What is SSE?
SSE (Security Service Edge) is a bundle of cloud-based security services, including zero trust access, web protection, cloud firewall and data protection functions, delivered centrally from the cloud instead of through individual appliances in a data centre. SSE forms the security-focused core of SASE, without its SD-WAN network component. For users, all internet and application access runs through this security layer, which checks identity, device posture and context on every request before letting it through.
SSE in detail
SSE typically brings several functions together: a secure web gateway for internet access, zero trust network access for applications, cloud firewall, cloud sandbox against malware, browser isolation for risky content, and data protection controls such as DLP and CASB. All these functions run on the same cloud platform and share policies, identities and log data.
That sets SSE apart from older architectures, where each function was its own appliance with its own configuration. With SSE, control is centralised, even though the individual functions remain distinct in what they do.
Why SSE matters in Zscaler operations
Because SSE bundles several functions together, a single policy change can affect multiple services at once, for example when a URL category affects both web access and sandbox behaviour. For diagnosis, that means testing individual functions in isolation is often not enough to fully understand a problem.
For operations, what counts is therefore a view that shows all SSE building blocks together, instead of looking at them individually and in isolation.
Common sources of error
- A change to one function, such as URL categories, unintentionally affects another, such as sandbox behaviour.
- Different teams maintain individual SSE building blocks without coordinating with each other.
- Without a combined view, teams end up repeatedly testing individual functions instead of analysing the whole picture.
- New functions get switched on without checking existing policies against them.
SSE in practice: what CentaurNexus contributes
CentaurNexus brings together the view of the Zscaler SSE building blocks ZIA, ZPA and ZDX in a single interface, so usage, policy and experience data get looked at together instead of separately, without support teams needing Zscaler admin rights. That makes it easier to spot interactions between individual SSE functions. The guide Zscaler support without admin rights shows this cockpit view in detail.
Related terms
Frequently asked questions about SSE
SSE stands for Security Service Edge. It refers to a bundle of cloud-based security services, including zero trust access, web protection, cloud firewall and data protection, delivered centrally through the cloud instead of through individual appliances in a data centre.
SSE covers the security functions. SASE adds the network component to SSE, usually SD-WAN, forming a complete architecture for network and security from a single cloud platform. SSE is therefore the security-focused core of SASE.
At Zscaler, ZIA for internet access and web protection, together with ZPA for zero trust access to applications, form the core of the SSE layer, supplemented by functions such as cloud sandbox, browser isolation and data protection controls like DLP.
SSE brings several previously separate security functions together on one platform. For operations and support, that means a single fault can affect several services at once, and diagnostic tools need to look across all SSE building blocks to find the cause.
Not necessarily as a complete package, but the individual functions it includes, such as web protection and zero trust access, are standard today in almost every IT security architecture. The advantage of SSE lies mainly in centralised, consistent control of these functions, rather than in a patchwork of separate point solutions.
- Zscaler Help Portal: ZIA, ZPA and Security Service Edge - help.zscaler.com
- In-house guide: Zscaler support without admin rights
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.