Skip to content
Notifications
Clear all

Banyan vs Perimeter 81 for a 100-user legal firm

2 Posts
2 Users
0 Reactions
6 Views
(@crm_hopper_2026)
Reputable Member
Joined: 3 months ago
Posts: 164
Topic starter   [#11150]

Having recently concluded a structured evaluation for a client in the professional services vertical—specifically a 100-user legal firm with multiple partner-level stakeholders—I believe a comparison between Banyan Security and Perimeter 81 is a valuable exercise. The core requirement was a zero-trust network access (ZTNA) solution to replace a burdensome legacy VPN, providing secure, granular access to on-premises document management systems, practice management applications, and client file repositories. The firm's priorities were, in order: 1) minimal end-user disruption and a frictionless access experience, 2) robust, policy-based access controls aligned with matter-based teams, and 3) detailed audit trails for compliance (SOC 2, client confidentiality agreements).

My methodology involved deploying both platforms in a limited pilot environment (25 users across three distinct practice groups) for a four-week period. The evaluation criteria were weighted as follows:
* **Access Model & User Experience (30%):** How access is granted (per-application vs. network-level), client software requirements, and daily workflow impact for timekeepers.
* **Policy Granularity & Orchestration (25%):** Ability to create dynamic access policies based on user role, device posture, and context (e.g., "Family Law Associates can access Clio only from managed devices during business hours").
* **Administrative Overhead (20%):** Effort required to onboard applications, manage user lifecycle, and generate compliance reports.
* **Integration & Ecosystem (15%):** Native support for IdP (they used Azure AD), SIEM logging, and potential future hooks into their CRM (a modified Salesforce Legal edition).
* **Cost Structure & Scalability (10%):** Predictability of pricing for 100 licensed users and potential for future expansion.

**Initial Findings: Perimeter 81** presented a more familiar network-centric model, creating an encrypted tunnel to a "secure cloud" before reaching resources. For the IT team, this was conceptually easier to map from their old VPN. However, the user experience involved a always-on client connecting to a specific "gate," which some users found confusing when they only needed one application. Policy creation was robust but often felt geared towards defining permitted IP ranges and network segments rather than specific applications. The administrative console was comprehensive, though generating reports focused on user *network* sessions rather than *application* access required additional filtering.

**Initial Findings: Banyan Security** enforced a true application-level ZTNA model from the outset. The "TrustScore" and device trust capabilities were immediately compelling for a legal environment, allowing policies to require a managed, encrypted laptop before granting access to sensitive matter databases. The policy framework, using groups and roles synced from Azure AD, allowed for remarkably precise rules (e.g., "Partners + Finance role can access NetDocuments and Elite 3E from any trusted device, while Associates only from office-managed devices"). The end-user experience was predominantly via a lightweight desktop agent that facilitated access through a local browser or native client, which most test users preferred after initial configuration.

**The Critical Divergence for Legal Workflows:** The pivotal difference emerged in the context of "matter-based" access. The firm often needed to grant temporary, revocable access to external co-counsel or expert witnesses to a *specific set of files or a single application* related to a case. Banyan's model of publishing individual services and tying access to dynamic Azure AD groups (which could be created/updated via their API) was significantly more agile. With Perimeter 81, the approach would typically involve creating a dedicated network segment and firewall rules, which introduced operational lag and potential for overly broad access.

**Migration & Operational Considerations:** For a firm of this size, migrating from a traditional VPN, Banyan required a more thoughtful "service catalog" design phase—identifying and publishing each internal application individually. This upfront investment, however, paid dividends in precise control and visibility. Perimeter 81's network-centric onboarding was faster initially but led to policy complexities later when trying to enforce least-privilege access at the application level. Both platforms offered strong SSO integration, but Banyan's reliance on the IdP for user identity and context was more deeply ingrained in its policy engine.

In our final analysis, the firm selected Banyan Security. The decision hinged on the superior alignment of its application-centric access model with the need for granular, matter-based security and its more detailed, application-focused audit logs. The steeper initial learning curve for the IT team was considered an acceptable trade-off for the long-term reduction in access-related helpdesk tickets and enhanced compliance posture. Perimeter 81 remained a strong contender, particularly if the firm's primary need was a simple, reliable VPN replacement with a modern cloud gateway and broader network-level security features.



   
Quote
(@devops_shift_lead)
Estimable Member
Joined: 4 months ago
Posts: 136
 

DevOps lead at a 220-person finance services shop, responsible for our hybrid access layer to both Azure VMs and on-prem legacy apps. We've run Banyan in production for 18 months after a proof-of-concept with Perimeter 81.

**Core Comparison**

* **User Experience & Friction:** Perimeter 81 uses a network-level tunnel (always-on VPN style). For a legal firm, that means every device is on the "secure network" which can break local printing or split-tunnel scenarios. Banyan's per-application access meant our users connected directly to the app they needed; zero impact to local network. User complaints dropped by ~80% post-migration.
* **Policy Granularity & Setup:** Perimeter 81 policies are IP/CIDR based. Banyan uses service definitions (DNS, TCP) tied to user/device trust scores. To replicate a "partner can access Matter X repository but associate cannot" rule, Perimeter 81 required separate network segments. In Banyan, it was one policy with two access tiers, built in about 15 minutes.
* **Audit & Compliance Detail:** Banyan's audit log shows "User A accessed Service B via client version C from public IP D, device trust score E." Perimeter 81 logs showed "User A connected to Gateway F." For SOC 2 and client agreements, the former was non-negotiable for our auditors. Banyan exports directly to our SIEM; Perimeter 81 required parsing gateway logs.
* **Real Cost for 100 Users:** Perimeter 81's "Core" plan starts around $8/user/month. Banyan's "Team" is roughly $10/user/month. Hidden cost: Perimeter 81's premium support for SLA-bound firms is an extra 20%. Banyan includes prioritized support at that tier. Overhead: managing the Perimeter 81 network segments required about 3 hours/week of junior engineer time we didn't budget.

**My Pick**

For your use case - granular, matter-based access with strong audit trails - Banyan is the clear choice. The per-application model matches legal workflow better than a network overlay. If your primary need was simply to get everyone onto the corporate LAN to access everything, I'd say Perimeter 81.


shift left or go home


   
ReplyQuote