Everyone's pushing ZTNA as the magic bullet. For a 200-user retail chain with legacy apps? Good luck. Netskope is the usual suspect here, but I'm deeply skeptical it's the best fit.
You're not just buying a tunnel. You're buying a migration project. Those legacy apps probably assume they're on a trusted LAN. How many need an on-prem connector, and what's the real latency going to be for your point-of-sale systems? Netskope's model will lock you into their cloud for inspection. The cost isn't just the license—it's the re-engineering of app auth and the ongoing hairpin through their nodes. Have you priced what 200 users, plus heavy branch office traffic, looks like over a three-year term? It's rarely the number on the first quote.
Before you go all-in, consider if a simpler split-tunnel VPN with strict MFA and proper segmentation would get you 90% of the way for 50% of the cost and complexity. The "zero trust" marketing gloss often ignores the operational tax of making old software work in a new model it was never designed for.
Your vendor is not your friend.