By Daniel Osho, Presales Engineer, DataGroupIT

I sit through a lot of network refresh conversations. Nine times out of ten, they start the same way: a customer wants faster branch connectivity, lower MPLS cost, better application performance. SD-WAN delivers all of that, and it delivers it well. The problem is what happens after the deal closes, when the same customer assumes the network upgrade also covered their security posture. It didn’t, and that gap has a habit of surfacing at the worst possible time.

Why a good decision created a blind spot

Direct internet breakout is usually the feature customers are most excited about. Branch traffic goes straight to the internet instead of backhauling through a data centre, latency drops, cost drops, everyone’s happy. What gets less airtime is that the same traffic just left the centralised security stack that used to inspect it. I’ve seen this play out across branch networks here in Nigeria and in conversations with partners in Kenya and Ghana: policy enforcement becomes inconsistent from site to site, visibility drops, and once visibility drops, control goes with it. Shadow IT fills that space quietly. So does exposure to malware and data exfiltration, usually long before anyone notices the traffic was never inspected at all.

This isn’t a theoretical risk for our region. Interpol’s 2025 Africa Cyberthreat Assessment found cybercrime now accounts for more than 30% of all reported crime across Western and Eastern Africa, with two-thirds of surveyed member states describing cyber-enabled crime as a medium-to-high share of total criminal activity. Ethiopia, not South Africa or Nigeria, ranked as the world’s most targeted country for cyberattacks in 2024 by malware detection volume, a detail that surprises most customers I bring it up with. Since 2019, cyber incidents across the continent have driven estimated losses of more than $3 billion.

The network was never designed to ask who you are

Traditional networking assumed that if you were inside the corporate network, you could largely be trusted. SD-WAN inherited that assumption. It secures sites and links well. It was never built to continuously verify the user, the device, or the behaviour behind the connection, and attackers stopped targeting the wire years ago. Credentials are the target now. A compromised laptop on a “trusted” branch link is no safer than one connecting from a co-working space in Lekki.

That’s the case for Zero Trust principles doing the real work here: continuous verification, least-privilege access, policy that adjusts to risk rather than location. Trust tied to network position has already been tested by real attackers, and it failed.

Where the budget is already moving

Security teams aren’t the only ones catching up to this. . Gartner’s latest forecast puts global information security spending at $248.9 billion in 2026, up 12.7% in constant currency. Dell’Oro Group projects cumulative SASE spending across SSE and SD-WAN at $97 billion between 2025 and 2030, close to triple the 2020 to 2024 total, with SD-WAN already deployed across 60% of enterprise WAN estates. Customers aren’t buying networking and security as two separate conversations anymore. When I walk a CISO through what Security Service Edge (SSE) actually adds, Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access, enforcing policy consistently regardless of where someone connects from, the reaction is usually the same: “why wasn’t this already part of the network project?”

What I tell customers now

SD-WAN transformed how organisations connect their users to applications. SSE transforms how they protect that connection once it’s made. Skip the second half and the gap doesn’t close on its own. It just waits to be found. Ransomware detections rose sharply through 2024 and attackers have already hit, from Kenya’s Urban Roads Authority to Nigeria’s own National Bureau of Statistics.  That’s not a bet worth taking.

Together, SD-WAN and SSE form the foundation of SASE (Secure Access Service Edge): performance and protection converged at the edge rather than stitched together after the fact. The customers I see moving fastest on this aren’t waiting for an incident to force the conversation. That’s the shift worth making before the next network refresh, not after.

Daniel Osho is a Presales Engineer at DataGroupIT (DGIT), a pan-African cybersecurity value-added distributor helping organisations build security architecture across identity, data, cloud, network, and managed security services.

Leave a Reply