TL;DR: A Forrester Total Economic Impact study commissioned by Tailscale models a 3,000-employee enterprise and reports 213% ROI, payback in under six months, $1.2 million in present value from retiring legacy VPN and remote access infrastructure, and a 70% reduction in exposure to breach costs for addressable attacks. The governance shift is not about faster networking, but about replacing layered access with identity-based control that reduces friction, overhead, and blast radius.
NHIMG editorial — based on content published by Tailscale: The hidden costs of “good enough” network access
By the numbers:
- The study found that Tailscale delivered a 213% ROI with a payback in under six months.
- Time spent managing remote access dropped by 60%.
Questions worth separating out
Q: How should security teams govern infrastructure access for both people and workloads?
A: They should use one policy model that covers human administrators, service accounts, and automation identities across all infrastructure layers.
Q: Why does simplifying remote access improve both security and operations?
A: Every added access layer introduces configuration drift, support overhead, and more opportunities for broad trust to persist.
Q: What breaks when organisations keep treating VPN access as a trusted internal path?
A: The main failure is that a VPN turns successful authentication into broad network reach, which creates a large blast radius if credentials are stolen or bypassed.
Practitioner guidance
- Map network access to identity entitlement Inventory which users, service accounts, and workloads can reach which internal resources, then remove broad paths that are not tied to a specific business function.
- Retire layered remote access dependencies Document the full stack supporting remote connectivity, including VPNs, load balancers, NAT, and manual support processes, then remove duplicated controls where they add complexity without improving assurance.
- Enforce default-deny connection policy Require an explicit policy decision before any session can connect to a destination, and restrict that policy to the smallest viable set of resources.
What's in the full article
Tailscale's full blog post covers the operational detail this post intentionally leaves for the source:
- Forrester TEI modelling assumptions behind the 3,000-employee composite enterprise
- Breakdown of the $1.2 million present value from retired remote access infrastructure
- Productivity and IT efficiency calculation methods behind the 60% and 50% reductions
- Security risk model used to estimate the 70% reduction in exposure to breach costs
👉 Read Tailscale's analysis of the Forrester TEI study on identity-based networking →
Identity-based networking: what it means for IAM and zero trust?
Explore further
Identity-based networking is now an identity governance problem, not just a transport problem. When access is defined by identity and policy, network design starts to overlap with IAM, PAM, and machine access governance. That means the programme has to account for who or what is allowed to connect, under what conditions, and with what scope. Teams that ignore this intersection leave a gap between identity policy and actual connectivity.
A question worth separating out:
Q: How do teams know whether identity detection is actually reducing risk?
A: Look for fewer unresolved high-risk sessions, faster containment of suspicious privilege use, and better analyst prioritisation. A strong programme changes how quickly the team can identify, contain, and explain identity misuse. If alerts rise but response quality does not improve, the control is producing noise rather than reduction in risk.
👉 Read our full editorial: Identity-based networking shows why “good enough” access is costly