Multi-cloud growth creates two problems at once: applications and data spread across providers, while users and branches need predictable access to them. A useful SASE decision must therefore account for workload identity, cloud routing, data controls and the teams responsible for operating each layer.

TL;DR: Multi-Cloud Decision Map

  • Zscaler is best for zero trust workload communication across public clouds.
  • Netskope suits teams combining multi-cloud routing with data-aware inspection.
  • Fortinet is good for coordinated network and security policy across cloud providers and on-premises environments.
  • Pilot policy portability, traffic visibility and incident ownership before committing.

The shortlist includes six complete SASE platforms and three narrower products that can support a multi-cloud design. Skyhigh Security focuses on SSE, Sophos provides a modular ZTNA path, and Darktrace adds cloud detection and response. Those distinctions matter when comparing proposals and assigning operational responsibility.

Start with four multi-cloud control questions

First, identify what receives access. A user session, workload, service account and application-to-application connection need different identity signals. NIST SP 800-207A recommends application and service identities for granular policies that work across on-premises and multiple cloud environments.

Second, map every traffic path. Include user-to-cloud, branch-to-cloud, cloud-to-cloud and traffic inside each cloud. An inspection service may protect internet access well yet require a different design for east-west workload communication.

Third, separate access enforcement from cloud posture and workload protection. CISA’s Cloud Security Technical Reference Architecture treats shared services, migration and cloud security posture management as connected but distinct operating concerns. A SASE platform should complement those controls rather than obscure ownership.

Fourth, decide who changes policy during an incident. Network, identity, cloud platform and security operations teams need one escalation path, clear logging responsibilities and a tested rollback process.

1. Zscaler: for identity-led workload communication

Best fit: businesses replacing network-based workload trust with application identity. Zscaler Workload Communications applies policies to traffic between workloads across AWS, Microsoft Azure, Google Cloud and on-premises data centers.

The proxy architecture can hide workloads from direct exposure and limit unauthorized lateral communication. It is particularly relevant when cloud teams want consistent rules across VPCs, VNets, regions and providers without extending a traditional routed mesh everywhere.

Buyers should test protocols, throughput and failure behavior for representative applications. A design that works for web traffic may need different connectors or service edges for database, API and high-volume east-west flows.

2. Cato Networks: for one cloud-delivered operating model

Practical fit: organizations ready to carry sites, users and cloud traffic through one SASE service. Cato connects branches, data centers and cloud environments through physical Sockets, virtual Sockets, IPsec tunnels and direct cloud interconnects.

All connected sites can use the same security stack and policy layer. That can reduce the handoffs between separate WAN, remote-access and cloud-security consoles when the organization accepts Cato Cloud as a common transport and inspection fabric.

Migration scope is the main design question. Teams must plan how existing MPLS, cloud transit, routing ownership and local resilience move into the service without changing every location at once.

3. Netskope: for data-aware multi-cloud networking

Practical fit: teams that need cloud-to-cloud connectivity and detailed data context in the same architecture. Netskope One Multi-cloud Networking supports user-to-cloud, region-to-region and cloud-to-cloud paths across AWS, Azure and Google Cloud.

Netskope One can steer those flows through web inspection, cloud firewall, private-access, SaaS control and data-protection services. This is useful when routing decisions and policy both depend on the application, user, activity and information being moved.

The proof of concept should examine network behavior as closely as DLP results. Validate cloud-native integrations, segmentation, latency, route recovery and visibility when traffic crosses providers.

4. Fortinet: for coordinated policy across cloud and network layers

Best fit: multi-cloud businesses that want network enforcement, cloud protection and centralized operations to share policy context. Fortinet Secure SD-WAN connects to services including AWS Transit Gateway Connect, Azure Virtual WAN and Google Cloud Network Connectivity Center while extending related security and segmentation rules.

FortiGate VM, FortiManager, FortiAnalyzer and FortiCNAPP address different parts of the environment. Together, they can connect cloud networks, centralize policy and telemetry, and add posture, entitlement, workload and code-to-cloud risk controls.

This is a platform architecture rather than one automatic bundle. Buyers should map which Fortinet components protect traffic, workloads, applications and development pipelines, then compare licensing and operational ownership against the intended scope.

Where access security meets workload protection

SASE secures connections, but a multi-cloud program also needs visibility into misconfigurations, excessive permissions, vulnerable workloads and infrastructure-as-code. Fortinet’s enterprise cloud security for multi-cloud brings CSPM, CWPP, CIEM, vulnerability management and IaC security into FortiCNAPP with agent and agentless coverage.

That adjacent layer should not be treated as proof that every SASE control is present. The architecture should show which product evaluates posture, which product enforces the connection and how the two exchange risk context.

5. Cloudflare One: for composable services on a global edge

Practical fit: businesses that want to adopt access, web security and WAN services in stages. Cloudflare One brings private-app access, web filtering, SaaS visibility, data protection, cloud firewall and network services onto one connectivity cloud.

Cloudflare Tunnel supports outbound-only application connectivity, while Cloudflare WAN on-ramps can carry branch and data-center traffic for inspection. The programmable model can suit teams that value APIs, infrastructure-as-code and incremental adoption.

Evaluate private-cloud connectivity, branch hardware requirements and traffic residency by region. Even a broad edge network requires teams to verify the on-ramp and inspection path for each workload.

Compare the operating model, not the logo

ProductMulti-cloud roleBoundary to verify
ZscalerIdentity-led workload accessProtocol and connector fit
Cato NetworksCommon network and security serviceWAN migration scope
NetskopeData-aware cloud routingCloud-native route behavior
FortinetCoordinated cloud and network policyComponent and license map
Cloudflare OneComposable global edge servicesOn-ramp and residency design
Versa NetworksFlexible deployment modelsOperational skill requirement
Skyhigh SecurityData-first SSESeparate networking layer
SophosEndpoint-informed ZTNACoverage beyond private apps
DarktraceCloud detection and responseSeparate access enforcement

6. Versa Networks: for blended deployment control

Practical fit: enterprises and service providers that need cloud, on-premises or mixed SASE delivery. Versa Unified SASE places networking and security functions in a shared stack governed through centralized policy, analytics and administration.

The deployment range can support sites with different regulatory, latency or ownership constraints. Versa can connect users, branches and cloud applications without requiring every enforcement point to use an identical delivery model.

That flexibility creates an operational choice. Buyers should define who designs routing, maintains gateways, manages upgrades and investigates events across the selected cloud and on-premises components.

7. Skyhigh Security: for data-first SSE

Practical fit: regulated organizations focused on consistent data policy across web, SaaS, email and private applications. Skyhigh Security Service Edge combines secure web gateway, CASB, Private Access, DLP and remote browser isolation.

Its data-first model can apply shared classification and policy across several control points. This can help when sensitive information moves through sanctioned and unsanctioned cloud services as well as private applications.

Skyhigh supplies the security edge rather than the whole SASE architecture. The design still needs an SD-WAN or networking layer, with tested integration between traffic steering and Skyhigh inspection.

8. Sophos: for endpoint-conditioned private application access

Practical fit: organizations using Sophos Central, Endpoint and Firewall that need a focused VPN replacement. Sophos ZTNA checks the user’s identity, requires MFA and incorporates endpoint conditions into application-specific access decisions.

Sophos supports cloud, on-premises and hybrid gateway arrangements. Security Heartbeat can restrict access when an endpoint becomes compromised, which gives existing Sophos customers a direct link between device condition and application policy.

The product remains a modular ZTNA route. Buyers needing SaaS controls, data protection, web filtering, cloud firewall and SD-WAN coverage must identify the additional services and management handoffs.

9. Darktrace: for adaptive multi-cloud detection and response

Practical fit: security teams that need behavior-based visibility across cloud assets, identities, containers, APIs and network activity. Darktrace / CLOUD learns normal patterns, identifies anomalies and supports autonomous response across hybrid and multi-cloud environments.

This layer can expose activity that a static access rule did not anticipate. It can also correlate cloud signals with Darktrace coverage across identity, email, endpoint, network and operational technology.

Treat Darktrace as an adjacent detection layer. Network transport, private-app access, web filtering, SaaS controls, data protection and firewall services must come from elsewhere.

Build the rollout around traffic domains

Begin with one traffic domain rather than one vendor dashboard. User access to SaaS, branch access to cloud applications and workload-to-workload communication each reveal different policy, routing and inspection requirements.

Use a phased sequence:

  1. Inventory users, workloads, service identities, cloud accounts and existing transit paths.
  2. Select one production-like application flow and document its normal dependencies.
  3. Apply identity, segmentation, inspection and logging rules through the proposed platform.
  4. Simulate provider failure, credential misuse, policy error and compromised workload behavior.
  5. Confirm which team investigates, approves changes and restores service.

Commercial comparison should include connectors, virtual appliances, cloud egress, log storage, endpoint agents, premium security modules, support and migration work. A low subscription price can be offset by duplicated controls or complex traffic paths.

Also test log-export delays and incident-response integrations during a cross-cloud investigation.

Multi-cloud SASE questions

Does a multi-cloud business need one SASE vendor?

No. A single-vendor design can simplify policy and support, while a dual-vendor design may preserve stronger existing network or security investments. The deciding factor is whether identity, telemetry, routing and incident workflows remain consistent across the boundary.

How is SASE different from CNAPP?

SASE protects connectivity and access for users, sites and applications. CNAPP focuses on cloud posture, identities, workloads, containers, code and runtime risk. Multi-cloud businesses often need both, with a documented exchange of risk context between them.

Which traffic should a proof of concept include?

Include user-to-SaaS, user-to-private-app, branch-to-cloud, cloud-to-cloud and east-west workload traffic. Test normal performance, policy enforcement, failover, encrypted inspection and logging for each path.

How should cloud egress costs be evaluated?

Diagram where traffic leaves each cloud, crosses regions or enters an inspection service. Model normal volume, peak volume, failover and log export. Compare the provider’s egress charges with any private backbone or cloud-native transit fees.

What should be written into the operating model?

Assign owners for identity, routes, connectors, policy exceptions, security alerts and recovery. Define approval paths, service objectives and rollback steps. The design is incomplete if every dashboard works but no team owns the handoff.

Adopt SASE in phases, not as a label

The most defensible choice follows the traffic and control model. Zscaler emphasizes workload identity, Cato centralizes transport and inspection, Netskope combines cloud routing with data context, and Fortinet coordinates network enforcement with broader cloud-security operations.

Cloudflare and Versa offer different forms of deployment flexibility. Skyhigh and Sophos cover narrower access and data-control needs, while Darktrace adds adaptive detection. A phased rollout should prove each boundary before the business expands the architecture across every cloud.

Posted by Raul Harman

Editor in chief at Technivorz and business consultant. I like sharing everything that deals with #productivity #startups #business #tech #seo and #marketing