Remote and hybrid working is now normal, and so is the question of how people safely reach company systems from home, a client site or a hotel. For years the answer was a VPN. VPNs still have their place, but the way most organisations think about remote access has shifted towards zero trust.
This guide explains the difference in plain language and gives practical steps you can take whichever approach you use.
How a traditional VPN works
A VPN creates an encrypted tunnel from a user's device into the office or cloud network. Once connected, the device is effectively "inside", often with access to large parts of the network.
That is convenient, and it has a weakness: trust is granted once, at connection time. If an attacker steals a user's credentials, or the user's laptop is compromised, they may be able to move around the network and reach systems the user never needed. VPN appliances are also an internet-facing target, so they need prompt security updates.
What zero trust means
Zero trust is a set of principles rather than a single product. The US National Institute of Standards and Technology describes it in NIST SP 800-207. The core ideas:
- No implicit trust based on network location. Being on the office network does not, by itself, make a request trustworthy.
- Verify every request. Access decisions consider who the user is, the health of their device, and what they are asking for, every time.
- Least privilege. Users get access only to the specific applications they need, not the whole network.
- Assume breach. Design as if an attacker may already be inside, so that one compromised account or device cannot reach everything.
Zero trust network access (ZTNA)
Zero trust network access applies these principles to remote access. Instead of connecting users to a network, it connects them to specific applications, after checking identity, MFA and device health. Users never see the rest of the network, which greatly limits how far an attacker can move.
| Traditional VPN | Zero trust network access | |
|---|---|---|
| What the user reaches | A network or subnet | Specific applications |
| When trust is checked | At connection | On every request |
| Lateral movement risk | Higher | Lower |
| Device health checks | Sometimes | Usually built in |
Many organisations move gradually: keep the VPN for a few legacy needs while moving most applications behind identity-based access.
Practical steps for safer remote access
Whichever approach you use, these steps make the biggest difference:
1. Require MFA for all remote access
No remote connection, VPN or otherwise, should work with a password alone. Use an authenticator app or passkeys rather than text messages where you can.
2. Connect access to your identity provider
Let people sign in to remote access with their Microsoft 365 or Google Workspace identity, so disabling a leaver's account immediately removes their access everywhere.
3. Check device health
Allow access only from devices that are managed or meet basic requirements: up-to-date operating system, disk encryption, screen lock and endpoint protection.
4. Limit what each person can reach
Even with a VPN, use firewall rules and network segmentation so remote users reach only the systems they need. Separate administrative access from everyday access.
5. Retire the riskiest exposures
Remote Desktop (RDP) or SSH open directly to the internet is a common way in for attackers. Put such access behind a VPN or a zero trust gateway, or replace it with managed access tools.
6. Keep remote access systems patched
VPN gateways and firewalls are high-value targets. Apply security updates promptly and subscribe to your vendor's security notices.
7. Log and review
Record who connected, from where and to what. Alert on unusual activity, such as sign-ins from unexpected countries or at odd hours.
Where to start
A good first step is an inventory: what remote access methods exist today, who uses them, and what they can reach. That usually reveals quick wins, such as enforcing MFA, closing an exposed RDP port or tightening VPN access. If you would like help reviewing your remote access or planning a move towards zero trust, book a free consultation.