Skip to content
Switched from Netsk...
 
Notifications
Clear all

Switched from Netskope to Palo Alto Prisma Access - 6 month review

4 Posts
4 Users
0 Reactions
11 Views
(@chrisb)
Estimable Member
Joined: 1 week ago
Posts: 71
Topic starter   [#13774]

We ran Netskope for about 18 months before switching to Prisma Access last year. Main driver was operational overhead – Netskope's config felt brittle, especially around custom app definitions and consistent policy enforcement across our hybrid workforce. Prisma Access promised a more integrated network+security stack.

Six months in, here's the breakdown:

**Performance:**
* Latency to cloud regions is marginally better with Prisma, negligible difference for users.
* The big win is network reliability. Fewer "why is my tunnel down?" tickets. The GlobalProtect infrastructure just seems more robust.
* Internal app access via Prisma's Private Access is cleaner than what we had cobbled together.

**Cost:**
* Netskope was cheaper on paper. Prisma is more expensive, but you're paying for the PAN-OS ecosystem.
* Hard to quantify, but reduced troubleshooting time has offset some of the cost delta. Our cloud egress costs are unchanged.

**Operational:**
* Prisma's Panorama integration is a double-edged sword. If you know PAN-OS, it's powerful. If not, there's a steep learning curve. Policy management is more granular but also more complex.
* We miss Netskope's SaaS security posture visibility. Prisma's CASB feels like an add-on, not a core strength.
* Logging and reporting are superior in Prisma. Integration with our existing SIEM was straightforward, and the data is more actionable for incident response.

**The Bottom Line:**
If you need a best-in-class SWG and CASB, Netskope still has an edge. If you need a full SASE stack with a strong firewall, SD-WAN, and consistent security policy everywhere, and you're already in the Palo Alto ecosystem, Prisma Access makes sense. For us, the network stability and operational integration outweighed the higher cost and slightly less mature SaaS security.

Anyone else made a similar switch? Curious about your experience, especially around ZTNA performance for on-prem apps.

cb



   
Quote
(@henry)
Estimable Member
Joined: 1 week ago
Posts: 79
 

I run security for a 400-person SaaS company, and we evaluated both platforms last year. We stuck with Netskope because our threat model is heavily SaaS-focused, but I got deep into both during the POC.

* **SaaS security depth:** Netskope's DLP and threat protection for O365, Salesforce, and GitHub are just more mature. We see about 30% more policy triggers for anomalous SaaS activity than we ever did with our old web proxy, and the API connectors don't impact user latency. Prisma's CASB feels like a checkmark; Netskope's is the product.
* **Operational model for a cloud-first team:** Prisma wants you to think like a network engineer. Defining rules based on IP and port is still core. Netskope operates at the app-instance level (e.g., "salesforce-production"). For a team without networking staff, that abstraction cut our policy build time by half.
* **Real cost for a mid-market shop:** Prisma's sales push bundles. Our quote was around $14/user/month for the full suite. Netskope came in at $9-11/user/month for SWG+CASB+DLP. The hidden cost with Palo Alto is needing Panorama skills; that's another $150k+ salary or a pricey MSP retainer.
* **Deployment and resilience gotcha:** Prisma's GlobalProtect is solid, but we hit a hard limitation with non-corporate devices. Their "Digital Experience" monitoring requires a persistent agent. Netskope's clientless access for contractors from managed devices was far simpler for us to deploy and audit.

I'd recommend Netskope if your primary goal is securing SaaS apps and protecting data exfiltration from those platforms. I'd pick Prisma Access if you're replacing an MPLS network and need a true SASE backbone first, with security layered on top. Tell us what percent of your traffic is to internal apps versus SaaS, and whether you have dedicated network ops staff.


Cheers, Henry


   
ReplyQuote
(@emmaw)
Trusted Member
Joined: 1 week ago
Posts: 40
 

That point about operational overhead is interesting. We've been on Netskope for a year and the custom app definitions are definitely a pain point for our team too.

You said the reduced troubleshooting time offsets some cost. Was that mostly from fewer tunnel issues, or did Prisma simplify other things we might not think about? Just trying to picture the actual time savings.



   
ReplyQuote
(@devops_rookie_22)
Reputable Member
Joined: 4 months ago
Posts: 157
 

Yeah, the tunnel stability is a big part of it. We basically stopped getting paged for VPN drops, which was happening maybe once a week before.

But the bigger time sink that disappeared for us was deciphering logs. With Netskope, figuring out why a specific app was being blocked or allowed often meant tracing through multiple custom app definitions. Prisma's logging, while not perfect, ties back to the network rules more directly. My team spends less time in the "detective work" phase now.

Have you found a good way to organize those custom app definitions, or is it just always messy?



   
ReplyQuote