{"id":1440,"date":"2025-04-26T15:06:57","date_gmt":"2025-04-26T15:06:57","guid":{"rendered":"https:\/\/violethoward.com\/new\/from-friction-to-flow-why-swissport-scrapped-its-vpn-maze-for-catos-sase-platform\/"},"modified":"2025-04-26T15:06:57","modified_gmt":"2025-04-26T15:06:57","slug":"from-friction-to-flow-why-swissport-scrapped-its-vpn-maze-for-catos-sase-platform","status":"publish","type":"post","link":"https:\/\/violethoward.com\/new\/from-friction-to-flow-why-swissport-scrapped-its-vpn-maze-for-catos-sase-platform\/","title":{"rendered":"From friction to flow: Why Swissport scrapped its VPN maze for Cato\u2019s SASE platform"},"content":{"rendered":" \r\n<br><div>\n\t\t\t\t<div id=\"boilerplate_2682874\" class=\"post-boilerplate boilerplate-before\">\n<p><em>Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n<\/div><p>In Swissport\u2019s world, strengthening security and networking provides an opportunity to serve more customers and grow.<\/p>\n\n\n\n<p>Swissport\u2019s global IT operations started to expose the strains of relying on legacy systems for security and networking, which were quickly becoming a liability for the company. Senior management could see that centralized visibility was a major challenge, which led them to take quick action.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-swissport-s-growth-outpaced-its-legacy-systems\"><strong>Swissport\u2019s growth outpaced its legacy systems<\/strong><\/h2>\n\n\n\n<p>The security and networking challenges that Swissport faced began to multiply as its business expansion accelerated. Legacy systems were hindering the ability to serve customers, secure global locations and expand the business. The senior management team told VentureBeat that legacy systems weren\u2019t keeping up with the pace of their business, leading the team to consider new alternatives, starting with secure access service edge (SASE).<\/p>\n\n\n\n<p>In 2024, Swissport provided ground services for 247 million airline passengers, handled more than five million tons of air freight at 117 cargo centers and served airlines at 279 airports in 45 countries across six continents. As the world\u2019s largest provider of ground and cargo handling services in the aviation industry, a core part of how Swissport excels for its customers is connecting and securing its global IT operations. That\u2019s table stakes for a business with over 26,000 users, including ground crew and remote workers.<\/p>\n\n\n\n<p>\u201cThe biggest challenge wasn\u2019t just visibility\u2014it was consistency,\u201d said Giles Ashton-Roberts, Chief Information Security Officer at Swissport. \u201cWe had to unify how we enforce security across hundreds of sites without slowing down the business.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-from-fragmented-infrastructure-to-sase\"><strong>From fragmented infrastructure to SASE<\/strong><\/h2>\n\n\n\n<p>\u201cWe\u2019re truly a 24\/7 business. It\u2019s always peak time somewhere in the world, and we need to keep our network both secure and available,\u201d Richard Thorp, Chief Technology Officer at Swissport, told VentureBeat in a recent interview. \u201cThat means standardizing security and making sure every user and every device is covered\u2014whether they\u2019re in a coffee shop or on the tarmac.\u201d<\/p>\n\n\n\n<p>Legacy systems were not scaling fast enough to keep up with the rapid expansion pace that Swissport was experiencing. Legacy systems, along with the fragmented infrastructure on which they were based, were slowing down growth and creating potential security and networking challenges. Swissport set ambitious goals to redefine its security and networking stack, replacing fractured virtual private networks (VPNs), disparate appliances and inconsistent policy enforcement with an entirely new SASE architecture.<\/p>\n\n\n\n<p>\u201cBefore this change, we were managing different systems across different sites with different policies\u2014and visibility was fragmented,\u201d Thorp said. \u201cNow we operate under one set of security policies globally, and I can sleep at night knowing the environment is secure.\u201d<\/p>\n\n\n\n<p>Every connection, whether from an airport kiosk or a hybrid work device, is now identity-aware, continuously risk-scored, and enforced in real-time from a single, cloud-native SASE platform. Zero Trust is enforced on every endpoint and interaction, giving Swissport the flexibility to grow at the pace it needs to while serving its growing customer base.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-sase-is-at-the-core-of-swissport-s-architectural-overhaul\"><strong>Why SASE is at the core of Swissport\u2019s architectural overhaul<\/strong><\/h2>\n\n\n\n<p>Swissport\u2019s decision to adopt SASE architecture underscores the importance of maintaining real-time responsiveness, transparency and accuracy to sustain and enhance its numerous customer relationships worldwide. Excellence in global aviation services occurs when every operating unit has the necessary data. SASE helps Swissport create a unified team galvanized to the common goal of excelling on behalf of customers.<\/p>\n\n\n\n<p>VentureBeat is seeing SASE deliver benefits beyond replacing legacy systems with a unified architecture. The faster and more accurate the data, the more a business can reach remote offices and locations, keeping them coordinated with broader teams and achieving a greater return on invested capital (ROIC).<\/p>\n\n\n\n<p> VentureBeat is also seeing this play out across capital-intensive services businesses today, where improving responsiveness and unifying geographically diverse networks has a direct impact on revenue. Core to Swissport\u2019s SASE strategy is a unified architecture that unites over 320 locations, ensuring more secure, real-time communications across each location and network-wide.<\/p>\n\n\n\n<p>In defining its SASE strategy, Swissport opted for a single, cloud-native SASE platform. Gartner notes there are many benefits to this approach, including platform unification, simplified policy control and identity-aware access that adapts in real-time\u200b.<\/p>\n\n\n\n<p>Swissport did their due diligence across all SASE vendors who also offer zero trust as a part of their architecture and chose Cato Networks for its single management plane, unified data lake, global Points of Presence (PoPs) and ability to collapse software-defined wide area network (SD-WAN) and security into one enforcement layer\u200b. Thorp told VentureBeat that a significant motivation for adopting a SASE platform was the need to move away from supporting numerous legacy platforms, each with its unique configuration. \u201cDifferent platforms required different configurations, which complicated troubleshooting and made security enforcement a challenge,\u201d said Thorp.<\/p>\n\n\n\n<p>\u201cCato\u2019s TLS Inspection gives us the ability to inspect encrypted traffic while avoiding unintended service disruptions,\u201d said Ashton-Roberts. \u201cIt\u2019s been a major improvement to our security posture.\u201d\u200b Transport Layer Security (TLS) inspection is central to maintaining Swissport\u2019s network and security infrastructure. Encrypting and decrypting TLS and secure sockets layer (SSL) traffic is essential in Swissport\u2019s SASE infrastructure, as it secures data and helps identify potential threats.\u00a0TLS inspection analyzes the contents of every encrypted message to detect malware, data exfiltration, or other malicious activities that could be more damaging.\u00a0\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-five-lessons-learned-from-swissport-s-sase-blueprint\"><strong>Five lessons learned from Swissport\u2019s SASE blueprint<\/strong><\/h2>\n\n\n\n<p>While most enterprises are trying to integrate secure service edge (SSE), SD-WAN, and ZTNA from multiple vendors together, Swissport chose to go all-in on platform consolidation with Cato to collapse their security tech stack, standardize policy enforcement and embed security directly into the network fabric.<\/p>\n\n\n\n<p>Ashton-Roberts and Thorp told VentureBeat that SASE is delivering the visibility they need to keep their global IT operations running smoothly. At the same time, Zero Trust enforces the least privilege and protects assets, resources, and, most importantly, the identities and roles of employees and customers on the network.<\/p>\n\n\n\n<p>Swissport\u2019s SASE blueprint includes the following five principles:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>End-to-end zero trust turns detection into instant action. <\/strong>Swissport is enforcing Zero Trust across every edge and endpoint. They\u2019ve replaced legacy VPNs with a fully authenticated, segmented and adaptive network fabric that continuously scores every session for risk. \u201cWithin 15 minutes, our team identified excessive database traffic, blocked the device and restored normal operations\u2014something that would\u2019ve taken us days before,\u201d Thorp told VentureBeat.<\/li>\n\n\n\n<li><strong>Global security gets easier when policy is unified. <\/strong>Swissport\u2019s legacy systems were a patchwork of multiprotocol label switching (MPLS) links, region-specific VPNs and isolated firewalls, each created at different times and all delivering inconsistent policy enforcement and constant friction. Now, a single policy framework governs network access across Amazon Web Services (AWS), Microsoft Azure, cloud SaaS applications and airport edge systems. There\u2019s no location-specific logic or manual drift, just real-time control. Gartner forecasts that by 2027, 40% of large enterprises will adopt location-agnostic enforcement as a zero trust network access (ZTNA) baseline, up from less than 10% in 2024\u200b. Swissport is already operating on that model, flattening complexity while increasing reach.<\/li>\n\n\n\n<li><strong>Real-time visibility is a business accelerator driving results and ROI. <\/strong>Legacy systems left Swissport blind to cross-domain threats. Correlating the root cause with the response took days. Now, all traffic, from airport terminals to cloud SaaS applications, is streamed into a single data lake that supports continuous, role-based access control (RBAC) and threat analytics. \u201cIt\u2019s incredibly easy to pinpoint connectivity issues, analyze traffic patterns, and secure our network from a single interface,\u201d Thorp said. According to Gartner, fewer than half of vendors provide unified observability across users, devices and apps at all edges\u200b. Swissport built it into the foundation.<\/li>\n\n\n\n<li><strong>Decrypt everything, disrupt nothing: Secure TLS at scale. <\/strong>Encrypted traffic is the new blind spot. Many enterprises still bypass TLS inspection to avoid latency or application breakage. Swissport chose differently. By deploying full inline TLS inspection across its backbone, Swissport maintains visibility into encrypted threats without disrupting mission-critical aviation systems. Most SSE and ZTNA vendors still rely on partial decryption or bypass tunnels, according to Gartner\u2019s latest review of adaptive access capabilities. Swissport proved full inspection is achievable even in high-sensitivity, high-availability environments.<\/li>\n\n\n\n<li><strong>A SASE platform drives faster business wins. <\/strong>Swissport didn\u2019t add more vendors; they consolidated them. A SASE platform replaced a sprawl of SD-WAN appliances, VPN concentrators, and standalone security tools. The result? Sites come online in hours, not weeks. New users are protected instantly. Policy changes propagate globally in minutes. Gartner projects that 65% of all SD-WAN purchases will be bundled into single-vendor SASE platforms by 2027, up from just 20% in 2024\u200b. Swissport didn\u2019t wait. They made SASE the baseline, not a bolt-on, and it shows in their global agility.<\/li>\n<\/ol>\n<div id=\"boilerplate_2660155\" class=\"post-boilerplate boilerplate-after\"><div class=\"Boilerplate__newsletter-container vb\">\n<div class=\"Boilerplate__newsletter-main\">\n<p><strong>Daily insights on business use cases with VB Daily<\/strong><\/p>\n<p class=\"copy\">If you want to impress your boss, VB Daily has you covered. We give you the inside scoop on what companies are doing with generative AI, from regulatory shifts to practical deployments, so you can share insights for maximum ROI.<\/p>\n<p class=\"Form__newsletter-legal\">Read our Privacy Policy<\/p>\n<p class=\"Form__success\" id=\"boilerplateNewsletterConfirmation\">\n\t\t\t\t\tThanks for subscribing. Check out more VB newsletters here.\n\t\t\t\t<\/p>\n<p class=\"Form__error\">An error occured.<\/p>\n<\/p><\/div>\n<div class=\"image-container\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/venturebeat.com\/wp-content\/themes\/vb-news\/brand\/img\/vb-daily-phone.png\" alt=\"\"\/>\n\t\t\t\t<\/div>\n<\/p><\/div>\n<\/div>\t\t\t<\/div>\r\n<br>\r\n<br><a href=\"https:\/\/venturebeat.com\/security\/from-friction-to-flow-why-swissport-scrapped-its-vpn-maze-for-catos-sase-platform\/\">Source link <\/a>","protected":false},"excerpt":{"rendered":"<p>Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More In Swissport\u2019s world, strengthening security and networking provides an opportunity to serve more customers and grow. Swissport\u2019s global IT operations started to expose the strains of relying on legacy systems for security and networking, which were [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1441,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[33],"tags":[],"class_list":["post-1440","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-automation"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/violethoward.com\/new\/wp-content\/uploads\/2025\/04\/Swissport-goes-all-in-on-SASE-with-Cato-Networks-Unifying-security-and-networking-across-more-than-2.jpeg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/posts\/1440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/comments?post=1440"}],"version-history":[{"count":0,"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/posts\/1440\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/media\/1441"}],"wp:attachment":[{"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/media?parent=1440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/categories?post=1440"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/violethoward.com\/new\/wp-json\/wp\/v2\/tags?post=1440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69e302c146fa5c92dc28ac12. Config Timestamp: 2026-04-18 04:04:16 UTC, Cached Timestamp: 2026-04-29 05:19:51 UTC -->