Skip to content
Notifications
Clear all

My results after 6 months: ZPA cut our VPN helpdesk tickets by 70%.

1 Posts
1 Users
0 Reactions
0 Views
(@gracej)
Reputable Member
Joined: 3 weeks ago
Posts: 193
Topic starter   [#23678]

A seventy percent reduction in VPN helpdesk tickets is a compelling statistic, and I don't doubt you're seeing it. However, I've found that these initial, vendor-supplied metrics often tell a very selective story. What gets lost in the celebratory slide deck is the total cost of ownership and the new class of problems you've just purchased.

Let's start with what you're not measuring. You've eliminated tickets about client configuration and connection drops, but have you audited the increase in tickets related to application-specific access issues now that every app is individually micro-segmented? The old VPN gave a simple network path; ZPA requires perfect application definitions and continuous policy updates. Every new internal tool, every development environment, every legacy system that doesn't fit the zero-trust model becomes a new project for your security and infrastructure teams, not a simple route addition. That labor cost is real, but it's conveniently shifted from the helpdesk budget to the engineering budget.

Then there's the architecture you've committed to. Zscaler is not a product you buy; it's a relationship you enter. Their entire model is predicated on you routing all your private application traffic through their nodes. The technical lock-in is profound. Migrating away from this would require re-architecting application discovery, access policies, and user authentication from the ground up. Have you reviewed the contract terms around data egress, minimum commitments, and price escalation after your initial term? The sales pitch always focuses on the operational savings, but the financial calculus changes dramatically in year three and beyond.

Finally, I'm always skeptical of the security audit performed on these closed-box platforms. You are trusting Zscaler's infrastructure as an extension of your own private network. What assurances do you have beyond their marketing white papers about the integrity of their internal controls, their personnel security, and their ability to resist a state-level compromise? With a self-hosted or open-source zero-trust alternative, you at least have the option to inspect and verify the stack. Here, you are buying a promise.

I would be very interested to see a breakdown of your total spend, including the professional services for initial deployment, the ongoing administrative overhead for policy management, and a realistic projection of your costs for the next five years compared to your old solution. The helpdesk ticket metric is a good start, but it's the tip of the iceberg.

Just my two cents


Skeptic by default


   
Quote