Secure Networking Is a P&L Issue Now, Not Just an IT Issue
Ask most boards what they think “network security” costs them and they’ll point to a line item for firewalls and circuits. Ask what it’s actually costing them and the honest answer includes the deals slowed by a due-diligence questionnaire, the plant that lost four hours of production because a VPN concentrator fell over, the support tickets from a sales team that can’t reach Salesforce from a hotel Wi-Fi network and the breach that took 292 days to fully resolve because it started with a stolen credential.
That’s the real budget. Most of it never shows up in a network diagram.
You already know the acronyms — SD-WAN, SASE, SSE, ZTNA. This isn’t another explainer of what they stand for. It’s a case for treating secure networking the way you’d treat any other capital allocation decision: by the business outcome it buys, not the technology it’s built from.
The Old Scorecard No Longer Predicts the Right Things
For two decades, network architecture was graded on uptime and bandwidth. Connect the office, connect the branch, keep the lights on. That scorecard made sense when “the business” mostly happened inside buildings you controlled and on a network you owned end to end.
It doesn’t predict the things that now determine whether IT is seen as an accelerant or a drag:
● Deal velocity: Can a newly acquired subsidiary or a new market entity get secure access to core systems in weeks or does it take a quarter of network re-architecture?
● Workforce output: Is a distributed sales or field-service team as productive on a hotel network as they are in headquarters?
● Resilience: When a circuit or a data center fails, does the business notice?
● Exposure.: How much of the network can a single stolen credential reach?
Gartner projects the SASE market will grow at a 26% compound annual rate through 2028, reaching $28.5 billion — not because CIOs love new acronyms, but because work-from-anywhere has spread users, devices, and applications across the globe, and enterprises need scalable, location-independent access to match. The demand signal is coming from the business side of the house, even when the purchase order routes through IT.
What This Actually Looks Like in a P&L
Three examples, deliberately unglamorous, because that’s where the money is:
A regional manufacturer with 40 plants. Every plant ran its own VPN back to a central data center. A ransomware incident at one site didn’t stay contained to one site — the flat network let it reach shared file servers touching a dozen plants. Segmenting access by identity and device posture instead of by network location turned a plant-wide outage risk into a single-site incident. That’s not a security win to file away; it’s insurance against a multi-week production stoppage.
A professional services firm expanding into three new metros a year. Standing up a new office used to mean a firewall, a circuit order and six weeks of network engineering before the first consultant could bill a client from that location. Moving identity and policy to the cloud instead of the branch closet cut that to days, because “new office” became a config change instead of a hardware project.
A retailer with a seasonal contractor workforce. Contractors got full VPN access because scoping anything narrower took too much engineering time per contractor. That meant thousands of seasonal accounts with more network reach than the job required — exactly the kind of overprovisioned access that shows up in breach postmortems. Narrowing access to the specific application a contractor needs, rather than the network segment it sits on, removed that exposure without slowing down hiring.
None of these are stories about SASE, specifically. They’re stories about what happens when access is designed around identity, device, and application rather than around physical network topology. The architecture is the mechanism; the outcome is the point.
Why the Financial Case Has Gotten Sharper
Two numbers, both current, both worth putting in front of a CFO.
First, the downside. IBM’s 2025 Cost of a Data Breach Report puts the global average cost of a breach at $4.44 million, and breaches that trace back to compromised credentials or exploited edge devices are the expensive, slow-burning kind — the same report found supply chain compromise took the longest to resolve, at 267 days, and separately, credential-based incidents dragged on nearly as long. Legacy VPN infrastructure and flat, trust-the-network architectures are disproportionately represented in that category; they grant broad access on the strength of a single successful login rather than continuously verifying identity, device health, and context.
Second, the upside, when organizations move deliberately. A Forrester Total Economic Impact study commissioned by Cloudflare found a composite organization realized a 227% ROI and $21.4 million in net present value with payback in under six months, with benefits attributed to reduced downtime, streamlined IT operations and improved access performance. A separate Forrester TEI study commissioned by Zscaler found 289% ROI for Zscaler Private Access, driven by productivity gains, operational efficiency and reduced breach risk.
Vendor-commissioned studies deserve the usual skepticism — every composite organization looks a little more like a best-case scenario than your own environment does. But the direction of both studies is consistent with what shows up independently in breach-cost data: the expensive failure mode is broad, static, network-level trust and the return shows up in fewer incidents, less operational drag and less time spent managing access exceptions by hand.
The Diagnostic Questions…for Someone Who Already Knows the Stack
You don’t need a primer on ZTNA versus VPN, or SSE versus a proxy. You need a clear-eyed read on where your current architecture is quietly taxing the business:
● Where does a network-level trust boundary still stand in for an identity-level one (i.e., where does “on the VPN” or “on the corporate network” substitute for verifying who and what is actually connecting)?
● Which applications still get reached via a network path when the connection should be application-specific and identity-scoped instead?
● How long does it take to grant and, more importantly, to revoke access when someone changes roles, a contractor leaves or an acquisition closes?
● Where does the security team’s visibility stop being contiguous (the point where a firewall log, a CASB report, and an identity system stop telling a single, correlated story)?
● Which locations or business units are still riding legacy circuits and hub-and-spoke backhaul because nobody has made the case to change them?
The answers point to a prioritized list, not a platform decision. Some organizations have a branch-performance problem. Some have a legacy-VPN-as-attack-surface problem. Some have a fragmented-tool-visibility problem. Rarely are all three the same size and the sequencing matters more than the vendor logo.
SD-WAN Solves Half the Problem, on Purpose
It’s worth being precise about what SD-WAN does and doesn’t fix, because vendors blur this line constantly. SD-WAN is genuinely good at what it’s for: routing traffic intelligently across broadband, private & wireless links; prioritizing latency-sensitive applications; and giving branches automatic failover instead of a single point of failure. For a distributed retailer or a manufacturer with plants on mediocre local circuits, that’s a real, measurable resilience and performance gain.
What it doesn’t do is decide who should be allowed to reach what. That’s an identity and policy question, and it’s the one that shows up in breach reports. Pairing SD-WAN with cloud-delivered security (SSE for the security controls, SASE as the combined architecture) is how organizations get both the performance gain and the access-control gain in one design, rather than treating them as sequential projects five years apart.
Where the Market Is Actually Headed
This isn’t a fringe bet. Gartner expects that by 2026, 60% of new SD-WAN purchases will be part of a single-vendor SASE offering, up from 15% in 2022 — a sign that buyers are increasingly unwilling to stitch together networking and security as two separate procurement tracks. Roughly half of enterprises surveyed by Gartner plan to invest in SASE platforms within the next three years. That’s not a trend chasing a Gartner buzzword; it’s buyers converging on the same conclusion from different starting points — networking teams tired of backhaul, security teams tired of blind spots.
Start With a Business Case, Not an RFP
The sequencing that works: Start with the workflows that generate revenue or carry the most risk, map how access to them actually happens today (not how the architecture diagram says it happens) and prioritize the two or three gaps that are costing the most in either exposure or friction. Only then does the technology conversation (SD-WAN, SSE, SASE, ZTNA, identity modernization) become a way to close specific, quantified gaps rather than a category to shop.
The organizations getting real value out of this shift aren’t the ones with the most complete acronym coverage. They’re the ones who can say, specifically, what got faster, what got safer and what it was worth.