Hey everyone, I've been diving into some research on Zero Trust and ZTNA as part of a potential project at work. I keep reading about the security benefits, but I'm hitting a wall when it comes to the practical side of getting approval.
Our current setup is a traditional VPN. From what I can tell, it "works fine" – users connect, they get access. My boss's main question is the classic one: "Why fix what isn't broken?" The cost for a new ZTNA platform isn't trivial.
I understand the high-level concepts (least privilege, micro-segmentation), but I'm struggling to build a concrete, numbers-backed case. As an analyst, I'm used to working with tangible data.
Can anyone share specific examples or metrics they've used to justify the switch? I'm thinking about angles like:
* How do you quantify the risk reduction of moving from a network-centric to an identity-centric model?
* Are there operational efficiency gains that actually save time/money? For example, simpler onboarding for contractors?
* Does the improved user experience (no more routing all traffic, faster app access) translate to measurable productivity?
I'm also curious if the "agent vs. agentless" debate plays into the cost justification. Like, does one option typically lead to lower support overhead?
Any real-world examples or even a framework for building this business case would be super helpful. Thanks!
Your boss is right to ask for numbers, because the ZTNA sales deck is full of vague hand-waving about "reduced attack surface." Start by quantifying what "works fine" actually costs. How many hours does your team spend managing VPN user groups and troubleshooting split-tunnel configs? How often does a compromised contractor account have access to the entire network because the VPN can't do true app-level segmentation? That's your baseline.
The operational argument is usually stronger than the security one. If you onboard contractors frequently, the time saved not having to build and maintain a labyrinth of network policies can be substantial. But be honest, those savings get eaten up fast by the ZTNA platform's own management overhead and the inevitable "gotchas" in the licensing model.
As for quantifying risk, ask the vendor for a real-world breach scenario your VPN would have allowed and their product would have stopped. When they give you the usual lateral movement spiel, ask for the CVSS score or the financial impact data. They won't have it. It's always theoretical. The productivity angle is the only one with potential hard numbers, but you'll need to run a pilot to measure app latency differences, and you'll be shocked how many legacy apps break without full network tunneling.
Buyer beware.