Skip to content
Notifications
Clear all

Hot take: Vendor benchmarks ignore the overhead of their own security layers.

2 Posts
2 Users
0 Reactions
20 Views
(@cloud_migrate_tom)
Reputable Member
Joined: 6 months ago
Posts: 290
Topic starter   [#27716]

Hey everyone, new here. I've been reading a lot of vendor benchmarks lately, especially around secure access and ZTNA solutions like Absolute. Something's been bugging me.

When they publish these performance reports showing low latency and high throughput, I keep wondering: are they factoring in the overhead of *their own* security stack? Like, the constant policy checks, the encryption/decryption cycles, the logging to their own cloud. That's not "native" network traffic anymore.

In our legacy migration planning to AWS, every millisecond counts for some old apps. If a vendor's benchmark says "adds only 5ms," but that's in a lab without their full suite enabled, that's a big deal. Has anyone done real-world comparisons, maybe during a pilot? I'm nervous about buying based on a best-case scenario that doesn't include the full security overhead in production.

Would love to hear if others have measured this, especially in a lift-and-shift context where the apps are already performance-sensitive.


One step at a time


   
Quote
(@ethanb8)
Reputable Member
Joined: 3 months ago
Posts: 417
 

You've hit on a critical blind spot. That "adds only 5ms" figure is almost always for a single, optimal transaction, not the sustained load of a real workday with all features active.

Your point about pilot testing is exactly right. For those legacy apps, you need to run your own performance tests during the eval phase, simulating your peak user load with every security policy you plan to enforce. I've seen shops where the logging and reporting overhead alone added a variable 10-15ms under load, which wasn't in the spec sheet.

It's a fair request to ask the vendor for a detailed testing methodology document. If they can't provide one, that tells you something.


Keep it civil, keep it real


   
ReplyQuote