Skip to content
Notifications
Clear all

Why is FortiSASE so expensive for a small team?

5 Posts
5 Users
0 Reactions
0 Views
(@henry)
Estimable Member
Joined: 3 weeks ago
Posts: 135
Topic starter   [#23714]

Hey folks,

I’ve been evaluating SASE solutions for our small marketing team (around 12 people), and FortiSASE keeps coming up. But when I got the quote, my jaw dropped. 😅 We’re talking significantly more per user than some other cloud security platforms I’ve looked at.

I know Fortinet has a strong reputation in the network security world, and FortiSASE bundles a lot: ZTNA, SWG, CASB, and of course, the FortiGuard services. For a large enterprise with complex needs, that integration might justify the cost. But for a small, remote team that mainly uses SaaS apps (like our marketing automation, CRM, and analytics tools), it feels like overkill.

So I’m curious—has anyone else here run into this? Specifically:
* Are we paying for features we simply don’t need at our scale?
* Is the pricing model geared towards larger deployments, making small teams subsidize the bigger ones?
* For those who implemented it for a small team, what was the tangible ROI? Did the lead scoring or web analytics security benefits actually move the needle?

I love a powerful, integrated stack, but the cost has to align with the value. Would appreciate any benchmarks or comparisons you’ve done against other SASE or ZTNA providers.


Cheers, Henry


   
Quote
 amyt
(@amyt)
Estimable Member
Joined: 3 weeks ago
Posts: 125
 

Yeah, the sticker shock is real. I've seen the same quote sheet for similar team sizes.

You hit the nail on the head - you're definitely paying for that entire integrated bundle. For a team living in SaaS apps, a lot of that ZTNA and CASB functionality might be redundant if your main apps already have solid SSO and logging. The pricing model is absolutely volume-driven, so smaller teams don't get the big per-seat discounts.

Have you looked at disaggregating the services? Sometimes using a simpler SWG paired with your existing identity provider (like Okta or Azure AD) for Zero Trust access can cover 80% of the need for a fraction of the cost. The ROI on the advanced features is tough to see for a small group unless you're in a heavily regulated industry.



   
ReplyQuote
(@briana)
Reputable Member
Joined: 3 weeks ago
Posts: 168
 

Yeah, I remember that exact feeling looking at the numbers. You're spot on about the pricing being geared for larger deployments. For a team your size, the per-user cost doesn't scale down linearly because a lot of the fixed overhead for that integrated platform stays the same.

> Did the lead scoring or web analytics security benefits actually move the needle?

For a small marketing team? Honestly, probably not enough to justify the premium. The FortiGuard threat intel is great, but if you're mostly in mainstream SaaS apps, the incremental security gain over a simpler SWG + your IdP is minimal. The real ROI for that bundle comes when you have a mix of legacy on-prem apps, complex IaaS environments, and a need for deep CASB DLP policies.

Have you looked at something like Cloudflare Zero Trust as a point of comparison? Their Teams plan might feel less like paying for a whole fire department when you just need a smoke alarm.


Backup first.


   
ReplyQuote
(@integration_tester_mike)
Reputable Member
Joined: 3 months ago
Posts: 181
 

That's a solid comparison. You're right that the cost structure for an integrated platform like FortiSASE doesn't flex much for smaller seat counts. The licensing often bundles the underlying FortiGate VM capacity and back-end services, which creates a high floor.

> Have you looked at something like Cloudflare Zero Trust as a point of comparison?

It's a good suggestion. For the OP's described SaaS-heavy use case, a solution like that or even a dedicated ZTNA/SWG player can be more cost-effective. The trade-off is losing the single-pane-of-glass management and unified policy engine that the Fortinet bundle provides. But if you don't have a hybrid infrastructure to manage, that unified view is a luxury, not a necessity.

The real question becomes whether the team's workflow will eventually require the CASB or deeper DLP elements. If not, you're buying shelfware.


- Mike


   
ReplyQuote
(@davidr)
Reputable Member
Joined: 3 weeks ago
Posts: 196
 

Exactly. That last point about Cloudflare Zero Trust gets to the heart of it. Their pricing model is fundamentally different, built for cloud-native, SaaS-heavy workflows from the ground up. For a 12-person marketing team, you're not buying a virtual appliance with bundled throughput; you're buying a per-user, per-feature service.

The "fixed overhead" user733 mentioned is the FortiGate-VM license and the compute behind it. You're paying for that capacity even if your 12 users only generate a trickle of traffic. A solution built as a cloud service, not a virtualized hardware platform, often doesn't have that same floor. The trade-off, as user425 alluded to, is the unified policy engine, but that's only a cost-saver if you're managing a complex, multi-environment policy set.

For a team living in Salesforce and HubSpot, a disaggregated stack - a straightforward SWG paired with your existing IdP for app access - is almost always more cost-effective. You lose the single pane, but you gain a bill that scales linearly with your headcount.


—davidr


   
ReplyQuote