The Question

SASE is a compelling security investment. Zero trust access architecture replaces implicit trust models that are fundamentally incompatible with distributed workforces and cloud-first application portfolios. Inline threat inspection at cloud scale catches what perimeter-based architectures miss. CASB visibility into SaaS usage closes shadow IT blind spots that have grown significantly as cloud application adoption has outpaced IT governance capacity.

The CISO can make this case fluently. The problem is that most CFOs don't approve security investments on threat narrative alone. They approve investments that have a defensible cost reduction story, a three-year TCO that is lower than the status quo, and a payback period that fits their capital planning horizon. Security improvement is a co-benefit — it supports the business case but doesn't drive it.

The gap between how security teams present SASE and how finance teams need to see it is one of the primary reasons SASE projects stall at the budget approval stage. CISOs who understand both framings — who can translate the security value into financial terms and build the cost reduction case alongside the threat case — get SASE approved. Those who lead with threat scenarios get asked to resubmit with numbers.

The SASE business case that wins is not the one with the most compelling threat scenarios — it is the one that shows a three-year TCO that is lower than the status quo.


Why This Matters Now

In Q4 2024, Forrester published research on enterprise security investment approval patterns that found SASE had the highest stall rate of any major security architecture initiative — 38% of SASE proposals stalled at CFO review, compared to 22% for cloud security tools and 19% for endpoint detection investments. The primary cited reason: insufficient cost justification. Security teams were presenting SASE as a security improvement initiative. Finance teams were evaluating it as a capital expenditure that needed a return.

The organizations that successfully advanced SASE through budget approval in 2024–2025 shared a common characteristic: they built the cost case from existing spend data rather than from industry benchmarks. Point-product license costs, pulled from actual contract renewals. WAN circuit costs, pulled from actual invoices. IT labor hours for security tool management, pulled from time-tracking or informal estimation validated by IT management. These concrete numbers, assembled into a three-year TCO comparison, were what moved the approval conversation from "this is a security improvement" to "this is a cost reduction with a security co-benefit."

The macro environment has strengthened the cost case for SASE in 2025–2026. MPLS pricing has remained elevated while broadband capacity has increased significantly, widening the cost differential between legacy WAN and SD-WAN over broadband. Point-product security licensing has increased 15–25% annually for many incumbent vendors, raising the baseline cost of the status quo that SASE displaces.


What the CURVE™ Data Shows

The 2026 Stackcurve SASE/SSE CURVE™ Report includes a financial analysis dimension that evaluates each major SASE platform's published TCO calculators, available customer-reported cost savings data, and analyst-validated payback period ranges.

Cato Networks publishes the most transparent TCO comparison methodology, including specific line items for displaced point products, WAN cost reduction, and IT labor savings. Zscaler's ROI Calculator (updated in 2025) uses a Forrester-validated methodology but requires accurate input data about existing license spend to produce meaningful output. Palo Alto Networks Prisma SASE ROI materials are strongest for organizations with existing Palo Alto investments, where the cross-product consolidation savings are most clearly documented.

The CURVE™ analysis found median three-year cost savings for enterprises migrating from a mature point-product stack to a full SASE platform in the range of 18–34% of total security and WAN spend, with the high end of that range achievable by enterprises with significant MPLS exposure. Payback periods ranged from 14 to 28 months depending on deal structure, existing contract timing, and the degree of WAN transformation included.

The full vendor rankings are in the 2026 Stackcurve SASE/SSE CURVE™ Report — free to download.


The Gap Most Buyers Miss

The SASE ROI case has five components. Most security teams build two or three of them and present them as a complete argument. Finance teams notice the missing components and ask for a resubmit.

Hard cost reduction: point-product license consolidation

The most credible and easiest-to-document component of the SASE cost case. A typical enterprise with a mature point-product security stack runs some combination of: VPN concentrator infrastructure and licenses (Cisco ASA/FTD, Palo Alto GlobalProtect, Fortinet FortiGate), a standalone SWG (Zscaler, Symantec/Broadcom, Cisco Umbrella), a CASB solution (Netskope, Microsoft Defender for Cloud Apps, Broadcom Symantec), a standalone DLP tool, and possibly a separate ZTNA product if VPN replacement is in progress.

The license consolidation math is straightforward: add up the annual renewal cost of each point product being displaced, subtract the SASE platform annual cost, and present the delta. The challenge is that these costs are often distributed across multiple budget owners and multiple procurement cycles, making aggregation non-trivial. Do the work to aggregate them — the resulting number is almost always larger than anyone expected.

WAN cost reduction: MPLS displacement

MPLS pricing ranges from $300 to $500 per Mbps per month in most enterprise contracts. Internet broadband with SD-WAN overlay costs $5 to $20 per Mbps per month for equivalent capacity. For enterprises with meaningful MPLS spend — typically those with many branch offices or international connectivity requirements — the WAN cost reduction from MPLS displacement over a three-year period can fund most of the SASE investment.

This calculation requires knowing your total MPLS spend and your current contract terms. Organizations mid-contract have a more complex calculation: the early termination penalty plus the SD-WAN investment cost must be offset against the monthly savings over the remaining contract period. For most contracts with more than 18 months remaining, partial MPLS displacement (moving 50% of bandwidth to broadband) produces a positive return even accounting for early termination costs.

Productivity improvement: latency reduction for cloud applications

This component is harder to quantify but defensible. The standard pre-SASE architecture routes all internet-bound traffic from branch offices and remote workers through a central internet breakout point — headquarters or a regional data center. This backhaul adds 40–120ms of latency for cloud applications relative to direct internet breakout through an SSE PoP near the user.

Microsoft's own research documented that every 100ms of additional latency for Microsoft 365 applications reduces productivity by approximately 1% of affected users' workday. For a 1,000-user organization with 60% of users on affected applications, 80ms of latency reduction translates to roughly 4,800 productive hours per year — a number that can be converted to labor cost at average loaded salary.

IT labor reduction: platform consolidation

Managing six security platforms requires six sets of administrative skills, six vendor relationships, six support contracts, and six training curricula. Consolidating to one SASE platform reduces this to one.

The labor savings are real but require honest estimation. The transition year typically sees a net increase in IT labor as the old stack winds down and the new platform is configured. Year two and three show the full savings. A reasonable estimate for a 1,000-user organization: 0.5 to 1.0 FTE-equivalent of security operations labor savings annually after the transition year.

Incident cost reduction: risk-adjusted probability

The most contested component because it requires probability assumptions. The standard methodology: estimate the probability of a significant security incident at your current security posture, estimate the cost of such an incident (Ponemon Institute's 2024 Cost of a Data Breach Report estimated $4.88M average cost), and estimate the reduction in incident probability that SASE provides. A 15% reduction in incident probability applied to a $4.88M expected incident cost produces roughly $730K in risk-adjusted annual benefit.

Finance teams are appropriately skeptical of this calculation because the assumptions are hard to validate. Present it as a sensitivity analysis rather than a primary financial driver — it supports the case but shouldn't be its foundation.

Assembling the three-year TCO comparison

The standard format is a side-by-side three-year TCO table: current state (point products + MPLS + IT labor) versus future state (SASE platform + broadband + IT labor). Year one typically shows net investment due to migration costs and parallel-run infrastructure. Year two typically breaks even or turns positive. Year three shows full cost reduction. The three-year net is the number that gets the meeting with the CFO.


Questions Your Buying Team Should Be Asking

1. Have we aggregated the total annual cost of all point products being displaced by SASE — including products that may sit in different budget lines across network, security, and IT operations?

The total displaced cost is almost always higher than the initial estimate because security tool costs are distributed across multiple budget owners. Centralizing this number is the foundation of the cost reduction case and typically requires coordination between network operations, security operations, and procurement.

2. What is our total annual MPLS spend, and what is the per-Mbps cost of our current circuits versus broadband-plus-SD-WAN alternatives in each of our major branch locations?

WAN cost reduction is frequently the largest single line item in the SASE business case for enterprises with significant branch footprints. Getting the actual circuit costs from your WAN vendor and comparing to broadband pricing in each location is worth the procurement effort.

3. Have we measured the current latency profile for our top cloud applications from branch offices and remote worker locations — and what is the productivity impact of reducing that latency by 40–80ms?

Latency measurement is the foundation of the productivity improvement case. Without baseline measurements, the productivity claim is theoretical. A two-week latency measurement exercise using tools like ThousandEyes or Catchpoint establishes the baseline and makes the post-SASE improvement claim quantifiable.

4. For our three-year TCO comparison, what are the migration costs, parallel-run infrastructure costs, and training costs in year one — and how do those affect our payback period calculation?

Year-one migration costs are frequently underestimated in SASE business cases, which leads to payback periods that are shorter on paper than in practice. Build year-one costs conservatively: professional services for design and implementation, parallel-run infrastructure for 60–90 days, training for IT staff, and productivity impact during the transition period.

5. What is the contract structure and payment timing for our chosen SASE vendor, and can we align the payment schedule with the cost savings realization curve — specifically deferring the full investment until MPLS displacement savings begin to flow?

Many SASE vendors will negotiate payment schedules that align with the economic benefits timeline — particularly if MPLS displacement is a significant component of the business case. Aligning cash flows to benefit realization makes the year-one net investment smaller and shortens the apparent payback period, which helps CFO approval.


The Stackcurve Take

The SASE business case is genuinely strong — stronger, in many cases, than security teams realize because they're not assembling all five components. The combination of point-product consolidation savings, MPLS displacement economics, productivity improvement from latency reduction, IT labor reduction, and risk-adjusted incident cost reduction produces a three-year TCO comparison that is favorable in the majority of enterprise environments.

The security narrative is important and should be presented — zero trust architecture, improved threat visibility, reduced attack surface. But it should follow the financial case, not precede it. CFOs approve investments that make financial sense and have security co-benefits. They don't approve security investments that are expensive to implement and happen to save some money on the side.

The discipline required is building the cost case from actual enterprise spend data, not from industry benchmarks. The numbers that get SASE approved are the ones that come from your own procurement contracts, your own WAN invoices, and your own IT labor data — assembled into a three-year comparison that is honest about year-one migration costs and realistic about the timeline to full cost reduction realization.

The 2026 Stackcurve SASE/SSE CURVE™ Report covers ROI frameworks, TCO methodology, and financial benchmarks for SASE investment cases across enterprise verticals. Download it free →


← Back to Research Library

Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.