Zscaler & Zero Trust operations glossary ยท Access & traffic

What is SSE?

Definition

SSE (Security Service Edge) is a bundle of cloud-based security services, including zero trust access, web protection, cloud firewall and data protection functions, delivered centrally from the cloud instead of through individual appliances in a data centre. SSE forms the security-focused core of SASE, without its SD-WAN network component. For users, all internet and application access runs through this security layer, which checks identity, device posture and context on every request before letting it through.

SSE in detail

SSE typically brings several functions together: a secure web gateway for internet access, zero trust network access for applications, cloud firewall, cloud sandbox against malware, browser isolation for risky content, and data protection controls such as DLP and CASB. All these functions run on the same cloud platform and share policies, identities and log data.

That sets SSE apart from older architectures, where each function was its own appliance with its own configuration. With SSE, control is centralised, even though the individual functions remain distinct in what they do.

Why SSE matters in Zscaler operations

Because SSE bundles several functions together, a single policy change can affect multiple services at once, for example when a URL category affects both web access and sandbox behaviour. For diagnosis, that means testing individual functions in isolation is often not enough to fully understand a problem.

For operations, what counts is therefore a view that shows all SSE building blocks together, instead of looking at them individually and in isolation.

Common sources of error

SSE in practice: what CentaurNexus contributes

CentaurNexus brings together the view of the Zscaler SSE building blocks ZIA, ZPA and ZDX in a single interface, so usage, policy and experience data get looked at together instead of separately, without support teams needing Zscaler admin rights. That makes it easier to spot interactions between individual SSE functions. The guide Zscaler support without admin rights shows this cockpit view in detail.

See the combined view of your Zscaler SSE building blocks in the live demo.Watch the live demo

Related terms

Frequently asked questions about SSE

What does SSE mean?

SSE stands for Security Service Edge. It refers to a bundle of cloud-based security services, including zero trust access, web protection, cloud firewall and data protection, delivered centrally through the cloud instead of through individual appliances in a data centre.

What is the difference between SSE and SASE?

SSE covers the security functions. SASE adds the network component to SSE, usually SD-WAN, forming a complete architecture for network and security from a single cloud platform. SSE is therefore the security-focused core of SASE.

Which Zscaler services make up the SSE layer?

At Zscaler, ZIA for internet access and web protection, together with ZPA for zero trust access to applications, form the core of the SSE layer, supplemented by functions such as cloud sandbox, browser isolation and data protection controls like DLP.

Why SSE matters in Zscaler operations

SSE brings several previously separate security functions together on one platform. For operations and support, that means a single fault can affect several services at once, and diagnostic tools need to look across all SSE building blocks to find the cause.

Does every organisation need SSE?

Not necessarily as a complete package, but the individual functions it includes, such as web protection and zero trust access, are standard today in almost every IT security architecture. The advantage of SSE lies mainly in centralised, consistent control of these functions, rather than in a patchwork of separate point solutions.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.