Join our Newsletter — 33% off our NHI Course
Home› FAQ› Architecture & Implementation› What happens when SD-WAN traffic bypasses the data…
Architecture & Implementation

What happens when SD-WAN traffic bypasses the data centre without equivalent controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Architecture & Implementation

The organisation may gain performance, but it can also lose the inspection and segmentation assumptions that used to exist at the hub. That creates a scenario where traffic still moves successfully, yet trust boundaries become less visible and harder to enforce. The risk is control loss, not connectivity loss.

Why bypassing the data centre changes the security model

When SD-WAN traffic takes a direct path instead of hairpinning through the data centre, the network may be faster and simpler, but the control model changes with it. The old hub often acted as the place where inspection, filtering, logging, and segmentation were assumed to happen. If those functions are not re-created at the edge or in-line, the design still works, but the security posture no longer matches the original trust model.

That is why the issue is not whether packets can reach their destination. The issue is whether the organisation still has equivalent control over what is allowed, what is visible, and what can be separated. In practice, bypass architectures force teams to decide which protections move with the traffic and which protections were only present because everything passed through the centre.

What control assumptions are most likely to break

The most common breakage is a silent gap between connectivity and enforcement. A branch, cloud workload, or remote site may continue exchanging traffic normally while the inspection point, segmentation boundary, or policy checkpoint has been removed from the path. NIST Cybersecurity Framework 2.0 is useful here because it forces the question of whether protect, detect, respond, and recover functions still exist after the routing change.

Another common failure is policy inconsistency. If the data centre used to centralise controls, teams may discover that the same traffic type is now handled differently depending on location, tunnel type, or exit point. That can create uneven enforcement, incomplete telemetry, and gaps in incident investigation. CIS Controls v8 is relevant because inventory, secure configuration, logging, and access control all become harder to trust when the network path changes but the control inventory does not.

In more mature environments, the right comparison is not “hub versus no hub”, but “equivalent control versus assumed control”. NIST Cybersecurity Framework 2.0 and CIS Controls v8 both support that shift in thinking, because the design question becomes whether monitoring, policy enforcement, and recovery can still be executed at the point where traffic now exits.

What good looks like when traffic no longer hairpins through the hub

Good design means the bypass path is not treated as an exception. Inspection, segmentation, and logging should be deliberately redistributed so they follow the traffic or are enforced at equivalent points of control. Where the bypass is to cloud services or SaaS, the equivalent guardrails may need to be at the branch, in the edge platform, or in the cloud security stack rather than in the legacy centre.

The practical test is whether an administrator can answer three questions quickly: what is allowed, where is it enforced, and how would we prove it worked during an incident? ISO/IEC 27001:2022 Information Security Management fits this scenario because it ties control selection to managed risk rather than to a specific network topology. If the topology changes, the controls must still be selected, owned, and tested for the new path.

NIST Cybersecurity Framework 2.0 also helps organisations judge whether the new routing model preserves detection and recovery, not just throughput. If a bypass design cannot show equivalent visibility, equivalent segmentation, and equivalent response evidence, it should be treated as a redesign problem, not a performance optimisation.

Risk and Threat Considerations

When traffic bypasses the data centre without equivalent controls, exposure increases because security functions can disappear from the path while business connectivity remains intact. That creates a false sense of safety: the system appears healthy, but trust boundaries, telemetry, and containment are weaker than before.

Failure mechanism: The organisation removes a central inspection or segmentation point without replacing its enforcement at the edge, so traffic flows normally even though policy checks are no longer consistently applied.

Impact: Unauthorised movement, reduced detection fidelity, and wider blast radius become more likely because compromised or misrouted traffic can traverse the bypass path with fewer obstacles.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01 — Oversight of Cybersecurity Risk ManagementBypass routing changes require oversight of whether controls still match the new trust path.
PR.AA-05 — Least Privilege and AuthorizationEquivalent segmentation and access enforcement are central when bypassing central choke points.
DE.CM-01 — Networks and network services are monitored to find potential cybersecurity eventsBypass paths can reduce visibility unless monitoring moves with the traffic.
Recommendation — Review whether edge controls still satisfy the intended security outcomes after traffic bypasses the hub. Enforce least-privilege segmentation at the new enforcement point rather than assuming the hub still protects traffic. Verify that network monitoring still covers the direct path and produces actionable telemetry.
CIS Controls v8CIS-4 — Secure Configuration of Enterprise Assets and SoftwareNetwork path changes often create uncontrolled configuration drift in security enforcement.
CIS-8 — Audit Log ManagementControl loss often shows up first as missing or incomplete logging on the new path.
Recommendation — Harden the new routing and policy points so bypassing the hub does not weaken the approved configuration. Ensure the bypass path generates logs that are retained, protected, and reviewable.
ISO/IEC 27001:2022A.5.15 — Access controlThe topic is about preserving access enforcement when traffic no longer crosses the centre.
A.8.15 — LoggingDirect paths can remove the logging point that the hub previously provided.
Recommendation — Map access-control decisions to the new path and confirm they are still enforced consistently. Implement logging at the bypass control point and verify it remains available for investigation.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureEquivalent controls at the edge align with never-trust, always-verify design principles.
Recommendation — Apply zero-trust principles so traffic remains verified and segmented even when it skips the data centre.

Practitioner Guidance

What to verify: Confirm where inspection, segmentation, and logging now occur for each major traffic class. If the answer is “somewhere else”, require evidence that the new control point is equivalent in scope and enforcement before accepting the design.

Decision rule: If a bypass path removes a control that used to be relied on for containment or monitoring, treat the path change as a security architecture change, not a routing change. The implementation is only acceptable when the equivalent control set is explicitly documented and tested.

Practitioner takeaway: The goal is not to preserve the old hub, but to preserve the old security outcomes. If the new path is faster yet materially less observable or less enforceable, the organisation has traded away control for convenience.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org