Site and branch connectivity
- Third-party and contractor access
- Access reporting and review
Zero trust access to applications
People are granted access to named applications rather than to the network. Access is tied to identity, group and device state, so a person only ever sees the systems their role requires.
VPN replacement without the friction
Connections are brokered through the nearest cloud point of presence instead of being backhauled to a head office firewall, so remote work stops depending on one appliance and one internet line.
Secure web and DNS filtering
Web traffic and DNS requests are inspected and filtered wherever the user is working, blocking malicious destinations, phishing infrastructure and categories your policy does not allow.
Device posture as a condition of access
A device must meet an agreed standard, such as encryption, patch level and endpoint protection, before access is granted, and access is withdrawn when the device drifts out of standard.
Controlled third-party access
Contractors, auditors and vendors receive time-bound access to specific applications from devices you can check, without an account that lives on your internal network.
Managed policy and change
Joiners, movers and leavers, new applications, new sites and exception requests are handled as part of the service, with every change recorded rather than made quietly in a console.
Access designed around the people who need it.
Every organisation has more than one kind of user: employees, contractors, seasonal staff, auditors and directors on their own devices. Each needs a different answer, and each answer has to be written down before it can be enforced.
We design the access model against those groups, then run it as a service so it stays accurate as roles, applications and sites change.
See how this pairs with cyber resilienceOpen any item for what falls in scope, the policy we design to, what it changes in practice and the evidence you receive.
Hybrid and remote employees
People working from home, from client sites and while travelling, needing the same protection they would have in the office.
- Managed laptops and desktops, the applications each role requires, and the internet traffic those devices generate.
- Access by identity and group, conditional on device posture, with web and DNS filtering applied everywhere the device connects.
- One consistent security position regardless of location, with no dependence on a user remembering to connect a VPN.
- Per-user access entitlements, connection records and filtered-request reporting.
Private applications and internal systems
Line-of-business systems, file servers, finance and practice platforms that were historically reached over VPN.
- Named internal applications published individually, with the underlying network kept unreachable.
- Least-privilege access per application, granted to roles rather than to devices, and reviewed on a schedule.
- Lateral movement is removed as an option: a compromised device cannot scan or reach what it was not published to.
- Application publication list, access matrix by role and a dated record of access reviews.
Branch offices and multiple sites
Distributed operations where each site historically ran its own firewall, its own rules and its own drift.
- Site connectivity, inter-site access, guest and operational network separation, and internet breakout per location.
- Central policy applied to every site, with local breakout for performance and consistent inspection everywhere.
- Standards hold across the estate instead of varying by whoever last configured the local box.
- Site inventory, policy consistency reporting and exception log per location.
Contractors, vendors and auditors
Third parties who need a narrow slice of access for a defined period, and nothing beyond it.
- Specific applications, defined access windows, and the device conditions the third party must meet.
- Time-bound, application-scoped access with automatic expiry, separate from employee identity groups.
- Third-party access stops being a standing account nobody remembers to remove after the project ends.
- Third-party access register, expiry dates and activity records per engagement.
Unmanaged and personal devices
Directors on personal laptops, seasonal staff, and people using a device the business does not own.
- Which applications may be reached from an unmanaged device, and which are restricted to managed hardware.
- Tiered access: sensitive systems require a managed, compliant device, while lower-risk applications allow controlled browser access.
- A practical answer that neither blocks the business nor pretends an unmanaged device is safe.
- Device posture reporting, blocked-attempt records and the agreed exception list.
Joiners, movers and leavers
The everyday process where access risk is actually created, and where most estates quietly accumulate exposure.
- Onboarding, role changes and offboarding across every application published through the service.
- Role-based entitlement templates, so access follows the role and is removed with the identity, not per system.
- A leaver's access ends at one point, immediately, rather than across a checklist of consoles.
- Change records per identity, time to revoke and a periodic entitlement review report.
Ransomware and credential theft
The scenario the access model exists for: someone has valid credentials or a foothold on a device.
- Containment through segmentation, posture enforcement and the ability to cut access centrally.
- Explicit deny by default, per-application publication, and immediate revocation as an operational action.
- The blast radius is what one identity could reach, not the whole network the device was sitting on.
- Access logs, blocked destination records and a post-incident containment timeline.
Regulatory and insurance requirements
Where access control is not just good practice but an obligation you must be able to demonstrate.
- Access control statements, review cadence, logging retention and the reporting your obligation specifies.
- Controls mapped to the framework in play, whether ISO 27001, SOC 2, Cyber Essentials or an insurer's questionnaire.
- The questionnaire is answered from evidence already produced, rather than assembled the week it is due.
- Control mapping, access review records and retained activity logs for the required period.
Scope is agreed up front, group by group, so no one is assumed to be covered who is not.
Security that travels with the person.
The service runs on an enterprise cloud networking and security platform we licence, deploy and operate on your behalf. You do not buy the appliances, the licences or the expertise to run them. What it means in practice is that the same policy applies in the office, at home and on the road, and that it is maintained rather than left to drift.
Cloud-delivered, close to the user
Inspection and brokering happen at a cloud edge near the person working, so protection does not depend on the capacity of one office appliance.
Identity at the centre
Policy is written against people, roles and groups in your existing directory, so access reflects the organisation rather than a list of IP addresses.
Applications published, networks hidden
Internal systems are reachable only through the broker and are not exposed to the internet or discoverable from a connected device.
Posture-aware access
Encryption, patch state and endpoint protection are checked as a condition of connecting, not assumed at the point a device was first issued.
Filtering that follows the device
Web and DNS controls apply on any network, including hotel, home and mobile connections, without routing everything through the office.
Managed and monitored for you
Policy changes, alerts, blocked-access queries and tuning are handled by our operations centre as part of the service.
Who can reach what, answered on demand.
Access control is only as good as your ability to show it. Each cycle produces a plain report on who is covered, what they can reach, what was blocked and what needs a decision from you.
- Application and access inventory
- Zero trust access policy design
- Device posture standard
- Third-party access register
- Monthly access and activity report
- Periodic access review record
- Users and sites protected
- Applications published
- Device posture compliance
- Blocked and filtered activity
- Access changes and revocations
- Open exceptions and remediation
A monthly subscription, priced per user.
Managed SASE is proposed on a twelve month agreement, billed monthly in advance and sized by protected users and network locations, with a one-off onboarding fee covering discovery, policy design, pilot and staged rollout. The platform, the cloud edge capacity and the ongoing policy management are part of the service.
Onboarding
Application and access discovery, policy design, device posture standard, pilot group and staged rollout.
Managed service
Policy management, joiners and leavers, filtering tuning, monitoring, user support for access issues and reporting.
No hidden fees
Platform licensing, cloud edge capacity, site connectivity policy and access reviews. VPN decommissioning is part of the rollout.
Built for hybrid, distributed and regulated teams.
- People work from anywhere, and VPN has become the support ticket nobody enjoys.
- Multiple sites or franchise locations run inconsistent local network security.
- An insurer, client or regulator asks how access is granted, reviewed and removed.
Clear boundaries keep the position honest.
We secure access to systems inside the agreed scope. Physical network cabling, carrier circuits and third-party platform outages sit outside the service, as do application permissions owned inside a vendor's own product. Where identity itself needs work, that is scoped alongside rather than assumed.

A scalable technology foundation across a national franchise network.
A franchise-led group with head office, company-owned and independently operated sites moved from uneven local control to one managed, visible and consistent operating model.
Read the case studyManaged SASE, answered.
What is SASE, in plain terms?
Secure Access Service Edge is the replacement for the old model where security lived in a box at the office. Access, filtering and inspection move into a cloud service that follows the user, so the same rules apply whether someone is in the office, at home or on a client site.
Does this replace our VPN?
In most cases, yes. Traditional VPN puts a device on the whole network and trusts it. We replace that with identity-based access to named applications, so a compromised laptop cannot reach systems the person was never meant to touch.
Will it slow people down?
It usually does the opposite. Connections are brokered to the nearest cloud point of presence rather than backhauled to a head office firewall, and there is no client to remember to switch on. Most users notice the login, not the network.
Do we still need a firewall at the office?
You still need local network protection where you have on-site infrastructure, printers and guest access. SASE changes what that firewall is doing: it stops being the single choke point for every remote user and every internet request.
How does this help with compliance?
Access becomes explicit and evidenced. You can show who can reach which application, on what conditions, when access was granted and when it was removed, plus web and DNS activity records. That is what an ISO 27001, SOC 2 or cyber-insurance assessor asks for.
Can contractors and third parties be covered?
Yes, and this is often the strongest reason to adopt it. A contractor is given time-bound access to the two applications they need, on a device that meets a posture standard, without an account on your internal network.
How long does deployment take?
A typical small or mid-sized estate runs to a few weeks: discovery and policy design, a pilot group, staged rollout by site or team, then VPN decommissioning once the access model is proven.
How is it priced?
As a monthly subscription on a twelve month agreement, priced per protected user with network locations included, plus a one-off onboarding fee covering discovery, policy design, pilot and rollout.
Find out what your remote access
actually allows.
We map who can reach what today, design the access model you should be running, then operate and evidence it.
