Modern UK office workspace with secure digital connections representing Zero Trust architecture
Publié le 17 mai 2024

Replacing your VPN with Zero Trust Network Access (ZTNA) is not a simple product swap; it’s a fundamental shift in security philosophy required for the modern, distributed workforce.

  • Legacy VPNs grant excessive, implicit trust, creating a wide « blast radius » once an attacker is inside the perimeter.
  • ZTNA operates on a « never trust, always verify » principle, granting access to specific applications, not the entire network, based on continuous, real-time risk assessment.

Recommendation: Begin by mapping critical applications and user groups to shift from a network-centric to an application-centric access model, effectively dismantling the outdated perimeter-based security posture.

The corporate perimeter is an illusion. For decades, CISOs and their teams have meticulously built digital fortresses, with the Virtual Private Network (VPN) serving as the main drawbridge. The rule was simple: if you were inside, you were trusted. But the mass shift to hybrid and remote work in the UK has shattered this model. Your users are everywhere, on countless devices, accessing cloud applications that live outside the castle walls. The question is no longer just « who is at the gate? » but « what happens once they are inside? »

Continuing to rely on VPNs is clinging to a dangerous assumption of implicit trust. An adversary with a single stolen credential can gain broad access to your network, moving laterally undetected, turning a minor breach into a catastrophic incident. This isn’t theoretical fear-mongering; it’s the operational reality of today’s threat landscape. The traditional « trust but verify » model, where authentication is a one-time event at the perimeter, is fundamentally broken. It fails to account for insider threats, compromised devices, or sophisticated attackers who excel at blending in.

This is why a new, professionally paranoid philosophy is taking over: Zero Trust. It’s not a single product, but an architectural approach built on a simple, ruthless principle: never trust, always verify. This guide deconstructs the core reasons why this strategic shift is happening, moving beyond the buzzwords to give you, the security director, the tactical understanding needed to defend a modern, borderless organisation. We will dissect how Zero Trust contains threats, enhances performance, and, when implemented correctly, improves the user experience without compromising security.

This article will guide you through the critical pillars of a modern security posture. We will explore the core principles of Zero Trust, compare its performance and security against traditional VPNs, and provide actionable insights on implementation, budget allocation, and choosing the right tools for your teams.

Why « Trust But Verify » Is Dead: The Principle of Continuous Authentication

The foundational flaw of a traditional VPN is implicit trust. Once a user authenticates, they are granted broad access to the internal network, effectively becoming a « trusted » entity until they log off. This is a static security posture in a dynamic threat world. An attacker who compromises a legitimate user’s credentials inherits this trust and gains a significant foothold. The « trust but verify » model verifies once at the perimeter and then trusts for the entire session. In today’s landscape, this is an open invitation for disaster.

Zero Trust inverts this model with the principle of continuous authentication. Trust is never permanent; it’s a temporary privilege that is continuously re-evaluated with every single access request. Is the user who they say they are? Is their device secure? Are they accessing a typical resource from a normal location and at a usual time? ZTNA architecture doesn’t grant access to the network; it brokers a secure, encrypted connection from a specific user and device to a specific application. This shift is gaining significant traction, with market analysis showing that 65% of enterprises recently reported plans to replace their VPNs with a more modern approach like ZTNA.

This isn’t just about adding more login prompts. It involves a dynamic assessment of multiple contextual signals—user identity, device posture, location, and application sensitivity—to create an adaptive trust score. If the risk profile changes mid-session (e.g., the user’s device suddenly fails a health check), access can be instantly revoked or stepped up to require further verification. The system is designed to be professionally paranoid, constantly asking, « Should this connection still be allowed? » This moves security from a single checkpoint at the gate to a persistent, vigilant guard escorting every interaction inside the walls.

How to Stop Lateral Movement if a Hacker Breaches One Device?

Imagine an adversary has breached a single laptop in your sales department via a phishing email. With a traditional VPN, that compromised device is now inside your trusted network. The attacker can scan the network, discover other servers and workstations, and move laterally to find high-value targets like financial records or the domain controller. The initial breach was a small fire, but the VPN’s broad network access provided the fuel for a wildfire. This is the danger of a large blast radius.

Zero Trust is fundamentally designed to shrink this blast radius through micro-segmentation. Instead of connecting users to the network, ZTNA connects a verified user on a trusted device directly to a specific, authorized application. The network is abstracted away and becomes invisible. The attacker on the compromised sales laptop can’t see the finance server because, from their perspective, it doesn’t exist. They are isolated within a tiny segment with access to only what that user role explicitly requires. This compartmentalisation acts like submarine doors: a breach in one section is sealed off and cannot flood the entire vessel.

Close-up macro shot of segmented compartments representing network micro-segmentation

This is achieved through a set of advanced capabilities that go far beyond simple IP-based rules. A mature ZTNA solution enforces security by:

  • True least-privileged access: It identifies applications at Layer 7, allowing you to create precise rules for who can access an application and even specific features within it (sub-apps), regardless of the underlying network topology.
  • Continuous trust verification: It constantly assesses trust based on real-time changes in device posture, user behaviour, and application activity.
  • Continuous security inspection: All traffic is subjected to deep and ongoing inspection, even for connections that have already been allowed. This helps prevent threats, including zero-day exploits, from using an established connection as a delivery vector.

By implementing these principles, you ensure that even if an attacker gets in, they are trapped. Their ability to reconnoitre and move laterally is severely crippled, dramatically reducing the potential impact of a breach.

VPN or ZTNA: Which Offers Better Performance for Remote Workers?

A common complaint from remote workers in the UK is the sluggish performance of traditional VPNs. When all traffic—whether for a SaaS application in the public cloud or a server in the corporate data centre—must be backhauled through a central VPN concentrator, it creates a significant bottleneck. This « hairpinning » of traffic introduces latency, degrades the user experience for cloud-based tools like Microsoft 365 or Salesforce, and is notoriously difficult and expensive to scale as the remote workforce grows.

ZTNA architecture resolves this performance issue by design. As a policy enforcement point, the ZTNA broker first verifies the user and their device. Once trust is established for a specific request, it facilitates a direct, encrypted connection between the user and the application, wherever it resides. This means that traffic destined for a cloud application goes directly to the cloud, while traffic for an on-premise resource goes to the data centre. This approach provides faster, more direct access to applications, significantly reducing latency and improving productivity for a distributed team.

This fundamental difference in architecture has a profound impact on both performance and security. The following table breaks down the key distinctions:

VPN vs. ZTNA: A Comparative Overview
Aspect Traditional VPN ZTNA
Access Model Users are granted complete access to the entire network Users connect directly to applications rather than to the network—only to authorized applications
Authentication Verifies users at point of entry with login and password Continuous background monitoring of user and device context to adapt access levels at every connection request
Performance Impact Can introduce latency and are challenging to scale Secure access directly to applications without routing all traffic through a VPN, improving performance and scalability
Security Risk Full network access runs the risk of exposing the network Limits user connections to specific applications and continually verifies trust, better reducing risk

Ultimately, ZTNA not only strengthens the security posture but also removes a major point of friction for remote employees. By eliminating the unnecessary backhauling of traffic, it delivers a faster and more reliable experience that directly supports modern, cloud-centric work patterns.

The User Experience Mistake That Makes Staff Bypass Security Controls

The most sophisticated security control is useless if your staff actively works to circumvent it. A major mistake in many security rollouts is creating excessive security friction—a user experience so cumbersome that it hinders productivity. When employees face constant, intrusive login prompts, slow connections, and restrictive policies that don’t understand their workflow, they will find workarounds. They might use personal devices, unsanctioned cloud storage, or disable security agents, inadvertently creating shadow IT and re-opening the very security gaps you tried to close.

A well-designed ZTNA strategy avoids this by trading blunt, constant friction for intelligent, adaptive trust. The goal is not to eliminate verification but to make it as seamless as possible during normal, low-risk activity, while applying friction only when the context demands it. A user working from their managed corporate laptop, on the corporate network, during business hours should have a near-frictionless experience. The same user attempting to access a critical financial application from a personal tablet on a public Wi-Fi network at 2 AM should face a step-up authentication challenge.

Case Study: Adaptive Trust in Action

With a continuous and adaptive security model, the user experience becomes a balance of security and convenience. As detailed in implementations of this philosophy, users enjoy a smoother workflow because they only need to reauthenticate when their risk level actually changes. For instance, if a device’s antivirus becomes outdated or a user connects from a new, untrusted location, the ZTNA policy can automatically trigger a request for multi-factor authentication. This targeted approach, as noted by security leaders at Microsoft in their adaptive access guides, ensures that security is proportional to risk, preserving productivity and reducing the incentive for users to bypass controls.

The key is to build policies that enforce strict, repeated verification in a way that is mostly invisible to the user. By leveraging a rich set of contextual signals, the system can make intelligent trust decisions in the background. This maintains a robust security posture while respecting the user’s need for a productive and efficient workflow, turning security from a roadblock into a transparent enabler of business.

How to Set Access Rules Based on Device Health and Location?

The power of Zero Trust lies in its ability to make granular access decisions based on rich, real-time context. It moves beyond the binary question of « is the password correct? » to a more nuanced assessment: « Given everything I know about this user, their device, and their current situation, should I grant this specific access request right now? » The two most critical contextual signals in this assessment are device health and location.

Device health, or posture, is a continuous check of the endpoint’s security hygiene. An access rule might require that a device must have the latest OS patches, an active and updated anti-malware agent, and disk encryption enabled before it can connect to any internal application. If a device falls out of compliance, its access can be automatically quarantined to a remediation network or blocked entirely until the issue is resolved. Location provides another layer of context. An access policy can be configured to treat requests from a known corporate office differently than those from an employee’s home network or, more suspiciously, from an unfamiliar international IP address. Combining these allows for powerful rules, such as allowing a user on a healthy device at home to access most apps, but requiring additional MFA if they try to access the same apps from a cafe’s public Wi-Fi.

Diverse professionals in modern UK office demonstrating secure device access with emotional connection

Building these contextual rules requires a framework that can continuously collect and act on this data. A mature ZTNA implementation is not a single product but an ecosystem of integrated components working together.

Action Plan: Your Device Health Verification Checklist

  1. Identity Providers: Verify user identities through strong authentication methods. As confirmed by security frameworks from providers like Fortinet on ZTNA, this must include robust multi-factor authentication (MFA) to ensure only legitimate users gain initial access.
  2. Policy Enforcement Points: Deploy agents or gateways that enforce access control policies based on the combined context of user identity, device posture, and other signals (like location or time of day), acting as the gatekeepers to your applications.
  3. Continuous Monitoring: Implement tools that offer real-time visibility into user and device behaviour to detect anomalies. This continuous feedback loop enables dynamic adjustments to access privileges if a new risk is detected.
  4. Endpoint Detection and Response (EDR): Integrate your EDR solution to feed device health data directly into the ZTNA policy engine. Is the device showing signs of compromise? Block access immediately.
  5. User and Entity Behavior Analytics (UEBA): Use UEBA to establish a baseline of normal user behaviour. Deviations from this baseline (e.g., a user downloading an unusually large amount of data) can trigger an alert or an automated policy action.

Firewall or Backup: Where Should You Spend Your Limited Security Budget?

The classic CISO dilemma is allocating a finite budget across an infinite list of security needs. Do you invest more in prevention (like a next-gen firewall) or in recovery (like a robust backup and disaster recovery solution)? Zero Trust reframes this question. Instead of viewing ZTNA as yet another line item to fund, it should be seen as a strategic reallocation of budget away from a collection of disparate, complex, and often redundant point products.

Traditional perimeter-based security has led to « product sprawl. » A typical enterprise might have separate solutions for VPN access, firewalls, web gateways, data loss prevention (DLP), and cloud access security brokers (CASB). Each requires its own licensing, management overhead, and skilled staff. This complexity not only drives up costs but also creates security gaps between the products. A ZTNA strategy, especially when part of a broader Secure Access Service Edge (SASE) framework, aims to consolidate these functions into a single, cloud-native platform.

Budget Reallocation Through SASE Consolidation

The strategic value of consolidation is a core tenet of modern security architectures. As analysts at Palo Alto Networks explain, SASE solutions integrate ZTNA with Cloud SWG (Secure Web Gateway), CASB, and FWaaS (Firewall as a Service) into a single, integrated service. This consolidation dramatically reduces both network and security complexity. By retiring legacy appliances and overlapping software licenses, organizations can decrease their total cost of ownership while simultaneously increasing agility and strengthening their security posture. The budget once spent managing a dozen different tools can be redirected towards a unified platform that delivers more effective, context-aware security.

Therefore, the question is not « Firewall or ZTNA? » but rather, « Can a ZTNA/SASE strategy allow me to simplify my stack and achieve better security outcomes for the same or lower cost? » For many UK businesses, the answer is yes. It allows a shift from capital expenditures on hardware appliances to a more flexible operational expenditure model, while freeing up security teams from managing complex infrastructure to focus on higher-value tasks like threat hunting and policy refinement.

YubiKey or App: Which MFA Method Is Best for Remote Admins?

Multi-Factor Authentication (MFA) is a non-negotiable cornerstone of any Zero Trust architecture. However, not all MFA methods are created equal, and the stakes are highest for privileged users like system administrators. A compromised admin account is « game over » for the organisation. Therefore, choosing the right MFA method for remote admins is a critical security decision that requires a paranoid level of scrutiny.

The primary contenders are hardware security keys (like a YubiKey) and authenticator apps on a smartphone. While both are a significant improvement over passwords alone, they offer different levels of protection against sophisticated attacks. Authenticator apps, which generate time-based one-time passcodes (TOTP), are convenient but are vulnerable to advanced phishing and man-in-the-middle (MitM) attacks where an adversary tricks the user into entering their code on a malicious site. The app has no way of knowing it’s communicating with a fake service.

Hardware keys based on the FIDO2/WebAuthn standard are inherently phishing-resistant. The key is cryptographically bound to the legitimate website’s domain during registration. When a user tries to log in, the key will simply refuse to authenticate to a fake site, even if the user is completely fooled by the phishing page. This makes it the gold standard for protecting high-privilege accounts.

The choice of method should be based on risk, with a layered approach providing the best resilience.

MFA Methods Comparison for Privileged Access
MFA Type Security Level Best Use Case
Hardware Keys (YubiKey) Phishing-resistant (FIDO2) High-privilege admin accounts accessing critical infrastructure
App-based Authentication Good protection, vulnerable to sophisticated attacks General user access, backup recovery option
Combined Approach Maximum resilience Define and automate multi-factor authentication (MFA) policies to allow users and devices access to the assets they need, then continuously monitor and verify access

Key Takeaways

  • Implicit trust is the fundamental vulnerability of VPNs; Zero Trust replaces it with continuous, real-time verification for every access request.
  • Micro-segmentation is key to stopping lateral movement. ZTNA connects users to applications, not networks, drastically shrinking the « blast radius » of a breach.
  • A successful ZTNA implementation balances security with user experience, applying « intelligent friction » only when risk levels increase to avoid staff workarounds.

Why SMS MFA Is No Longer Secure Enough for UK Businesses?

For years, receiving a one-time code via SMS was seen as a simple and effective way to implement MFA. It was better than a password alone, and its ubiquity made it easy to deploy. However, in the context of a modern, professional security posture, relying on SMS for MFA is akin to using a simple padlock to protect crown jewels. It is no longer considered a secure method, especially for businesses in the UK facing sophisticated threats.

Traditional security models, which grant broad network access to internal users, are insufficient against today’s sophisticated cyberthreats, especially insider threats or threats arising from compromised credentials.

– Microsoft Security, Microsoft Zero Trust Network Access Guide

The fundamental weakness of SMS lies in the underlying telephony network (SS7), which is notoriously insecure and susceptible to interception. More commonly, adversaries use social engineering tactics to perform SIM-swapping attacks. An attacker convinces the mobile provider’s support staff to port the victim’s phone number to a SIM card they control. From that moment on, they receive all the victim’s calls and text messages, including MFA codes. For the targeted UK business, this means an attacker can bypass a critical security layer with a simple, convincing phone call.

Furthermore, the codes themselves are vulnerable. They can be stolen by phishing attacks where the user is tricked into entering the code on a fake website, or by malware on the phone that can read incoming text messages. Given these well-documented and widely exploited vulnerabilities, continuing to use SMS MFA demonstrates a disconnect from the current threat landscape. It’s a « checkbox » security measure that provides a false sense of security. Adopting a true Zero Trust mindset requires moving to more robust, phishing-resistant methods like FIDO2 hardware keys or, at a minimum, certified authenticator apps for all users, and especially for those with privileged access.

To truly secure your organisation, it’s essential to understand why legacy methods like SMS MFA are a liability in a modern threat environment.

The transition from a perimeter-based VPN model to a Zero Trust architecture is the single most important security evolution your organisation can make. It is a strategic response to the reality of a borderless workforce and sophisticated adversaries. To begin this journey, start by identifying a small, high-impact user group and a critical application, and build your first context-aware policies. This iterative approach will allow you to demonstrate value, refine your strategy, and build the momentum needed for a full-scale transformation.

Rédigé par Priya Patel, Priya is a Certified Information Systems Security Professional (CISSP) with 14 years of experience in software engineering and cloud architecture. She actively consults for Fintech and Healthtech firms on GDPR compliance and ISO 27001 certification. Her role focuses on modernizing legacy tech stacks and implementing Zero-Trust security frameworks.