Five security vendors — Zscaler, Palo Alto Networks, VMware, AppGate, and Perimeter 81 — lead the nascent zero trust network access (ZTNA) market, according to Forrester.
The analyst firm’s inaugural ZTNA New Wave assessed 15 vendors with at least $5 million annual ZTNA revenues and designated the above-mentioned five as “Leaders.” The next group, “Strong Performers,” includes Citrix, Akamai, Netskope, and Google. And finally, Forrester labeled Proofpoint, Cisco, Cloudflare, Wandera, Tencent Security, and Juniper Networks “Contenders.” Cisco and Proofpoint, while ranked, didn’t participate.
Unlike its regular Forrester Wave report, the New Wave evaluates emerging technologies. The analysts spent two hours with each vendor and ranked them against 10 criteria. They positioned the 15 on the wave chart based on ZTNA product and strategy. Forrester also reviewed the companies’ market presence.
Zscaler ZTNAZscaler has the largest ZTNA market presence, according to Forrester, and it is also the only vendor that doesn’t have any “needs improvement” areas on its scorecard. However, it does say Zscaler must add support for server-initiated applications like VoIP.
“Zscaler has the greatest ZTNA mindshare among Forrester clients,” the report says. “The vendor is enrolling organizations with tens of thousands, and in some cases, hundreds of thousands of users.”
ZTNA, which reduces organizations’ attack surfaces by setting secure boundaries around applications and workloads, became an increasingly attractive alternative to VPNs during the pandemic and resulting remote workforce. And as such, it plays a major role in edge-cloud delivered security and networking capabilities, or secure access service edge (SASE) — Forrester calls this “zero-trust edge.”
While Forrester’s latest report focuses on ZTNA, Zscaler also ranks at the top of SASE leaderboards. The cybersecurity vendor has pulled several recent high-profile SASE and ZTNA partnerships with the likes of IBM and CrowdStrike, and Verizon offers a managed SASE service that uses Zscaler’s ZTNA and secure web gateway.
Palo Alto Networks ZTNAPalo Alto Networks’ ZTNA product, Prisma Access, received high marks for its strong combination of deployment options, IDP integration, and non-web apps. It can be self-hosted, deployed as software-as-a-service, or used in hybrid environments.
“The vendor’s support for authenticating and authorizing third parties is superior to other ZTNA solutions,” Forrester wrote.
However, Palo Alto Networks needs to improve its endpoint offering, the scorecard says. “Customers say the mobile experience Prisma Access still needs improvement, and they report some technical challenges with the endpoint software for desktops and laptops.”
In a blog post about the Forrester New Wave, Palo Alto Networks SVP and GM Anand Oswal says ZTNA plays a crucial role in its — and any — SASE platform. “ZTNA offers organizations scalable remote access, consistent identity-based access control, and continuous trust assessment wherever data or users are,” he wrote.
And on the vendor’s most recent earnings call earlier this month, CEO Nikesh Arora said Palo Alto Networks nearly doubled its SASE customer count during the quarter to roughly 2,500. Of those, 25% were new customers.
AppGate ZTNAAppGate, a small, Scandanavian network security startup, is one of the few vendors evaluated in the ZTNA New Wave that doesn’t offer a full SASE stack. Forrester says while it offers “exceptional” integrations with services like IT service management and configuration management database, it lags behind its competitors in inline security inspection.
“ZTNA solutions are usually inline in order to provide authentication and contextual authorization,” the report says. “AppGate’s inline security inspection could be improved by adding more behavioral analytics and machine learning.”
VMware ZTNAVMware, on the other hand, has superior inline security inspection via technologies including watermarking, risk scoring, and behavioral analytics, Forrester says. Its ZTNA, which is part of VMware’s larger SASE platform, integrates well with its own endpoint and device security products as well as major third-party vendors, the report adds.
However, VMware needs to improve its legacy application support, according to the New Wave. Companies with numerous non-web applications aren’t a good fit for VMware’s ZTNA until it improves its remote desktop capabilities.
Perimeter 81 ZTNAThe final ZTNA “Leader,” Perimeter 81, is the youngest of the bunch. The 3-year-old startup, which has raised $65 million to date for its ZTNA and SASE software, focuses on cloud-delivered and managed SaaS deployments. Forester calls out Perimeter 81’s ability to handle non-web applications like VoIP as its major differentiator, but says it still needs to add integration with Microsoft endpoint security and apply more inline security and analytics.
Perimeter 81’s ZTNA is a good fit for smaller enterprises that want to rapidly deploy ZTNA as a service, the report says.
Comments