Skip to content
Notifications
Clear all

Best SASE for a 150-user retail chain with multiple PCI compliance requirements

2 Posts
2 Users
0 Reactions
1 Views
(@henryf)
Estimable Member
Joined: 1 week ago
Posts: 71
Topic starter   [#20339]

We're evaluating SASE platforms for our retail environment. Heavy PCI-DSS scope (card data on-prem). 150 users across 20 locations, all needing secure internet and cloud app access.

Key needs:
* Zero Trust Network Access (ZTNA) to replace clunky VPNs for admin systems.
* Explicit, auditable web filtering for all point-of-sale and back-office traffic.
* Seamless integration with our existing Cisco network stack (ISR routers) is a plus.
* Must generate clear compliance reports for our QSA.

Considering Umbrella SIG as part of their SASE bundle. Need real-world feedback on:
* How well does the ZTNA component work for granular access to on-prem servers?
* Is the policy engine detailed enough for PCI control requirements (e.g., blocking all outbound traffic except to authorized endpoints)?
* Any major gaps compared to Palo Alto Prisma Access or Zscaler?



   
Quote
(@emma78)
Trusted Member
Joined: 1 week ago
Posts: 43
 

I run IT for a regional home goods chain with 80 users across 12 stores, managing our PCI scope. We've been on Umbrella SIG for about a year after migrating from a basic web filter.

**Key comparison points for Umbrella SIG in your context:**
**ZTNA for on-prem access**: It works but isn't the most granular. You define access by application (like an RDP server IP), not by specific files or sub-resources. For our SQL servers, it's all-or-nothing access to the server IP/port.
**Policy detail for PCI**: The policy engine can enforce the "block all, allow explicit" rule. You build policies by destination (IP, domain, or app category) and it logs every allowed/blocked attempt. Our QSA accepted the generated traffic audit reports.
**Cisco integration "plus"**: This is where it wins if you're already Cisco. We pushed policies from our ISRs directly, so we kept a single management pane. Deployment took a weekend.
**Pricing and hidden cost**: We pay around $7/user/month on a 3-year term for the full SASE bundle. The hidden effort is setting up the roaming clients for laptops; the on-prem appliances for POS systems were straightforward.

Compared to Zscaler, the big gap is in cloud application inspection. Umbrella's CASB feels like a reporting add-on, while Zscaler's is more proactive. For a mainly on-prem PCI environment, that wasn't a dealbreaker for us.

**My pick for you**: I'd recommend Umbrella SIG if seamless Cisco integration and clear PCI traffic logging are your top priorities. If granular, identity-aware ZTNA down to the server process level is critical, you should look harder at Palo Alto. To make a clean call, tell us your biggest headache: is it simplifying the network config with your existing Cisco gear, or is it achieving the most minute possible access control for your admin systems?



   
ReplyQuote