Skip to content
Notifications
Clear all

Rolled out Banyan to 300 users in a finance firm - what went wrong

1 Posts
1 Users
0 Reactions
6 Views
(@martech_trail_blazer)
Trusted Member
Joined: 5 months ago
Posts: 29
Topic starter   [#2247]

Our firm's recent implementation of Banyan Security for zero-trust network access, covering 300 users across trading, compliance, and operations, has been a significant operational challenge. The projected efficiency gains and simplified access model have not materialized as anticipated. Instead, we are managing a series of systemic issues that, in aggregate, question the ROI of the platform in its current configuration for our specific high-compliance environment.

The primary failure points were not in the core security functionality, which is robust, but in the operational integration and user experience design. The financial sector's workflows are non-negotiable, and any tool that disrupts them becomes a liability.

* **Agent Performance and Resource Conflict:** The persistent desktop agent, while necessary for its always-on security posture, has created continuous conflicts with legacy in-house trading applications and market data terminals. The resulting instability—crashes, latency spikes—is unacceptable. Our IT support volume related to application performance has increased by approximately 40% post-deployment, directly contradicting the goal of reducing overhead.
* **Overly Rigid Policy Configuration:** The policy engine, while powerful, lacks the granular conditional logic we require. For instance, creating a rule that allows access to a research portal only from corporate-managed devices *during market hours* while factoring in user department (e.g., compliance always has access) became an exercise in creating multiple overlapping policies. This has led to policy "collisions" where users are incorrectly denied access, requiring manual troubleshooting.
* **Administrative Overhead vs. Promised Automation:** The centralized dashboard is comprehensive, but the administrative tasks for onboarding/offboarding and policy exceptions are more manual than our previous VPN solution. There is no seamless integration with our HR system (Workday) to automate user lifecycle events, forcing a dual maintenance routine in Banyan and Active Directory.
* **User Friction and Shadow IT Risk:** The access flow, particularly for contractors, is perceived as cumbersome. Users report confusion with the trust scoring display and frequent re-authentication prompts for low-sensitivity internal tools. This has already led to departments seeking informal, insecure workarounds to share data, creating new security vulnerabilities the tool was meant to eliminate.

From a marketing operations and analytics perspective, the data export for auditing is sufficient, but the attribution of access events to specific business initiatives (e.g., "access to merger model repository by deal team") is not natively supported. We must enrich logs externally to gain that level of insight for compliance reporting.

The critical question for the community is whether these are configuration shortcomings or inherent platform limitations. Specifically:
* Has anyone successfully mitigated agent-level software conflicts in a dense, proprietary application environment?
* Are there best practices for structuring complex, conditional access policies without exponential complexity?
* Is there a functional API-driven approach to user provisioning that ties into common HRIS platforms we have overlooked?



   
Quote