SASE for SMBs: Enterprise-Grade Security Without Enterprise Complexity

Most small businesses still secure their networks the way they did when everyone worked in the office: a firewall at the door and a VPN for anyone outside it. SASE, short for Secure Access Service Edge, moves the firewall, web filtering, and remote access into the cloud, where the same policy follows every user and device. When vendors talk about SASE for small business, they usually mean enterprise security at a smaller price. For an MSP, the better reason is that it takes perimeter hardware off your patch list, and that hardware is where attacks are landing.

Exploiting a vulnerability is now the most common way attackers get in, according to Verizon's 2026 Data Breach Investigations Report: 31% of breaches started that way, overtaking stolen credentials for the first time in the report's 19 years. Among small and medium-sized businesses, exploitation was the entry point for 26% of breaches, against 13% for credential abuse, and Verizon notes that small organizations are disproportionately hit by ransomware. Coalition's Cyber Threat Index 2025 put the pattern in claims terms: 58% of the ransomware claims it saw in 2024 started with attackers compromising a perimeter security appliance, such as a VPN or a firewall.

Those appliances are usually yours to patch. Verizon found that organizations fully remediated only 26% of the critical vulnerabilities on CISA's Known Exploited Vulnerabilities list in 2025, down from 38% the year before, and that the median time to full resolution rose to 43 days, from 32. Every client running its own firewall and VPN adds another device to that queue, and another window in which a known flaw stays open.

The fix is to change where enforcement lives. When it moves off an appliance the client owns and onto the user and the device, the MSP's job changes from maintaining perimeter hardware to writing access policy, and that is work a small team can do well.

What SASE for an SMB means when nobody on staff runs the network

In an enterprise, the case for SASE is consolidation: one cloud service in place of a firewall, a web gateway, DNS filtering, and remote access bought as separate boxes. In a 25-person accounting firm with no IT staff, the bigger win is that there is no longer a perimeter appliance for anyone to forget about.

NIST SP 800-207 describes the alternative: zero trust assumes no implicit trust is granted to users or assets based solely on their physical or network location. For most SMB clients, location stopped meaning much the first week someone took a laptop home. SASE is how you put that idea into practice.

Cloud-delivered security that follows the user, not the building

An agent on each device sends traffic to the nearest point of presence, where policy is applied first. The same web filtering, firewall rules, and application access apply at the office, at home, and on hotel Wi-Fi. There is no appliance to size for the office's bandwidth and no second policy for remote staff.

SASE is not SD-WAN, though clients often hear them pitched as the same thing. SD-WAN decides how traffic moves between sites. SASE decides whether that traffic should be allowed at all. Clients will ask which one they are paying for, so it helps to know the difference between SASE and SD-WAN cold.

Why the VPN became the riskiest box your client owns

A VPN concentrator is a login page on the public internet that grants broad network access to whoever gets past it. Each half of that sentence causes its own trouble. The joint advisory from the Canadian Centre for Cyber Security, CISA, the FBI, and partners states that VPN solutions have been identified in many high-profile cyber incidents.

The public login page turns every advisory into a patching race. In January 2024, CISA issued Emergency Directive 24-01 in response to widespread and active exploitation of Ivanti Connect Secure and Ivanti Policy Secure. Federal agencies were ordered to disconnect every instance by February 2, 2024, and had staff to do it. A dental practice with a VPN appliance in the closet had you, and you had every other client's appliance to patch too.

The broad access makes stolen credentials far more dangerous. Coalition found stolen credentials were the initial access vector in 47% of ransomware claims. A VPN that admits a valid username and password to the whole office subnet turns one phished login into access to every device on it. For the longer vulnerability history, see why MSPs are moving from VPN to SASE.

You can patch faster and enforce MFA on the VPN, and you should. But an appliance whose job is to face the internet will keep facing it, and no patch cadence changes that.

How to replace a small business VPN with secure remote access

The replacement for the VPN is zero trust network access, or ZTNA. Instead of admitting a user to the network, ZTNA denies everything by default and grants access to specific applications based on identity, device, and context. There is no login page sitting on the public internet for anyone to find. For the full model, see what ZTNA is and how it differs from a VPN.

Inventory what the VPN is for before you remove it

In most small businesses, the VPN does three or four jobs nobody wrote down. Someone reaches a file share, someone opens a line-of-business app on a local server, and the owner remotes into an office machine. Pull the VPN's connection logs, talk to the people who appear in them, and list each destination with the users who need it. That list is your first access policy.

Publish each application to the group that needs it

Map every destination on the list to a user group and publish it through ZTNA to that group only. The bookkeeper reaches the accounting server. The front desk reaches the scheduling system. Nobody reaches the server's management interface except you. Add conditional access on device posture, so an unmanaged personal laptop with valid credentials still does not get in.

Blueclone Networks took on a manufacturing client after a ransomware breach. Its remote access ran through four RDP servers in Azure, exposed on public IPs and authenticated over OpenVPN. Moving that client to SASE eliminated the VPN and RDP servers, which saved $6,000 a year, and cut 15 hours a week of helpdesk tickets.

Close the old listener and confirm it is gone

The migration is done when the VPN's internet-facing port stops answering, not when users stop complaining. Disable the listener, remove the port forward, and scan the client's public IPs from outside to confirm nothing still responds. Coalition found that more than 65% of businesses applying for insurance had at least one internet-exposed web login panel, and a forgotten VPN portal is an easy way to end up in that group.

Which network security controls a small business needs first

Turning on every SASE control on day one buys you a week of tickets and a client who wants the old setup back. Order the controls by how much protection they add against how much friction they create.

Start with DNS filtering, because users will not notice it

Secure DNS blocks requests to known malicious and newly registered domains before a connection is made. It rarely breaks anything or needs exceptions, and it stops many phishing links and malware callbacks at the first step. Turn it on for every device in the first week.

Put a web gateway in front of every device, not every office

A secure web gateway adds category filtering and content inspection, but only with SSL inspection, because it cannot filter encrypted traffic it cannot read. It is also where most of the friction comes from. Plan exclusions for banking, health portals, and any application that pins its certificates, and run the policy in monitor mode before you enforce it. Our guide to SASE web filtering covers how to structure categories so you are not writing exceptions every week.

Write firewall rules for users, not subnets

The office firewall's rules were written for IP ranges. A cloud firewall can apply rules to a user and a device wherever they are, which means the bookkeeper's rules travel with the bookkeeper. Rebuild the rule set around roles, keep it short, and log what each rule blocks so you can show the client what it is doing.

Segment the office LAN so one laptop cannot reach everything

Inside the office, most SMBs still run a flat network, with printers, cameras, and the old server on the same segment as every laptop. Microsegmentation applies zero trust on the local network, so a compromised device cannot scan and reach its neighbors. Todyl's approach to zero trust on the LAN is one example of how that works.

What makes a SASE solution affordable for a small business

The license is usually the smallest line in the cost comparison, next to a firewall that will need replacing, VPN licensing, the server the VPN terminates on, and the hours your techs spend patching all of it. SASE takes most of those costs off the client's budget, and most of those hours off yours. Gather figures like Blueclone's from your own clients before you quote.

Be careful with products sold as affordable SASE that turn out to be DNS filtering with a new name. Ask four questions of anything you evaluate. Does it inspect encrypted traffic? Does it replace remote access with per-application ZTNA, or does it still hand out network access? Does it run from a single agent, or do you deploy a separate client for each function? Can you manage every client's policy from one console? A product that fails two of those will cost you more in labor than it saves in licensing.

Apply the same test to the rest of your stack. A bundle is not a platform unless the modules share an agent and a data model, and you feel the difference every time you onboard a new client.

How to roll out SASE to a small business client in phases

Start with a pilot group of two or three users, and include the owner and one person who works remotely. The owner will flag friction fastest, and the remote worker tests the path that matters most. Deploy the agent, turn on DNS filtering, and put the web gateway in monitor mode.

After the pilot, extend the agent to every device, build exclusions from what the gateway would have blocked, then enforce web policy across the client. Give it a review window measured in weeks, not days, before you move on.

The ZTNA cutover comes last, because it is the change users feel most. Publish applications from your inventory, run ZTNA and the VPN side by side for a short overlap, then disable the VPN on a date the client agreed to in writing. Keep a documented break-glass path for yourself, so a policy mistake on a Friday evening does not leave you locked out of the client's server.

Tell the client what will change for their staff before each phase, in their terms. Staff tend to shrug off a blocked site they were warned about and escalate one they were not.

Where SASE for small business becomes an MSP service line

SASE sells best when you stop selling it as a product. Make it your remote access and network security standard, priced per user, inside a tier the client already understands. The platform guide recommends per-user tiering over itemizing tools, and SASE fits that model because the agent is per device and the policy is per user.

The client conversation gets simpler too. Instead of quoting a firewall replacement or explaining a weekend emergency patch, you tell the client their staff can work from anywhere under the same rules, and you can show them the logs.

That evidence matters at renewal. When a client's insurance application asks how remote access is secured, an MSP that can produce a per-client access policy and the logs behind it has a better answer than a checkbox, which is the broader case we make in how cyber insurance is forcing MSPs to get serious about GRC. It is also a reason to price the service above a commodity tier, and our post on the value SASE lets MSPs deliver covers how to package it.

The part of SMB network protection you cannot build yourself

Most of a SASE rollout is policy work. The inventory, user groups, web exclusions, role-based firewall rules, and phased cutover are all work your team can do this quarter. The enforcement layer underneath is a different matter. That layer means points of presence close to every user, inspecting encrypted traffic at speed and patched on someone else's schedule. An MSP cannot justify building it, and a 40-person client cannot justify buying it as hardware.

That layer is what Todyl SASE provides. The policy you write applies through a single agent and runs on more than 40 global points of presence, with ZTNA and conditional access replacing the VPN and a next-generation firewall with full SSL inspection replacing the box in the closet. You manage it across clients from one console. Commercially, remote access becomes a standard you can write into every client agreement and hold, because the edge is no longer an appliance waiting on your patch ticket. See the platform.

AI Defense Readiness Assessment

Evaluate your security posture against AI-powered attacks and get recommendations to close any gaps.

Stay on the Cutting Edge of Security

Subscribe to our newsletter to get our latest insights.