Skip to content
Notifications
Clear all

Just built a comparison matrix for our procurement team - happy to share.

6 Posts
6 Users
0 Reactions
21 Views
(@brian)
Reputable Member
Joined: 3 months ago
Posts: 282
Topic starter   [#21714]

We just finished a 6-month bake-off for a zero trust VPN replacement. Banyan was on the shortlist. The marketing is slick, but the reality is more complicated.

I built a side-by-side matrix for our procurement team. Covers the real details: true per-user costs at scale, API limitations for automation, support SLA gaps, and the actual technical debt incurred during deployment. The sales sheets never mention half of this.

Key takeaway: their "simplified" model falls apart if you have legacy systems or need granular network controls. The cost model also gets punitive for contractor-heavy teams.

Happy to share the framework and our findings. What specifics are people most interested in? Pricing gotchas, integration headaches, or the actual session performance under load?


Trust but verify.


   
Quote
(@alexg2)
Reputable Member
Joined: 2 months ago
Posts: 363
 

Thanks for putting this together, it's exactly the kind of real-world analysis that's so valuable here. The point about >contractor-heavy teams is a great catch, that's a cost scenario that often gets completely overlooked until the first invoice hits.

I'd be most interested in the API limitations and the support SLA gaps. In our experience, that's where the operational friction really builds up months after the "win." Would you mind sharing that section?


Stay constructive


   
ReplyQuote
(@devops_dad)
Honorable Member
Joined: 7 months ago
Posts: 543
 

Oh man, the "slick marketing vs reality" gap is such a classic story. Been there with more than one vendor where the demo environment is this pristine greenfield site and then you try to plug in your decade-old CI server or some dusty on-prem finance system and the whole elegant model just crumbles. It's like trying to park a cruise ship in a suburban driveway.

Your point about granular network controls for legacy systems is spot on. We learned that the hard way a few years back with a different ZTA tool. The promise was "simple policy," but when you need to carve out that one weird /28 subnet for a legacy app that only speaks in IPs, not services, you're suddenly deep in custom connector hell, writing more terraform to work around the platform than you would have just managing a traditional VPN. The technical debt accrues silently.

Would love to see your framework. The true per-user costs at scale especially, because that's where procurement always gets blindsided. The per-seat quote is one number, then you realize "user" includes every service account and temporary contractor, and suddenly you're buying blocks of seats you never planned for.


it worked on my machine


   
ReplyQuote
(@contrarian_kevin)
Honorable Member
Joined: 3 months ago
Posts: 418
 

Banyan isn't special there. Every ZTA vendor's simplified model falls apart. The real question is which one leaves you holding the bag with more custom scripting.

Their cost model for contractors is just a classic bait-and-switch. You get sold on employee seats, then find out every temp needs a full license because their "user" definition is conveniently vague.


Just saying.


   
ReplyQuote
(@brian7)
Reputable Member
Joined: 3 months ago
Posts: 254
 

Thanks for sharing this. I'm just starting to look at zero trust options and this is really helpful.

Could you explain the "true per-user costs at scale" part a bit more? I see a lot of pricing per user per month, but I'm guessing the real cost is much higher when you actually deploy.



   
ReplyQuote
(@hobbyist_hex)
Estimable Member
Joined: 3 months ago
Posts: 118
 

That sounds incredibly useful. I'm starting to research this space myself, and the sales pages all look the same.

Could you share the framework you used? I'm trying to build a simple comparison for my team, and I'm not sure what to look for beyond the obvious feature list.

Especially on the "true per-user costs" point. Does that include overhead from the management console, or is it mostly about the hidden license tiers?



   
ReplyQuote