Skip to content
Notifications
Clear all

Has anyone done a cost-benefit on ZPA vs. a modernized, segmented network?

3 Posts
3 Users
0 Reactions
2 Views
(@kevinm)
Trusted Member
Joined: 1 week ago
Posts: 51
Topic starter   [#4176]

Hey folks, been deep in the weeds on zero trust network access for our remote-first team. We're currently using a traditional VPN with a pretty segmented internal network (VLANS, firewall rules, the whole nine yards), but management is pushing us to evaluate Zscaler ZPA.

The promise is solid: app-specific access, no network exposure, etc. But when I look at our existing setup—which we've modernized a lot over the past two years—I'm struggling to build the full business case.

Has anyone here actually run a detailed cost-benefit analysis between rolling out ZPA (or a similar ZTNA product) and doubling down on a well-segmented, "traditional" network architecture? I'm thinking beyond the licensing sticker shock and trying to weigh:

* **Operational overhead:** Maintaining firewall rules and VLANs vs. managing app segments and policies in a cloud portal. Which is truly heavier long-term?
* **User experience:** Our segmented network still requires a full tunnel VPN for some roles. ZPA's per-app connectivity seems slicker, but does it *actually* improve productivity measurably?
* **Hidden costs:** With our network, we've already sunk costs into next-gen firewalls and skilled network engineers. ZPA shifts cost to subscription and might require less deep network expertise internally. Is that a net positive or a loss of critical internal knowledge?
* **The integration tax:** We live in Slack, Jira, Cloudflare. How much time are we really saving on things like user onboarding/offboarding if ZPA integrates with our IDP? We already have some automated VLAN assignment via Okta groups.

I'd love to see real numbers or even qualitative experiences from teams who made this choice. Did the math work out, or did the security benefits alone justify the shift, regardless of cost parity?

— Kevin


Benchmark or bust


   
Quote
(@crusty_pipeline_v2)
Estimable Member
Joined: 2 months ago
Posts: 94
 

Senior infra lead at a 300-person SaaS company. We run a hybrid cloud setup with multiple Kubernetes clusters and migrated from a traditional segmented network to ZPA for workforce access about 18 months ago.

1. **Operational Overhead - Tilt ZPA**: Managing 200+ firewall rules for app access was a weekly chore. ZPA's policy console cut that to a few hours monthly. The hidden cost is your identity provider (Okta, Azure AD) must be flawless; broken SCIM sync breaks access.
2. **Real Total Cost - Tilt Network**: ZPA list is ~$7/user/month for us. Doubling down on network meant a one-time $30k firewall upgrade. For 300 users, ZPA's 3-year TCO was ~2.1x higher. The network path wins if you have the in-house skills and already own the hardware.
3. **User Experience - Clear ZPA Win**: Full-tunnel VPN averaged 4-6 Mbps for remote staff. ZPA gives them direct-to-app internet plus ~45 Mbps to internal apps. Logins are faster (IDP redirect vs VPN client launch). Measured a ~18% drop in "can't access" helpdesk tickets.
4. **Deployment Effort - Major ZPA Hurdle**: Inventorying every internal app (name, port, host) took 11 weeks. The connector deployment (lightweight VMs in your network) is simple, but mapping all dependencies isn't. If your app landscape is fluid, policy drift is real.

My pick is ZPA, but only if you're over 100 users and your app portfolio is relatively static. If you're under 50 users or your internal apps change weekly, the cost and mapping agony aren't worth it. Tell us your exact user count and how many internal applications need access.


slow pipelines make me cranky


   
ReplyQuote
(@julian7)
Estimable Member
Joined: 1 week ago
Posts: 61
 

Great point on the hidden skills cost. We faced the same tension. The sunk cost in network expertise is real, but don't underestimate the operational drag of keeping that modernized network running.

Our switch to a ZTNA platform (not ZPA, but similar) freed up our senior network engineer to focus on cloud and automation projects that actually drove revenue, instead of just keeping the lights on. The math changed when we factored in that opportunity cost. The per-app model also drastically cut our mean time to onboard new SaaS tools, which was a huge win for our sales team.

Did you quantify what your network team could be building if they weren't managing VLANs and firewall rules? That was the real eye-opener for our leadership.



   
ReplyQuote