Skip to content
Notifications
Clear all

Worth migrating from legacy VPN to Banyan for a 50-user shop?

3 Posts
3 Users
0 Reactions
9 Views
(@hannahm)
Reputable Member
Joined: 3 months ago
Posts: 217
Topic starter   [#28153]

Hi everyone! I'm new to the whole Zero Trust thing, but I've been tasked with looking into modernizing our remote access. We're a team of about 50, mostly devs and marketing, and we've been using the same clunky IPSec VPN for years. The complaints about speed and constant drops are getting pretty loud.

I've been reading about Banyan Security and the promise of device trust and least-privilege access sounds great. But I'm honestly a bit overwhelmed. For a shop our size, is migrating actually worth the pain? I'm especially worried about:
* The setup complexity compared to just handing out VPN configs.
* Whether the per-user pricing adds up fast for 50 people.
* If the day-to-day management for a small team (we don't have a dedicated security person) is a huge burden.

We all use a mix of personal and company devices, and we mainly need to reach a few internal web apps and our dev environments. Has anyone made a similar switch from an old VPN? How bad was the migration, and what were the real day-to-day benefits (or new headaches)? 😅

New here!


Just my two cents.


   
Quote
(@cameronj)
Reputable Member
Joined: 3 months ago
Posts: 324
 

Oh, you're worried about the per-user pricing and the management burden for a small team. Good, you should be. That's the part the shiny Zero Trust marketing glosses over entirely.

The migration pain is real, but for your size and mix of devices, the constant complaints about VPN drops might actually make it worthwhile, if only to stop the endless support tickets. You'll trade the technical pain of a split tunnel config for the administrative pain of defining explicit access policies. No more just "being on the network," which is a good thing. But the real sticker is the ongoing cost versus your old VPN appliance's capital expense. For fifty people, you're committing to a forever operational spend that adds up alarmingly fast, and you don't have a security person to babysit the policy updates. Have you run the five-year TCO against just getting a better, modern VPN?

You mentioned a mix of personal and company devices. That's where the device trust part gets either very useful or a total nightmare, depending on how you define "trust." How are you planning to handle that?


Trust but verify.


   
ReplyQuote
(@consultant_mark)
Reputable Member
Joined: 5 months ago
Posts: 231
 

Your concerns about management burden and pricing are valid, but focusing solely on the operational spend versus a VPN's capital expense misses a key element of total cost. The financial impact of your current VPN drops and support tickets, especially for a dev team waiting on environments or marketing missing deadlines, likely exceeds any per-user subscription fee. You're quantifying pain, not just line items.

You're correct that you'll trade split-tunnel configuration for policy management. However, for a defined set of internal web apps and dev environments, that policy definition can be a one-time effort per resource. The ongoing burden isn't in constant policy updates, but in the initial mapping of who needs what. Without a dedicated security person, the clarity of "dev team gets dev environment A, marketing gets web app B" can actually simplify access reviews.

The mix of personal and company devices is where Banyan's device trust becomes critical, and that's the complexity bump. You'll need to define what a "trusted" device means for your shop, which might be as simple as a managed OS version and disk encryption. That's a new conceptual layer, but it directly addresses the risk your current "just hand out configs" model ignores.



   
ReplyQuote