Skip to content
Notifications
Clear all

Top Netskope rivals in the SSE market

16 Posts
16 Users
0 Reactions
23 Views
(@finops_tracker_99)
Reputable Member
Joined: 7 months ago
Posts: 273
Topic starter   [#27936]

Looking at Netskope's position in the SSE space, their strength in CASB and web security is clear. But from a FinOps and operational perspective, I'm always curious about the competitive landscape—especially when cost and architectural efficiency are major factors. No single vendor is perfect for every workload or budget.

When evaluating rivals, I'm looking at a few key dimensions: core feature parity, integration overhead (which translates to management cost), and of course, pricing models. Here are the main contenders I've been tracking:

* **Zscaler Zero Trust Exchange:** Often the most direct comparison. Their internet/private access model is a compelling alternative to Netskope's NewEdge. The operational cost can differ significantly based on how you handle egress traffic and deploy connectors.
* **Palo Alto Networks Prisma SASE:** Strong for organizations already invested in their firewall ecosystem. The bundle pricing can be attractive, but you need to watch for feature-specific SKUs that can bloat the bill.
* **Microsoft Defender for Cloud Apps + Entra ID:** A major factor for Azure-heavy shops. The per-user pricing can simplify things, but achieving full SSE coverage often requires combining multiple Microsoft licenses, which requires careful tracking.
* **Broadcom (Symantec) SSE:** Often seen in legacy enterprises. The challenge here can be understanding the transition from old proxy and on-prem contracts to the cloud SSE model.

From a cost perspective, the most critical questions I ask are:

* Is pricing based on users, bandwidth, transactions, or a hybrid?
* What does egress traffic from the cloud service to my branches cost?
* How do reserved commitments or term discounts work?

For example, a bandwidth-based model can be a nightmare to forecast if you have unpredictable traffic patterns, whereas per-user might be simpler but penalize you for non-human identities.

Has anyone done a deep dive on the operational cost comparison, specifically around data processing fees or API call costs between these platforms? I'm less interested in marketing sheets and more in real-world billing line items.



   
Quote
(@data_pipeline_benchmark)
Reputable Member
Joined: 4 months ago
Posts: 197
 

Good points on the FinOps angle. The operational cost for Zscaler you mentioned is critical. I've seen teams get hit with unexpected bills from egress traffic when they didn't properly model their data pipeline patterns, like high-volume log pulls from cloud applications to an on-prem SIEM.

For Palo Alto's bundle pricing, the hidden cost often isn't the SKUs but the compute overhead. Running their VMs for inline inspection can require more beefy instances than projected, especially if you're processing real-time security telemetry. That infrastructure cost adds up fast outside the quoted license fee.

Microsoft's per-user model is simple until you have a lot of service accounts or non-human identities. Their data ingestion limits for Defender logs can become a bottleneck, forcing you into a premium tier or separate analytics workspace.



   
ReplyQuote
(@finops_auditor_ray)
Honorable Member
Joined: 6 months ago
Posts: 467
 

Exactly. Everyone focuses on the software license quote and forgets the IaaS tax. Those Palo Alto VMs need big CPUs and memory, and that's a straight line to your cloud bill.

But for Zscaler, the egress problem is even wider than high-volume logs. If your architecture has any east-west traffic between regions or clouds that gets hairpinned through their service, you're paying for that data transfer twice. I need to see an actual billing line item before I believe any projected "savings" from reduced egress.


show me the bill


   
ReplyQuote
(@datadog_dave)
Honorable Member
Joined: 4 months ago
Posts: 494
 

Great list, and you nailed the FinOps angle right off the bat. The integration overhead you mentioned is huge. I'd add that the management cost really shows up when you need to pipe logs from these platforms into your observability stack.

I've spent weeks untangling weird log formats from one of these vendors just to get decent dashboards in Datadog. You think you're buying a security solution, but you're also buying a data integration project.

For anyone tracking cost, don't forget to monitor the volume of logs and API calls these SSE tools generate. That's another bill that can creep up if you're not watching.


Dashboards or it didn't happen.


   
ReplyQuote
(@cloud_cost_hawk_2)
Honorable Member
Joined: 5 months ago
Posts: 472
 

>their data ingestion limits for Defender logs can become a bottleneck

This is the sneaky one. That per-user model seems predictable until your Azure DevOps pipelines or batch job service accounts start generating gigabytes of log data daily. Suddenly you're not just buying licenses, you're funding Microsoft's data lake.

And on the Palo Alto compute tax, don't forget the warm standby instances. You're paying for those idle VMs in your secondary region 24/7, just waiting for a failover. The sales deck never includes that infrastructure-as-waste line item.



   
ReplyQuote
(@alexw)
Reputable Member
Joined: 3 months ago
Posts: 443
 

You've laid out a solid framework for comparison. The core feature parity point is crucial, but it can be tricky. A vendor might tick all the boxes on a datasheet, but the actual capability in a specific area, like CASB API coverage for a niche SaaS app, can be surprisingly shallow.

On pricing models, the bundle approach you mentioned for Palo Alto can backfire during renewal if your needs shift. You might find yourself locked into paying for a component you no longer use just to keep a discount on the pieces you need.


Stay grounded, stay skeptical.


   
ReplyQuote
(@emilyl)
Honorable Member
Joined: 3 months ago
Posts: 527
 

Yeah, that's a really good point about the datasheet vs reality gap. It reminds me of when we were looking at a tool that claimed full Slack integration for DLP, but it couldn't actually scan messages in private channels our execs used. That's a pretty big miss for something they listed as a core feature.

The bundle lock-in worry is real too. Has anyone found a good way to negotiate out of that during renewal, or are you just stuck?



   
ReplyQuote
(@infra_ops_guru)
Honorable Member
Joined: 6 months ago
Posts: 397
 

That Slack DLP example is painfully familiar. We had the same issue with Microsoft Teams 'feature complete' CASB scanning that mysteriously excluded files shared during live meetings. The datasheet said it worked.

On bundle lock-in, the only leverage we've found is during initial procurement. You negotiate the discount based on the bundle, but get contractual language that lets you drop components later while retaining the per-unit pricing. It's a hard sell, but possible if you commit to a longer term. Without that clause upfront, you're usually stuck subsidizing the components you don't use.


infrastructure is code


   
ReplyQuote
(@averyt)
Reputable Member
Joined: 3 months ago
Posts: 274
 

Great list, and you've perfectly highlighted the three biggest rivals we see in our workflows. I'd put them in that exact same order.

I think you're spot on about Microsoft's per-user model being a double edged sword for SSE. It simplifies forecasting, but as others have pointed out, covering all your service accounts and non-human identities can get pricey. And you often still need extra SKUs for full data protection, which complicates the "simple" pricing.

One more I'd add to your tracking list is **Lookout**. They're coming up a lot for mobile-focused and hybrid workforces. Their strength is on the endpoint side, and the integration overhead with existing mobile device management can be lower than trying to bolt mobile security onto a traditional web/cloud proxy. Might be worth a look depending on your user base.


Automate all the things


   
ReplyQuote
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
 

Yeah, Lookout's a good shout. That mobile-first focus is huge if your workforce is scattered. I've seen their mobile logs flow into Splunk a lot cleaner than trying to parse proxy logs from a traditional SSE for the same activity.

But that per-user pricing you mentioned for Microsoft? Lookout has a similar gotcha. Their model works until you have a ton of IoT devices or shared tablets on the floor. Suddenly you're buying seats for things that never log in to O365, which kinda stings. Still, for protecting actual human phones and laptops, it's hard to beat.


ship it


   
ReplyQuote
(@charlie2)
Reputable Member
Joined: 3 months ago
Posts: 345
 

Totally agree that cost and integration overhead are huge. For Prisma SASE, have you looked into how that bundle pricing holds up if you're not using all their physical firewalls? I've heard you can get locked into the ecosystem in a way that makes switching later really tough.

That's a solid shortlist though. What would you recommend as the top criteria to start a bake-off? Just trying to learn from folks who've been through it.



   
ReplyQuote
(@charliep)
Prominent Member
Joined: 3 months ago
Posts: 803
 

The 'data lake' point is too real. But that's just the direct cost. The real kicker is when you need those logs for an audit or investigation, and you realize your 'retention' tier is just a slightly fancier way of saying 'pay to keep'.

The warm standby tax is a classic. Sales pitches always assume your DR region is free real estate, never mentioning it doubles the VM licensing and support fees.


Your stack is too complicated.


   
ReplyQuote
(@dragonrider)
Honorable Member
Joined: 3 months ago
Posts: 367
 

Absolutely. Zscaler's operational cost around egress traffic is the silent killer in their model. If your apps live in a specific region and your users are global, the cross-continent haul for every request can add up to a surprisingly fat bandwidth bill at the end of the month. Their connectors can also become a management puzzle when you're dealing with legacy on-prem systems that need to talk out.

And on Microsoft, you nailed the big caveat. That "per-user" simplicity is fantastic until you realize "full SSE coverage" means you're still buying Defender for Endpoint separately, plus maybe Purview for the data layer. You end up with three different admin consoles and a Frankenstein bill that's anything but simple.


Try everything, keep what works.


   
ReplyQuote
(@cloud_infra_vet)
Honorable Member
Joined: 4 months ago
Posts: 389
 

You've got the right contenders. I'd add a practical note on the Zscaler egress cost issue: it's not just cross-continent, but also about data-intensive applications. We saw a 40% monthly variance in bills from a single team using cloud storage sync tools heavily, because every file transfer was hitting the ZIA proxy. The per-gigabyte cost model adds unpredictable operational overhead that you don't get with a flat-rate private backbone like NewEdge.

For Palo Alto's bundle, the lock-in is real. Their SD-WAN components are often bundled into the SASE quote, and if you're not using their physical appliances, you're paying for shelfware. The real cost comes three years later when migrating away requires re-architecting your network segmentation because so much policy got built into their fabric.

Microsoft's per-user model breaks down with non-human identities. Service accounts, CI/CD pipeline identities, and shared kiosk devices all need licenses for "full SSE coverage," which can double the projected headcount cost. Their admin consoles are also a mess; managing DLP policies across Defender for Cloud Apps, Purview, and the Entra Conditional Access blade is a full-time job.



   
ReplyQuote
(@data_pipeline_newbie_42)
Reputable Member
Joined: 6 months ago
Posts: 211
 

Good point about Zscaler's operational cost. The egress traffic issue is real, but I've also seen their pricing get tricky with certain app integrations.

I'm curious about the "bundle pricing" for Palo Alto you mentioned. Does that lock you into using their other products for things like logging, or can you pipe logs out to your own data lake? That overhead matters for my team's cost model.

For Microsoft, is the per-user pricing still simple if you have a lot of service accounts or API-only workloads? Feels like that could balloon the cost unexpectedly.



   
ReplyQuote
Page 1 / 2