Posts tagged ‘Zero Trust’
The Essential Planes Every Sovereign SASE Vendor Must Support
“Sovereign SASE” has become a loosely used claim. This post breaks genuine sovereignty into four architectural planes — data, control, management, and jurisdiction — and shows how Versa Sovereign SASE, built on the VersaONE platform, is architected to satisfy all four, plus the questions that pressure-test any vendor’s claim.
The Trust Layer: How Versa Delivers AI-Driven NetOps with Explainability and Zero Trust Guardrails
AI in NetOps is transitioning from passive alerting to active decision support and execution, but adoption depends on whether engineers can trust it. Learn how Versa’s single-OS platform, unified data lake, Versa Verbo Copilot, and patent-pending Zero Trust MCP Server deliver AI-driven NetOps with explainability and governance built in.
The New OWASP GenAI Top 10 and Why Network Security Matters
Almost every risk in the 2026 OWASP GenAI Top 10 leaves observable artifacts at the network layer. This post walks through all ten categories, real-world incidents behind each one, and the specific SASE controls (SWG, CASB, DLP, ZTNA, RBI) that catch what app-layer guardrails miss.
Pervasive Security and Why the AI Era Needs a New Security Model
Attackers now exploit in hours while breaches take months to contain. Fragmented tools can’t close that gap. Here’s the case for Pervasive Security.
Beyond the Console: MCP and the New Operating Model for Enterprise Infrastructure
Enterprises are converging on the Model Context Protocol (MCP) to connect AI agents to networking and security infrastructure. This piece looks at why an enterprise routing and governance layer, not just vendor-specific MCP servers, is becoming essential for provisioning, troubleshooting, and threat hunting across a multi-vendor stack.
Your Next Switch Refresh Is an Architecture Decision, Not a Purchase Order
Campus switching estates turn over every five to seven years, and the refresh is usually run as a procurement exercise rather than an architectural one. This post examines the operational costs that sit outside the hardware line item, explains why software-defined networking largely stopped at the WAN edge, and shows how Versa Secure SD-LAN extends one fabric and one operating system into the LAN so that the refresh becomes the moment the operating model changes.
Beyond Integration: Why a Truly Unified Branch Needs Intelligent Edge, Pervasive Security, and AI-Native Operations
Piecemeal SASE creates security debt. See how Versa unifies pervasive security, intelligent edge, and AI-native operations on one platform.
The Network Is the Platform: Why Convergence at the WAN, LAN, and Security Defines the Next Era of Infrastructure
The network is no longer beneath the platform — it IS the platform. Learn why converging SD-WAN, SD-LAN, and SSE on one stack matters.
Your Next Firewall Refresh Is a Strategic Decision, Not a Renewal
Firewall refresh cycles feel like renewal paperwork—but they’re actually your best window to rethink security architecture. With switching costs at their lowest, this is the moment to move beyond legacy perimeter defense or poor device performance toward Zero Trust, SASE, and consolidated platforms, delivering higher performance at lower cost. Get the 6-step roadmap for a refresh that pays off for years.
Designing for Failure: Why DDIL Must Be the Starting Point
DDIL is the expected condition in modern tactical operations. See how multi-transport SD-WAN keeps warfighters connected when links fail.
Product & Engineering
Accelerating Digital Transformation with Secure SD-WAN
By The Versa Team
SASE Technical Professionals
April 2, 2020
Fiserv is the biggest financial company you may never have heard of. Every non-cash financial transaction that you conduct touches their network. Security is paramount for you—the consumer; for Fiserv’s clients—financial institutions, point-of-sale and payment industries in more than 100 countries; and for Fiserv’s global corporate network. Look at the staggering numbers on the right! If a company this size can successfully deploy a Secure SD-WAN, then the early adopter phase must be long over. It is. Mainstream companies like Fiserv are now deploying SD-WAN technology to manage—or survive—this era of rapid digital transformation. Which is not necessarily super-disruptive: SD-WAN…
Industry Insights
Enterprises Need to Keep Edge Networks Safe
By The Versa Team
SASE Technical Professionals
October 6, 2019
With enterprises investing heavily to transform themselves digitally, the threat environment has in many respects intensified and diversified. Enterprises pursuing a hybrid cloud or multi-cloud strategy, or relying on a software-as-a-service model to give remote workers access to critical applications, perhaps via a mobile device, will be potentially exposing themselves to new threat vectors that must be built into an already long list of security considerations for WAN edge optimization. As enterprises look for ways to accelerate their digital transformation journeys and to achieve greater business agility, they must match that by transforming their wide-area network to be more software-driven….
Industry Insights
Mitigating Sophisticated Security Threats at the WAN Edge
By The Versa Team
SASE Technical Professionals
March 20, 2019
According to several industry surveys, it takes the typical enterprise over 200 days to discover a security breach, such as undisclosed web vulnerabilities or spearfishing for email credentials, according to the 2018 Cost of a Data Breach Study: Global Overview from IBM Security and Ponemon Institute. The study calculated that the global average cost of a data breach is $3.86 million, up 6.4% from last year. The average cost, globally, for each lost or stolen record containing sensitive and confidential information is also up from last year, landing at $148 per record or a 4.8% increase from 2017. Although the…
Research Lab
Internal Network Exposure via UPnP NAT Injection
By Winny Thomas
Principal Security Architect
December 5, 2018
Universal Plug-n-Play – (UPnP) is a suite of protocols that enables a device to discover other devices on a network, configure itself to operate in the network, and advertise its services. This allows a device to locate routers, printers and other resources on a network. UPnP runs on UDP port 1900 and communicates using SOAP messages over HTTP. The actual configuration and management interface are implemented using a SOAP-based HTTP service running over a dynamically allocated TCP port. The UPnP protocol allows management of aspects of a device’s operation to extend support by the protocol implementation on the device and its…
Research Lab
Lateral Movement – Definition, Causes & Protection
By Winny Thomas
Principal Security Architect
October 5, 2018
Lateral Movement Definition: Lateral movement is a technique used by cyber attackers to infiltrate and move through a network with the intent of obtaining secure data. The Cause The term “Lateral Movement” has been around for a little over four years and was in the news when ransomware like WannaCry and APT’s like APT28 and APT29 used lateral movement techniques. Most often an attacker may not have direct access to a machine or resource on the internal network, which the attacker considers a prized trophy. The prized trophy may be the domain controller, a machine hosting confidential information, or the…
Industry Insights
Limit Impact of Data Breaches with SD-WAN Segmentation
By The Versa Team
SASE Technical Professionals
August 15, 2018
The 2018 Data Breach Investigations Report (DBIR) compiled by Verizon is loaded with cloak and dagger cyber events conducted by both known and unknown bad actors and mechanisms. Verizon identified 53,000-plus incidents and 2,200 breaches in only 12 months, suggesting an information parallel universe in which an uneven playing field exists whereby the bad guys and rouge bots consistently probe from the outside. Here are some of the key findings in terms of actual breaches: 73 percent were perpetrated by external forces 50 percent were carried out by organized crime groups 48 percent were due to hacking; 30 percent from…
Industry Insights
Security Breaches are often Network Breaches
By The Versa Team
SASE Technical Professionals
August 6, 2018
Once again, recently we heard about an enterprise that succumbed to a major security breach. Shipping giant COSCO lost email and IP phone connectivity throughout their entire US network. And without finding the cause, the company shut down networks within other regions. This example, along with countless others, solidifies the point that distributed networks and security are inherently symbiotic. COSCO says the incident was a network breakdown that led to the ransomware infection. While some are arguing it was the network, others say it was a Malware security breach. The COSCO event was not only a network breakdown, it was…
Product & Engineering
Building a Secure Architecture for the Enterprise Edge with SD-WAN
By The Versa Team
SASE Technical Professionals
July 24, 2018
Typically, WAN solution vendors talk about performance in terms of speeds and feeds. But, I like to think about performance as it relates to all aspects of connectivity. This includes speed, control, visibility, reliability, ease of deployment and monitoring, and of course security. I think about it in these terms because each of these areas are controllable by the right holistic SD-WAN architecture. Unfortunately, the accumulation of multiple disparate routing and switching devices, including firewalls, intrusion detection and threat mitigation, makes it difficult to obtain network visibility and correlate real-time events that can degrade or disrupt performance. With Secure SD-WAN,…
Industry Insights
3 Strategic Imperatives for Winning the Secure Cloud Transition
By The Versa Team
SASE Technical Professionals
July 6, 2018
Networking and security IT infrastructures have evolved to a level of complexity unmanageable by operators and enterprises using a conventional approach. The ongoing reliance upon legacy network hardware and disjointed WAN architectures inhibit the operational agility required by global organizations looking to digitize business services with secure, multi-cloud connectivity. The intersection of network reliability and application performance requires a more flexible, versatile network architecture with security and cloud integration at the forefront; thus, optimal WAN-path selection alone is no longer good enough in a multi-threaded threat environment. Large-scale enterprises with far-flung remote locations and highly distributed data centers are facing…
Subscribe to the Versa Blog
Recent Posts
The Essential Planes Every Sovereign SASE Vendor Must Support
By Anuj DutiaSeptember 17, 2026
Pervasive Security and Why the AI Era Needs a New Security Model
By Dhiraj SehgalSeptember 1, 2026
Topics
Top Tags
Gartner Research Report
2026 Gartner® Magic Quadrant™ for SASE Platforms
Versa has for the fourth consecutive year been recognized in the 2026 Gartner Magic Quadrant for SASE Platforms1 and is one of only 12 vendors that met the criteria for inclusion based on the analysts’ evaluation of the VersaONE Universal SASE Platform.




