Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security services can lag behind a network that spans office hardware, cloud platforms, endpoints, and remote users. The key question is whether licensing and coverage can follow those changes—or remain divided into separate device, appliance, and user-based silos. That is the argument John Maddison made in a 2021 SecurityWeek article; it is a useful procurement lens, not a current, independently verified comparison of providers.

Why flexible environments can clash with siloed security services

Cloud adoption and remote work have spread users and devices across more locations and environments. Organizations may combine tools for identity and access management, endpoint protection, cloud security, zero-trust network access (ZTNA), and secure SD-WAN. In that setting, users, applications, and workloads can move between physical infrastructure, cloud platforms, and end-user devices.

Maddison’s concern is that security licensing may still be organized around distinct categories even when the environment is blended. He argues that this can complicate forecasting, offer comparisons, and changes to capacity or capabilities. Those are qualitative claims in his article, not measured outcomes or proof that every organization encounters the same problem.

Three common licensing categories

Category Examples in Maddison’s article What the category is tied to
Device-based Endpoint protection (EPP) and endpoint detection and response (EDR) Protected endpoints or devices
Hardware-based Firewalls, intrusion prevention systems (IPS), and SD-WAN platforms Physical security or network appliances
User-based Email, identity, and ZTNA cloud tools Users or cloud-service entitlements

These categories are a way to understand the licensing model described by Maddison, not a universal taxonomy for every provider. A single security deployment may involve more than one category.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why ZTNA and SASE can make comparisons harder

Maddison points to ZTNA and secure access service edge (SASE) as examples of blended deployments: they can bring together device-, appliance-, and cloud-based licenses. Under the traditional models he describes, assembling those components may mean working through multiple terms or seeking custom quotes. That can make it harder for a buyer to compare costs or anticipate the effect of adding, reducing, or shifting capabilities.

The article does not quantify how often this occurs, identify providers, or show that a unified license will always be cheaper or simpler. The practical question is whether a proposed service’s coverage and contract structure match your architecture and how you expect it to change.

Questions to ask before choosing a service

Use these as procurement questions derived from Maddison’s argument, not as a proven industry standard:

  • Coverage: Does the service cover the endpoints, appliances, cloud environments, and user types your organization actually operates?
  • Portability and scaling: Can entitlements move or scale as employees, devices, applications, or workloads change environments?
  • Pricing and terms: Can you understand and compare costs across components, use cases, and contract dates? Which changes require a new quote or contract?
  • Administration: How are updates, threat intelligence, policy and configuration alignment, and compliance responsibilities handled?
  • Evidence of fit: What documentation, demonstrations, or evaluations show that the service suits your architecture and regulatory context?
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Maddison proposes—and what the article establishes

Maddison advocates flexible services and licensing that span network, endpoint, and cloud environments, with ZTNA, SD-WAN, and SASE among the use cases he names. SecurityWeek identifies him as Fortinet’s EVP of Products and CMO, so readers should understand the recommendation as vendor-perspective advocacy. The article, published November 9, 2021, offers no neutral provider comparison, prices, implementation results, or independently verified measures of benefit. It cannot establish which service is best today; a current decision needs up-to-date provider documentation and independent evidence relevant to the buyer’s own requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read John Maddison’s original SecurityWeek article.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.