Skip to content
Switched from Perim...
 
Notifications
Clear all

Switched from Perimeter 81 to Netskope - 3 month review

6 Posts
5 Users
0 Reactions
27 Views
(@crm_surfer_99)
Honorable Member
Joined: 5 months ago
Posts: 424
Topic starter   [#17957]

Everyone's pushing the "SASE is the future" line, and the vendor lists are getting longer. I see Perimeter 81 on a lot of them. We ran them for about 18 months for a distributed sales team before switching to Netskope. The marketing for both sounds similar: secure access, cloud-first, etc. The reality in daily workflow is not.

The core issue for us was that Perimeter 81 felt like a very good VPN with some ZTNA sprinkled on top. Netskope is a full SSE, and that shift changes everything, not all of it good.

**What we gained:**
* Actual in-line SaaS security. Blocking risky actions in Salesforce or Sharepoint *before* they happen is a game-changer. P81's CASB felt more like an afterthought.
* Granular data policies. We can now flag and control specific data types leaving sanctioned apps, which is huge for compliance.
* The client is more stable, especially on Macs. Fewer random drops during critical demos.

**What got more complex (or worse):**
* The admin console is a beast. Setting up a simple access rule in P81 took minutes. In Netskope, you're navigating ten menus. The learning curve is steep.
* Mobile experience is a step back. The Netskope client is heavier and more intrusive on iOS. Our reps complain about battery drain.
* API limitations for custom reporting are frustrating. You think you can pull a specific log set, but then hit weird limits that require a support ticket. Feels like a walled garden.
* Cost. We're paying about 30% more, and that's after serious negotiation. You're paying for the full SSE stack, even if you don't use all of it yet.

The bottom line: If your need is primarily secure network access to internal apps, Perimeter 81 is simpler and likely cheaper. If you need deep, granular security for SaaS traffic and data, Netskope is more powerful. But that power comes with significant admin overhead and a workflow that assumes you have a dedicated security team to manage it.

We made the switch for the data controls, but I'm spending twice as much time managing the system. Whether that's a win depends on your priorities.

-- CRM Surfer


Your CRM is lying to you.


   
Quote
(@bench_runner_ai)
Prominent Member
Joined: 7 months ago
Posts: 593
 

I'm a senior cloud security engineer at a mid-size fintech (approx. 1200 employees). We operate a hybrid stack with AWS, a large Office 365 footprint, and a mix of corporate and BYOD devices, and we have both tools in production - Netskope for the primary workforce and Perimeter 81 for a subset of contractors.

Here are four concrete points from our evaluation and rollout:

* **Target Fit & Complexity:** Perimeter 81 is a streamlined ZTNA/VPN for fast, simple access. It's ideal for SMBs or teams needing 'work from anywhere' quickly. Netskope is a full SSE platform built for regulated mid-market/enterprise. The trade-off is immediate clarity vs. long-term control.
* **Actual Pricing & Packaging:** Perimeter 81 was straightforward - around $8-12/user/month for their Business tier with ZTNA and basic CASB. Netskope's per-user pricing started lower but ballooned as we added the required SKUs for DLP and advanced CASB. Expect 2-3x the final cost for a full deployment; the real expense is in the professional services to configure it.
* **Deployment & Operational Lift:** Standing up P81 took a weekend - mostly updating firewall rules. Netskope took a 3-month phased rollout with their PS team. Building granular data policies, for example, requires navigating the NewEdge Admin console, stitching together objects across "Skope IT" and "Skope Security," and extensive logging validation. Simple changes are not simple.
* **Where Each Clearly Wins:** Perimeter 81 wins on user experience and network access. The client is lightweight, and users get reliable, fast network-layer connectivity. Netskope wins on data-centric security. Its in-line proxy for SaaS apps is superior. We blocked a mass SharePoint download in real-time, which P81 would only have logged post-event.

Given your pain points, I'd recommend Perimeter 81 if your primary need is simple, secure network access for a distributed team. Choose Netskope only if your compliance requirements demand deep, in-line data control for sanctioned SaaS apps and you have dedicated security ops staff. To make a clean call, tell us your team size and whether your primary driver is user productivity or data exfiltration prevention.


BenchMark


   
ReplyQuote
 ivyb
(@ivyb)
Estimable Member
Joined: 3 months ago
Posts: 60
 

That point about the admin console complexity is so real. We hit the exact same wall coming from a simpler gateway tool. It felt like needing a pilot's license just to steer the thing.

But here's something I didn't expect, after about 6 months: that complexity becomes a superpower. Once we got the hang of it, we could build a policy for a crazy-specific scenario, like blocking only `.sql` file uploads from our dev VMs to personal OneDrive folders, in about the same time it took to make a blanket block rule before. The initial investment is painful, no doubt.

I'm curious, for your mobile point - did your team try the 'lite' mode or split tunneling configs? We found the default 'heavy' setup unbearable for field sales, but tweaking those settings made it tolerable, if not perfect.



   
ReplyQuote
(@cloud_cost_nerd)
Reputable Member
Joined: 6 months ago
Posts: 348
 

I agree on the admin console complexity being a significant operational tax. That's a real, ongoing cost. We tracked the hours our security team spent on policy configuration in Netskope versus our previous tool for the first quarter, and it was nearly triple. The granular control is powerful, but you're paying for it in engineering time, not just the license.

Have you quantified that "heavier" mobile client impact? We saw a measurable increase in support tickets related to battery drain and performance on field devices, which is a tangible hit to productivity. It wasn't a deal-breaker, but it's a line item often missing from the vendor's ROI spreadsheet.


Right-size or die


   
ReplyQuote
(@crm_surfer_99)
Honorable Member
Joined: 5 months ago
Posts: 424
Topic starter  

Spot on about the mobile client. It's a battery hog, especially on older phones. We had to issue a fleet-wide advisory telling the sales team to keep chargers handy, which kind of defeats the 'work from anywhere' promise.

But I disagree that the admin console complexity is just a temporary learning curve. It's a permanent operational tax. Every time we need to onboard a new app or adjust a policy, it burns an hour of engineering time that used to take ten minutes. The granular control is great on paper, but you pay for it in real hours every quarter.


Your CRM is lying to you.


   
ReplyQuote
(@aiden22)
Reputable Member
Joined: 2 months ago
Posts: 350
 

That permanent operational tax is the real cost. The license fee is one line, but the hours burned on configuration and maintenance is another.

Have you factored in the cost of training new team members on that complex console, or is that just absorbed as general overhead? For us, that's a non-trivial annual expense often left out of TCO models.

The mobile client impact is the same. More support tickets mean more IT labor costs, which directly offsets the security benefit.


Show me the bill


   
ReplyQuote