Skip to content
Notifications
Clear all

What SASE actually works for a 100% remote workforce?

2 Posts
2 Users
0 Reactions
17 Views
(@cost_analyst_ray)
Honorable Member
Joined: 7 months ago
Posts: 434
Topic starter   [#14018]

The prevailing narrative suggests that SASE, as a unified concept, is a solved problem. However, my analysis, focused primarily on financial and operational overhead, indicates a significant divergence between marketing promises and the tangible outcomes for a fully distributed enterprise. With a 100% remote workforce, the traditional cost centers of hardware and datacenter transit are replaced by per-user licensing and egress from cloud security points of presence. This shifts the optimization lever from CapEx to OpEx, a transition many organizations are ill-prepared to manage.

I am examining Fortinet's FortiSASE offering through this lens. The integration of SD-WAN, ZTNA, and FWaaS from a single vendor promises simplified management, but the critical question is: at what marginal cost per user? For a scenario of 500 fully remote knowledge workers, I need to dissect the following:

* **The true composition of the per-user, per-month cost.** Does it bundle all necessary components (ZTNA, SWG, CASB, Firewalling) or are these incremental add-ons? Fortinet's historical model often involves separate feature licenses.
* **The data transit and processing model.** Does traffic hairpin through a fixed set of FortiGate-VMs in, for instance, AWS us-east-1 and eu-west-1, incurring cross-region egress charges and latency? Or is the PoP footprint genuinely global and cloud-agnostic?
* **The operational cost offset.** While management may be unified, what is the measurable reduction in FTE hours required for policy deployment and incident response compared to managing disparate point solutions? This must be quantified to justify any premium.

A preliminary comparison with a disaggregated model—using a cloud-native ZTNA provider, a separate DNS-based secure web gateway, and a cloud firewall service—often reveals a lower direct cost but higher administrative burden. The FortiSASE proposition hinges on its operational efficiency gain outweighing its potentially higher licensing cost. I have yet to see a publicly available total cost of ownership (TCO) model from Fortinet that provides the granularity needed for this calculation.

Therefore, my inquiry to this community is rooted in tangible data. For those who have implemented FortiSASE for a fully remote workforce:
* What was your final negotiated per-user, per-month cost, and what exact components (SKUs) does that include?
* How does your actual bandwidth consumption map to your contracted commit? Are you seeing significant overages?
* Have you measured latency penalties for users in regions distant from the primary FortiSASE PoPs?
* Most critically, what was your baseline administrative cost (in hours/month) before, and what is it after implementation?

Without these figures, we are merely discussing features, not financial viability. A solution "works" only if it achieves its security objectives within a predictable and justifiable operational expenditure.

Show me the bill.


CostCutter


   
Quote
(@aurorab)
Reputable Member
Joined: 3 months ago
Posts: 340
 

You've nailed the exact problem with the unified SASE pitch. That shift from CapEx to OpEx isn't just a financial accounting change - it's a complete rework of how you forecast and budget, and most vendors are shockingly opaque about it.

> The true composition of the per-user, per-month cost.

This is where the trouble starts. With Fortinet, and honestly with most of the big names, the "platform" fee often gets you the basic tunnel and maybe SWG. True ZTNA for app access, advanced data loss prevention, or full CASB functionality? Those are absolutely incremental add-ons. You might find yourself needing a "ZTNA User" license *on top of* the "SASE User" license. The final per-user cost can easily double from the initial quote once you enable the features you actually need for a zero-trust remote setup.

Your point about traffic hairpinning is also huge. If every byte from an employee's home office has to hit a PoP for inspection before going to SaaS apps, the latency and egress costs stack up fast. Some newer players are doing local client breakout for trusted SaaS traffic, which helps. But you're right to question the model before you get locked in.


don't spam bro


   
ReplyQuote