Does your company use exclusively SaaS solutions and no longer have any local servers? Then you often need less traditional network access, but that does not automatically mean that network security or a firewall is unnecessary.
More and more companies are working entirely in the cloud.
Email is in Microsoft 365, files are stored in SharePoint or OneDrive, and other applications are accessed directly via the browser.
In such an environment, there is often:
- no local server;
- no traditional file server;
- no internal ERP system;
- no need to connect from home to the office network via VPN.
Why is there less network complexity with SaaS?
With traditional IT, users often had to access via the company network:
- local servers;
- network shares;
- internal applications;
- databases;
- local mail servers;
- other private resources.
With SaaS, many of these dependencies disappear.
The user connects directly via the internet to, for example:
- Microsoft 365;
- Teams;
- SharePoint;
- OneDrive;
- online accounting;
- CRM;
- HR software;
- other cloud applications.
Does that mean the firewall is no longer needed?
Not necessarily.
Even in a fully SaaS-based organisation, a local network usually still exists.
For example, it hosts:
- laptops;
- smartphones;
- printers;
- Wi-Fi access points;
- conference devices;
- VoIP telephony;
- cameras;
- IoT equipment;
- guests.
All these devices communicate via the local network and with the internet.
It does not mean your office no longer has a network.
What does a firewall still do then?
In a SaaS-first environment, the role of the firewall changes.
It is less important for access to internal servers but can still be useful for:
- network segmentation;
- separating guest Wi-Fi from company devices;
- isolating IoT devices;
- blocking unwanted network traffic;
- DNS or web filtering;
- detecting suspicious network connections;
- logging and monitoring;
- central network rules;
- secure management connections.
Your identity becomes more important than your network
When applications are accessible directly via the internet, identity security becomes much more important.
Think of:
- MFA;
- passkeys;
- Windows Hello;
- Conditional Access;
- strong security of administrator accounts;
- monitoring suspicious sign-ins;
- least privilege.
The device must also be trustworthy
A secure SaaS environment looks not only at who the user is but also at the device the user is working with.
With device management and endpoint security, you can, for example, check:
- whether the device is managed;
- whether security updates are installed;
- whether encryption is active;
- whether endpoint protection is active;
- whether the device is compliant;
- whether malware or other threats are present.
This information can then be used to allow or block access to SaaS applications.
A user has a valid password and MFA but tries to access from an unmanaged laptop. Conditional Access can still deny that access.
Do you still need an expensive company firewall then?
Not necessarily.
A small organisation that truly operates fully SaaS and has hardly any local infrastructure may require a much simpler network architecture than a company with:
- local servers;
- production networks;
- multiple locations;
- lots of IoT;
- local telephony;
- complex segmentation;
- private applications.
The firewall should therefore fit the actual need.
When can a simple router be sufficient?
In a very simple environment, that might be possible.
For example, when:
- there are only a few employees;
- all applications are SaaS;
- there are no local servers;
- no external incoming connections are needed;
- laptops are professionally managed and secured;
- there is hardly any other network equipment present;
- guests can be safely separated;
- the router has sufficient management and security capabilities.
“We no longer have servers” is not by itself sufficient reason to remove all network security.
Guest Wi-Fi and IoT remain a point of attention
Even a SaaS company normally does not want visitors or IoT devices to use the same network as company devices without restriction.
Think, for example, of:
- cameras;
- smart TVs;
- printers;
- meeting room equipment;
- access control;
- domotics;
- private devices of visitors.
These devices should preferably not automatically have access to the same network zone as company laptops.
SaaS shifts the risk, it does not remove it
In a traditional network, much attention was focused on protecting internal servers.
With SaaS, a large part of the risk shifts to:
- identities;
- user accounts;
- endpoints;
- cloud configuration;
- access rights;
- external sharing;
- phishing;
- user behaviour.
You simply need different security layers than before.
What is more important than the firewall?
For an organisation that works exclusively with SaaS, these measures are generally particularly important:
- strong MFA or passkeys;
- Conditional Access;
- professional device management;
- endpoint protection and EDR;
- correct SaaS and Microsoft 365 configuration;
- least privilege;
- secure external sharing;
- logging and monitoring;
- backup and recovery;
- security awareness.
A firewall remains useful but should not be considered the main or only security layer in such an architecture.
No security layer is sufficient on its own
Even when you configure Microsoft 365, SaaS, Conditional Access, endpoint security and a firewall correctly, there is no absolute security.
A user can, for example:
- trust a convincing phishing email;
- approve a fraudulent MFA request;
- execute a malicious file;
- deliberately ignore a warning;
- share confidential data with the wrong person.
Have the entire architecture assessed
The decision to use a professional firewall should not be made independently of the rest of your IT environment.
You need to jointly consider:
- which SaaS applications are used;
- how identities are secured;
- how devices are managed;
- which network equipment is present;
- whether guests and IoT need to be separated;
- which monitoring is needed;
- which risks are acceptable for your organisation.
We assess not only the firewall but also Microsoft 365, identity, endpoint security, device management, Wi-Fi and the rest of your network.
Our cybersecurity expertise was recognised three years in a row by our Microsoft distributor with the Cybersecurity Partner of the Year award.
Would you like to know whether your SaaS-first organisation still needs a professional firewall or if a simpler solution suffices?
Contact us at:
sales@flexamit.com
In summary
- Those who use only SaaS usually need less traditional network security than before.
- That does not mean network security disappears entirely.
- Your local network still contains laptops, Wi-Fi, printers, IoT and possibly guests.
- Network segmentation remains useful.
- Identity, MFA, Conditional Access and endpoint security become more important with SaaS.
- A simple router can sometimes be sufficient in a very limited environment.
- A professional firewall remains sensible when you need more control, segmentation, monitoring or security features.
- The right choice depends on your entire IT architecture, not just on whether you have local servers.
- No technology can guarantee 100% security.
Comments
0 comments
Please sign in to leave a comment.