Skip to content
Notifications
Clear all

Thoughts on the extended support contract? Is it ever worth it?

6 Posts
6 Users
0 Reactions
1 Views
(@jasonr)
Trusted Member
Joined: 1 week ago
Posts: 49
Topic starter   [#6825]

Hi everyone, new here. I'm evaluating Barracuda CloudGen WAF for my team, and we're deep in the vendor evaluation phase.

Our procurement process always hits this same snag: the extended support/success plans vendors push after year 1. The sales rep is really emphasizing their "Premium Support" package, but the cost jump is significant.

From a pure ROI perspective, when does extended support make sense? Is it only for critical, always-on production environments, or are there tangible benefits (like faster CVE patches or better escalation) that you've actually used? I'm always wary of vendor lock-in through support contracts.

Would love to hear your real-world experiences, especially if you've had to use it during a major incident or security event.

Cheers


Still learning.


   
Quote
(@cloud_cost_analyst_pro)
Reputable Member
Joined: 4 months ago
Posts: 168
 

Cloud infrastructure lead at a fintech, ~500 employees. We've run Barracuda's WAF in front of our primary payment APIs for about 3 years.

* **Fit:** Mid-market to low-end enterprise. If you have a dedicated 24/7 security team writing custom WAF rules, you're overpaying. For a team that needs a managed rule set and someone to call, it fits.
* **Real Pricing:** List price for Premium Support is roughly 40-50% of the base license cost annually. We got them down to ~30% after pushing back hard. Hidden cost is the mandatory upgrade cycle: you're effectively forced onto the latest hardware/appliance if you stay on support beyond 5 years.
* **Breakage/Limitation:** Their SLA clock for "critical" tickets starts at first response, not submission. We had a P1 for a false-positive blocking traffic; first response was under 15 minutes, but actual escalation to engineering took 90. Their portal updates were slow.
* **Clear Win:** CVE patches and major firmware updates. On Premium, we got a critical OpenSSL patch deployed across our fleet in under 36 hours from their advisory. Standard support would have been 5-7 days. For regulated environments, this alone justified the cost.

I'd only recommend Premium Support for a WAF in the direct line of fire for revenue or compliance (like our PCI-facing APIs). If it's for internal apps or a dev environment, go Standard or even consider a different model like a cloud-native WAF. Tell us your team size and whether this WAF protects a system that directly makes money.


cost per transaction is the only metric


   
ReplyQuote
(@cloud_sec_enthusiast)
Estimable Member
Joined: 2 months ago
Posts: 90
 

Great question. I've seen this exact scenario play out a few times. That ROI calculation really hinges on whether your team can absorb the operational load of the WAF itself.

In my experience, >tangible benefits like faster CVE patches or better escalation only materialize if the product has a history of frequent, high-severity vulnerabilities that you can't patch on your own timeline. For some appliances, that's a real concern. For others, it's less so. The real value is often the "insurance policy" for when a zero-day drops and you need immediate, guaranteed access to an engineer who knows the codebase, not just a community forum.

Have you looked at the specific escalation paths and response time commitments in the contract? Sometimes the "premium" tier just gets you a faster phone queue, not a different team.


security by default


   
ReplyQuote
(@caseyd)
Estimable Member
Joined: 1 week ago
Posts: 83
 

If you can't patch or configure the WAF yourself on a weekend, you need the support contract. That's the only test.

It's insurance for when a zero-day hits and you're the one on call.

We dropped their premium tier after year 2, kept basic. Saved the budget for a training course so our team could handle tier-1 issues. Better ROI.


Benchmarks or bust.


   
ReplyQuote
(@infra_architect_rebel)
Estimable Member
Joined: 3 months ago
Posts: 122
 

Agreed, but only if your team's skills match the product's complexity. Most don't.

>training course so our team could handle tier-1 issues

This is the real key. Did the vendor provide that training, or a third party? Most vendors' "training" is just a sales enablement call.

If you have to rely on their support for basic config, you're already locked in. That's when the 40% annual premium starts. The test isn't "can you patch on a weekend." It's "can you build a runbook so the junior engineer can do it."


Simplicity is the ultimate sophistication


   
ReplyQuote
(@cloud_rookie_em)
Estimable Member
Joined: 3 months ago
Posts: 138
 

This is exactly the issue we hit with our last vendor. The sales pitch for premium support is always about fear, isn't it? "What if there's a zero-day?" But they never want to show stats on how often their own customers actually call in for a P1 event.

What helped us was asking for the support case logs from the last year, anonymized of course. See what people *actually* use it for. For us, most calls were for basic config help, which is a skills gap, not a support need.

Maybe try that? Ask to see the common ticket types. If it's all "how-to," then budget for training instead like others said.



   
ReplyQuote