The network conversation and the security conversation merged. Most organisations are still having both.
Every internet link is now a security decision. Every firewall rule is a network design choice. Every identity policy shapes connectivity. The two stopped being separate the day branches started reaching the cloud directly. The operating model often has not caught up.
This insight covers where network and security still operate as separate conversations, what that separation costs in practice, and how to review the current state before choosing SD-WAN, SASE or provider consolidation.
Three questions that explain why the merger already happened.
The conversations were always linked. The technology now makes the link unavoidable. Three questions explain what merged, what the old silo costs, and what an integrated model looks like.
What does it mean that network and security have merged?
The technology stopped treating them as separate. SD-WAN devices include encrypted overlays and built-in firewalling by default. Identity drives access decisions, not just authentication. Branch traffic reaches cloud directly with security applied at the edge nearest the user. Every WAN choice now shapes the attack surface, and every firewall rule shapes connectivity.
What does the old siloed model cost in practice?
Multiple consoles producing inconsistent policies between sites and tools. Change requests crossing separate ticket queues. Alerts bouncing between teams while one assumes a network fault and the other assumes a firewall drop. Compliance audits surfacing undocumented exceptions. Identity and remote access existing as ad-hoc combinations of VPN, MFA and cloud SSO that do not work together.
What does an integrated operating model look like?
One policy engine pushing consistent rules to every site. Identity as the access decision rather than just an authentication step. Telemetry from network, firewall, endpoint and cloud feeding one view. One accountable response model for incidents that cross connectivity, identity and security controls. Not exotic — what modern platforms can deliver if operated as one system.
Networks used to be plumbing. Security used to be gates. Both definitions are now wrong.
- Network team built the pipes
- Security team controlled who got through them
- Tooling own consoles, own people, own vendors
- Change separate change-control processes
- SD-WAN ships encrypted tunnels and firewalling by default
- Identity is the access decision, so the directory is a perimeter
- Branch traffic reaches cloud applications directly
- Attack surface every branch internet link
Whatever gets bought, it is being bought into one operating model whether the organisation intended it or not. The question is whether the operating model is also intentional, or just a consequence.
Where two separate conversations show up as one expensive problem.
The cost of running network and security as two functions does not appear as a line item. It appears in friction. None of these are dramatic individually. Together they describe a stack that is harder to operate, harder to defend, and harder to change than it should be.
What the integrated model looks like in practice, not in theory.
An integrated network and security operating model is not a particular vendor stack and not a particular organisational structure. It is a set of working assumptions that change how the team operates day to day. The technology choices follow from those assumptions, not the other way around.
One policy engine
Consistent rules pushed to every site rather than each branch firewall managed locally. The site cannot be an outlier because the policy is the same by design.
Identity is the access decision
Not the front door, the architecture. Every session evaluates user, device, location and posture, not just credentials. Identity systems become primary infrastructure.
The edge is governed like head office
The branch, the home office, the construction site, the remote mine: same controls, same monitoring, same policy — whether the connection is fibre, 5G or Starlink.
Telemetry feeds one view
Network devices, firewalls, endpoints, cloud applications and identity events feed a single observability layer that makes incidents legible across the stack rather than across the org chart.
One accountable response model
When an alert crosses connectivity and security, one team owns it. Escalation is internal. The customer experience is one phone call, not two providers debating whose problem it is.
Procurement, not just deployment
SD-WAN, firewalls, identity, endpoint protection and managed services treated as one decision shaping one operating model, not five separate decisions stitched together later.
The current-state map that decides what changes first.
An integrated network and security review is not a vendor pitch and not a tooling recommendation. It is a current-state map that surfaces where the silos still cost money and visibility, and a prioritised list of what closing the gaps actually involves. The output should support both leadership decisions and technical remediation.
The diagnostic is the foundation. Platform decisions, consolidation projects, ZTNA rollouts, MDR engagements: all are downstream of knowing what the stack actually looks like and where the silo is genuinely hurting.
The technology has converged. The operating model needs to catch up.
Network and security now operate through the same control points: identity, edge devices, firewall policy, endpoint posture, cloud access and telemetry. Treating those controls as separate conversations creates gaps that only appear when something needs to change quickly or an incident needs one accountable owner. Some organisations can make a split-provider model work, but only when ownership, escalation, policy authority and incident handover are explicit. The practical question is not "how many providers do we have?" It is "can this operating model work under pressure?" Inlight IT runs integrated network and security reviews and operates the resulting architecture as part of cyber-first managed services for Australian businesses.
The starting point is not SASE, SD-WAN or provider consolidation. The starting point is understanding how network and security operate together today.
Map the current state first
Standardise policy where inconsistency creates risk
Integrate identity and network access
Consolidate where the operating model benefits
Integrated network and security, delivered inside one accountable layer.
The argument on this page — that network and security have converged technologically but most operating models have not, and that the first step is current-state visibility rather than platform selection — describes how Inlight IT delivers integrated managed services across the Network Review and SASE & Zero Trust Access pathways. The SASE Architecture and Deployment and Zero Trust Network Access authority pages cover the underlying architecture decisions.
The diagnostic foundation: edge devices, firewall policy, remote access, identity integration, endpoint trust, cloud application protection, visibility and operating model.
The secure-access pathway available where the diagnostic justifies it.
The connectivity pathway available where the diagnostic justifies it.
Make network and security visible as one system.
Review network, firewall, identity and access controls as one operating environment. Scoped to your environment — Inlight IT remains the accountable service owner throughout.
Discuss Network Review