Case study SASE/SSE: One set of rules for twelve countries
Sites and users in twelve European countries, one shared access and security model: KAEMI introduced SASE/SSE with Cloudflare One at a Swiss retail company and has managed the platform completely ever since, up to handling the tickets directly.
The starting point
Twelve countries, grown structures: access to internal applications and the way to the internet had been solved differently in each country over the years. Every island worked on its own, but nobody could steer security and access consistently across all countries, and every change meant manual work in several places.
Add the reality of work: employees work at the site, at home and on the road. A security model that ends at the office door no longer fits. What was needed was an approach that ties access and protection to identity instead of location, and that can be steered centrally.
The answer: SASE/SSE based on Cloudflare One, introduced by KAEMI as a Cloudflare partner and managed as a full managed service ever since. As usual for references, we do not name the customer.
The project at a glance
- Industry
- Retail
- Location
- Switzerland, sites and users in 12 European countries
- Solution
- SASE/SSE with Cloudflare One
- Scope
- Zero Trust Network Access, secure web gateway, DNS filtering
- Service
- Full managed service: 24/7 management including direct ticket handling
Anonymised at the customer's request.
The approach
Why SASE/SSE was the right path here
SASE/SSE moves access control and web security to the edge: close to the user, steered centrally. Six reasons tipped the scales in this project.
Access by identity, not by network
Classic remote access puts users onto the network; Zero Trust Network Access puts them in front of the application: whoever signs in gets exactly the applications of their role, verified on every access. That shrinks the attack surface a single compromised account can open.
Coffee shop networking
Users are highly distributed, from sites to home offices to the road. The model therefore treats every network like the Wi-Fi of a café: the transport network is not trusted; security and access come from the edge. The office network is no longer a special case, just one network among many.
Device posture
It is not only who accesses that counts, but also with what: the state of the device feeds into the access decision, such as whether it is managed, the disk encrypted and the protection up to date. An account on an unknown or unmaintained device gets less access, or none.
Twelve countries, one set of rules
Before the project, the country setups had grown independently: different configurations, different upkeep. With SASE/SSE the policies are managed centrally and apply the same way everywhere, without traffic taking detours through a central data center.
The same protection in every place
Whether at a site, at home or on the road: web access runs through the same security functions, from DNS filtering to the secure web gateway. Protection no longer depends on which country or network someone happens to be working in.
Platform plus management
A SASE/SSE platform is only as good as its upkeep: policies change, applications get added, users have questions. So the operating model was part of the design: a full managed service by KAEMI, including handling the tickets directly.
The solution
What Cloudflare One takes on in this project
Three building blocks carry the model. All three run on the same platform and follow the same set of rules, from the first country to the twelfth.
Zero Trust Network Access
Access to internal applications runs through Cloudflare One instead of classic VPN tunnels: identity, device and context decide what is reachable. New applications are published by creating a policy, not a new tunnel.
Secure web gateway and DNS filtering
The path to the internet is filtered at Cloudflare's edge: known malicious sources, phishing domains and unwanted categories, for all users in all twelve countries under the same set of rules. Local breakouts keep the paths short.
One console for everything
Access, policies and logs live in one management interface instead of a dozen per-country islands. That makes changes traceable and is the basis for KAEMI managing the service as a whole.
The approach
Four phases to a managed SASE/SSE
Nobody migrates twelve countries in a weekend. So the rollout followed one principle: prove first, then extend, and the fallback stays until nobody needs it any more.
-
Analysis and target picture
Which applications, which user groups, which access paths in which country: first the existing access landscape was mapped, then the policy model designed. One target picture for all twelve countries instead of twelve individual solutions.
-
Pilot with real users
A pilot group worked through Cloudflare One first, in parallel to the existing access. That surfaced the special cases, such as legacy applications and country-specific quirks, before they could slow down the rollout.
-
Rollout country by country
Then the step-by-step migration across the countries, user group by user group, during normal business. The old access technology remained as a fallback per country until the new platform had proven itself in daily use.
-
Full managed service
Since go-live, KAEMI has managed the platform completely: policies, changes, monitoring and the direct handling of tickets, from the first report to the resolution. The internal team sets the requirements; KAEMI takes care of the rest.
The result
What the company has today
- One set of rules for access and web security across twelve countries instead of grown individual setups.
- Access to internal applications by identity and context, verified on every access.
- Users are equally protected at every place of work, from the site to the home office.
- One management interface for policies and logs, traceable for reviews and audits.
- A full managed service by KAEMI: platform, changes and monitoring from one provider.
- Tickets land directly with KAEMI and are handled there through to resolution, without a detour via the internal team.
SASE/SSE for your sites, managed by KAEMI
In a joint analysis workshop we look at your access paths and show what a SASE/SSE model can look like for your sites, up to a full managed service. No obligation, and specific to your environment.