We rolled out Netskope's ZTNA and SWG stack about 18 months ago, replacing a traditional VPN and a legacy proxy. The marketing promised seamless integration and better security posture. The reality, as always, is more nuanced.
**The Good:**
* The user experience, once connected, is solid. No perceptible latency hit for most SaaS apps. The client is relatively lightweight.
* The inline CASB features actually deliver on catching data exfiltration attempts we were blind to before. This is probably the strongest win.
* The policy engine is powerful. Creating rules based on application, instance, and user group is straightforward.
**The Gotchas (the important part):**
* The initial rollout was not "seamless." Expect a significant tuning period for your app discovery and access policies. We had a lot of false positives blocking internal apps.
* The "Private Access" (ZTNA) model requires rethinking your network architecture. You can't just lift-and-shift VPN rules. Legacy apps that assume a flat network or use broadcast protocols are a pain.
* Cost creep is real. The per-user pricing looks fine on paper, but once you start adding features like advanced DLP or custom data classifiers, the quote balloons. Watch your SKUs.
* Support is... tiered. Initial onboarding support was good. Post-sales, standard support can be slow for complex issues. You learn to document everything and escalate early.
Overall, it's a capable platform that does improve our security model. But it's not a magic bullet. The operational overhead is higher than advertised, and the total cost of ownership surprised our finance team. If you're looking at them, build a detailed PoC with your most problematic legacy applications.
—JW
—JW