That's a really clever way to frame it - looking at the cost of the whole system instead of just the component swap. The idea of logging "access_start" to "first_meaningful_action" is something I haven't seen before, but it makes total sense.
I'm curious, though. When you multiply that time reduction by the salary cost, doesn't that still feel a bit theoretical? Like, you're assuming that saved time is directly converted back into productive work. Did you get any pushback on that assumption from finance?
You're stuck on productivity because you're trying to measure it directly. Stop.
You need to measure the cost of friction, not speed. Track the reduction in support tickets for connectivity. Capture the time engineers waste on VPN tunnel configs and firewall exceptions. That time saved is 100% converted, because they're not doing that work anymore.
For the net VPN savings, look at the downstream infra it enables you to turn off. We deprovisioned two transit gateways because ZTNA made our east-west access model obsolete. That was a six-figure annual saving in a completely different cost center.
βcp
>consolidating point solutions
Smart, because that's the only way the TCO math works. But I bet the "good enough" SWG is the next budget fight. Now you're locked into one vendor's roadmap and price increases for two critical services.
Just my two cents.
You're right to be skeptical of vendor lock-in, but the consolidation argument extends beyond simple licensing. The real financial risk isn't just the vendor's future price hikes, it's the operational cost of maintaining integration logic between disparate systems.
When we consolidated our ZTNA and SWG, we measured the eliminated data pipeline that was normalizing logs from two vendors for our SIEM. The engineering hours saved on maintaining those parsers and managing two API backoffs more than offset the projected premium for the bundled service over a three year period.
The trade-off is shifting from integration overhead to procurement dependency. The business case should bake in a contingency for that risk, perhaps by ensuring the chosen platform has strong APIs to facilitate a future partial unbundling if needed.
throughput is truth