SSE
acronymsecuritycloud
Stands for: Security Service Edge
Gartner's 2021 name for the security half of SASE: secure web gateway, CASB, and zero trust network access delivered as one cloud service, with the networking left out.
When SASE proved to be two purchases wearing one acronym, Gartner split it in 2021: SSE names the cloud-delivered security stack (secure web gateway, cloud access security broker, zero trust network access, with firewall as a service and data protection in practice), while the SD-WAN networking half stays a separate decision. The split let security teams modernize inspection and access control without waiting for a WAN refresh, and SSE promptly got its own Gartner Magic Quadrant. The three letters are heavily overloaded outside this field, and context is everything: in web development SSE means Server-Sent Events, and in CPUs it means Streaming SIMD Extensions, neither of which will secure anyone's SaaS traffic.
Security Service Edge is the name for delivering security controls from a cloud rather than from appliances in a building, and it exists because the assumptions appliances were built on stopped holding. When users work anywhere and applications live in someone else's data centre, backhauling traffic to an office to inspect it adds latency to protect a perimeter that no longer contains anything.
The category usually bundles a secure web gateway for outbound traffic, zero trust network access for private applications, a cloud access security broker for software as a service, and often a firewall and data loss prevention. The argument for buying them together is a single policy model and a single enforcement point, rather than four consoles that disagree.
Two honest caveats belong with the enthusiasm. Concentrating inspection in one provider makes that provider a dependency on the critical path of everything, so their outage is your outage and their coverage is your coverage. And the acronyms are marketing before they are architecture: SSE, SASE and their neighbours are drawn differently by every vendor, so the useful question in an evaluation is which specific controls run where, not which three letters appear on the datasheet.