Megatrend · Cybersecurity & Digital Trust

When the castle walls stop working — because all the workers have left to work outside the city

IT security used to be like building a castle — dig a moat, raise a wall (firewall) around the office. Anyone inside the city counts as safe. But once everyone works from home and the apps move to the cloud, the castle stands empty — people and data are all outside the walls. So the new idea flips it on its head: stop trusting anyone based on location, and check everyone every single time they ask for access (zero trust), then lift the entire security job up to the cloud (SASE). This is one of the fastest-growing markets in all of security.

Category Cybersecurity Level Specific topic Layer Infrastructure Read time ~12 min
A stone castle wall crumbling down, while people scatter to work in different places, and checkpoints float on clouds, checking each person one by one
ภาพประกอบ (hero.webp)
A wall that means nothing. Once people and data are all outside the office, putting a wall around the "city" no longer protects anything.

01What it is

Picture the old way of doing security. It's like a medieval castle — the company digs a moat and builds a high wall (called a firewall) around the office. Anyone "inside the city" (connected to the office network) is one of us, trusted; outsiders have to pass through a single city gate. This model worked well when everyone sat in the same building and all the apps lived in the server room out back.

But the world changed two things at once: people moved to working from home / anywhere, and apps moved up to the cloud (Microsoft 365, Salesforce, AWS). Now the people and data you need to protect are all outside the walls — so the castle becomes a ghost town with nothing left to defend. This is the starting point of the new idea this node is about.

This node covers two intertwined topics — Next-gen firewall (a smarter new-generation wall that can see all the way down to the app and the identity) and SASE/SSE (lifting the whole set of network-security work up to the cloud instead of a box in the office). On the megatrend map it's a sub-branch under Endpoint & Network Security within the bigger trend Cybersecurity & Digital Trust, with a sibling right beside it — Endpoint Detection & Response (EDR/XDR), which looks after the "endpoint devices." This node looks after the "path and access."

Key terms
Zero Trust · SASE · SSE

Zero Trust = the principle of "never trust anyone automatically" — verify identity and permissions every time someone asks for access, whether they're inside or outside the office · SASE (Secure Access Service Edge) = combining the "network" (SD-WAN) and "security" into a single service on the cloud · SSE = the security half of SASE (web gateway, data-leak prevention, cloud-access control) — the layer that checks every connection before letting it through.

02Why it matters — the empty castle

This node matters because it solves a problem every organization hit at the same time after the remote-work era — how do you let thousands of employees scattered around the world reach cloud apps safely, without dragging them back through a slow VPN into the office first? The answer is to lift security up to the cloud so it sits "close" to both the people and the apps.

The result is money flowing fast from "hardware boxes in the office" to "monthly services on the cloud." The SASE market alone is worth around $15–19 billion in 2025–2026, and is expected to grow toward $45–68 billion by the early part of the next decade — about 24–29% a year on average, many times faster than the security market overall.

The SASE market grows in the low double digits every year
Market size (in billions of dollars) — 2030 is a projection, the midpoint across several firms (CAGR around 24–29%)
Source: MarketsandMarkets, Grand View, Mordor (midpoint; estimate range $44–68B)
>60% of Palo Alto Networks' Network Security sales in the latest quarter came from SASE and software, no longer from hardware boxes — a sign the whole industry is moving from "selling boxes" to "selling services."
An old hardware security box dissolving into a stream of monthly subscriptions flowing up into the cloud
ภาพประกอบ (subscription.webp)
From a box to a stream of revenue. Security is shifting from selling a device once to a subscription that flows in every month.

Why does this matter economically? Because it changes the business model of the whole industry — from selling a device once to subscription revenue that flows in every month and is predictable (ARR). Companies that switch in time see their stock jump, while those still leaning on box sales alone slowly get overtaken. This is a field where "whoever moves to the cloud fastest and most completely" wins.

03How it works (from a wall to a checkpoint every time)

The heart of the new idea is a single sentence: "Don't trust anyone for their location — check every time they ask to come in." Let's put the two models side by side.

The castle-wall model versus zero trust On the left, the old model has a wall around the office and trusts everyone inside. On the right, zero trust requires every request, no matter where it comes from, to pass through an identity checkpoint on the cloud before reaching the app Old way · castle wall Wall (firewall) Everyone inside is trusted Outsiders Problem: a hacked insider = can walk through the whole city New way · zero trust + SASE Users from anywhere Checkpoint On the cloud Apps/data Pass first, then let through — every time
From a single wall to a checkpoint every time. Zero trust doesn't care whether the request comes from inside or outside the office — every access has to prove its identity at a checkpoint on the cloud first.

What makes this model win is that it closes the biggest weakness of the castle wall — in the old days, if a hacker broke into the city even once, they could walk anywhere in the whole city (called lateral movement). But zero trust checks every door every time, so breaking in at one point doesn't mean reaching everything. And because the checkpoint sits on the cloud close to the user, employees at home don't have to drag a VPN back around to the office — you get more secure and faster at the same time.

04Where it sits in the security world

This node is the "gate and path" of cloud-era security. It works in concert with the other branches of the ecosystem so tightly you can't pull them apart.

  • Pairs with EDR/XDR (endpoint devices): this node controls the "access path," while EDR controls the "device itself" (laptops, phones) — only together do the two sides close the security loop. That's why many big players try to sell both in one platform
  • Opens the door for Cloud & Digital Infrastructure: organizations only dare to move important workloads to the cloud once they have a safe way to control access — SASE is what makes "work from anywhere on the cloud" real, without the fear
  • Accelerated by AI on both sides: AI helps the defenders detect threats more cleverly at the checkpoint, but it also lets attackers build more automated attacks — a cat-and-mouse game that keeps security demand growing nonstop
  • Prepares for Quantum Computing: future quantum may crack the encryption used today, forcing a switch to post-quantum encryption — and the checkpoint on the cloud is the easiest place to upgrade
Perspective An easy way to remember it: EDR looks after the "device," this node looks after the "path" — every connection between person, device, and app has to pass through this layer first. So it's the "front line" that every organization has to invest in first when moving to the cloud world.

05Where it stands now

This field is now seeing a war called "platformization" — instead of customers buying dozens of scattered security tools, the big players try to bundle everything (firewall, SASE, EDR) into one platform and sell it as a package. Leading this game is Palo Alto Networks, whose next-generation security revenue (NGS ARR) reached about $5 billion, growing ~34%, and which poured over $28 billion into acquisitions to fill in the puzzle.

The other pole is the "cloud-native" crowd, born on the cloud from the start, led by Zscaler — the standard for zero trust proxy for large enterprises that want to ditch the old VPN — along with Netskope and Cloudflare, who shine on data and world-scale speed. Meanwhile Fortinet plays a different angle — using its own custom chips to keep the price-performance high, growing SASE billings to ~40%.

The money has already moved from "the box" to "cloud services"
Share of Palo Alto's Network Security sales coming from SASE + software (latest quarter)
Source: Palo Alto Networks Q4 FY2025 (over 60% of Network Security bookings come from SASE/software)

And just like in other tech sectors, China has its own separate ecosystem — companies like Sangfor and Qi An Xin dominate a domestic market that Western firms can't reach, reflecting how security has become a matter of digital sovereignty that each side wants to control itself.

Key players in this field
US · platformization leader
The market leader driving the "everything in one platform" game — next-generation security revenue (NGS ARR) of about $5 billion, growing ~34%, and over $28 billion poured into acquisitions to round out firewall, SASE, and EDR.
core · platform leader
ZscalerZS · US
US · pure zero-trust
Set the standard for the cloud-based zero trust proxy (ZIA/ZPA) for large enterprises that want to drop the old VPN — born on the cloud from day one, with no hardware legacy to carry.
core · zero-trust pure-play
FortinetFTNT · US
US · price-performance with its own chips
Plays a different angle with its own custom ASIC chips, delivering superior price-performance — SASE billings up to ~40%, with full SASE capability in a single operating system.
core · price-performance
CloudflareNET · US
US · global edge network
Uses its worldwide edge network to deliver security and speed at the same time — strong on zero-trust for cloud-born organizations that need low latency.
core · global edge
NetskopeNTSK · US
US · cloud-first
The SSE-side leader, strong on data protection (DLP) and cloud-app usage control (CASB) — a top choice for organizations that weigh data leakage most heavily.
core · cloud-first
CiscoCSCO · US
US · the incumbent networking giant
The traditional networking-equipment leader with an enormous customer base, racing to transform itself from "selling boxes" to cloud security — wielding both scale and customer relationships as weapons.
core · incumbent giant
China · domestic leader
One of China's network-security leaders, dominating a domestic market Western firms can't reach — reflecting China's separate, self-contained security ecosystem.
core · China leader

06The road ahead

The first direction is consolidation will intensify. Customers are tired of managing dozens of tools, so the trend is toward a handful of winning platforms that can do both "path" and "device" — good for the market leaders with the full set, but it pressures small specialized players to either find a niche or get acquired.

Many small scattered security tools being sucked into one giant single platform
ภาพประกอบ (platform.webp)
From many boxes to a single platform. The platformization war is squeezing the market down to a handful of winners.

The second direction is AI becomes both weapon and shield. The checkpoint on the cloud sees enormous traffic, making it the best place to use AI to detect abnormal behavior. At the same time, attackers also use AI to build more automated threats — this cat-and-mouse game means security demand won't fade away easily.

The third direction is the browser becomes the new front line. When almost every app runs through the browser, the point of access control shifts to the browser itself (enterprise browser) — opening a new sub-arena that both big players and startups are fighting over.

07Challenges & risks

The first risk is that the platformization war is a winner-take-all game. Once customers pick a main platform, they tend to stay locked in for a long time. Players that can't keep up or don't have the full set risk being squeezed out of the market — so this field is fierce, with acquisitions happening all the time.

The second risk is high stock valuations and the high expectations that come with them. Cloud-security stocks trade at high price multiples, because the market expects them to keep growing fast. If growth slows even a little, the price can swing hard — it's a group that's "really growing, but not cheap."

The third risk is the split into two worlds and the dependence on trust. The Chinese market is dominated by domestic players, so Western firms can't reach one big chunk of the market. And because this product is "security," trust is everything — a single outage or vulnerability can hit reputation and trust far harder than it would for an ordinary product.

The bottom line for investors Network Security & SASE is the "front line" of cloud-era security — fast-growing, with steady subscription revenue, but fiercely competitive and not cheap. Three keys: (1) who wins the platformization war (combining "path + device" most completely) · (2) is subscription-revenue (ARR) growth still accelerating · (3) who uses AI best at the checkpoint — the real value is in "the platform customers lock into and keep expanding their use of," not just who has one standout feature.

In short: this node is the story of the collapse of the "castle wall" and the rise of the "checkpoint every time on the cloud" that replaces it — a change that not only made organizations safer in the remote-work era, but also flipped the entire business model of the security industry from selling boxes to selling trust by the month.

Explore this theme — live data, stocks & news →