Are VPNs holding your organisation back? With the rise of remote work and the increasing threat of cyberattacks, it has never been more critical to ensure that your organisation’s critical resources are protected.
ZTNA or VPN — which one to choose? This article looks at the limitations of VPNs, and at how Zero Trust Network Access provides a more secure and efficient alternative.
What does a VPN do?
VPNs were created to connect two trusted networks, allowing communication between them. An organisation might use a VPN to connect two different sites and exchange data.
In practice, users log into a VPN server which verifies their identity. If the identity is validated, access is granted to the network and its resources.
With time, organisations started using VPNs to give access to external users such as remote workers and third-party contractors — meaning VPNs are now used to connect an untrusted device to the network.
The VPN worked fine when the world was network-centric and the organisation’s data centre was the security perimeter, since all the applications and resources lived inside it. But remote access VPN is not enough anymore, and no longer provides the security, the visibility or the user experience required. Here is why.
Why the VPN is not enough anymore
Over the years we have seen a widespread move to cloud and SaaS, so third parties now manage infrastructures and applications. At the same time the value chains between suppliers and distributors have fragmented. The number of parties involved has increased and software dependency has risen with it. The switch from MPLS to SD-WAN, where the network has become a cloud service, made the security perimeter explode, because the network is now on the internet.
And this is where the VPN comes up short on both security and efficiency.
VPNs are not adapted to cloud needs
VPNs are inadequate for mobility and cloud needs. Since a VPN is a point-to-point solution allowing access to one site or one data centre at a time, multiple VPNs are needed to reach multiple sites. VPNs therefore cannot be used for accessing SaaS applications, and ZTNA or CASB technologies must be used in those cases.
Scalability can easily become a challenge
VPNs have proven to be resource-intensive, needing enormous infrastructure. As the number of users increases, the organisation needs high-capacity servers and network equipment to support a large number of VPN connections.
Outdated VPNs are opportunities for hackers
VPNs have an agent-based architecture, meaning updates cannot be skipped. Numerous cyberattacks have taken place by exploiting outdated VPNs. Hackers include malicious software whenever they get the chance to modify an agent; once the agent is launched, the software is downloaded and the system is infected. It takes software vendors several months to fix vulnerabilities, and organisations additional time to deploy patches, leaving them vulnerable throughout that period.
VPNs open a port to communicate with the network
VPNs communicate at the network level, which makes them dangerous when used from an uncontrolled device — under a Bring Your Own Device policy, for example. They allow any infection to spread through the network into the information system. And since they consider the network as a whole rather than the applications and resources within it, they cannot have integrated single sign-on, degrading both security and user experience.
What are the benefits of ZTNA?
ZTNA is a security paradigm based on the least privilege principle, which consists of limiting a user’s access rights to the minimum required to perform their job. It emphasises the need to verify the right of every user, in their context, at the moment they want to access corporate resources.
Secure access from anywhere to any application or resource
Unlike VPNs, which assume trust based on location — inside or outside the network perimeter — ZTNA is designed to provide secure access to resources based on the identity of the user and the security posture of the device, regardless of where they are. Users can securely connect from anywhere and access their resources from the corporate network or from the internet.
Simplified access management and scalability
ZTNA is highly scalable. It provides a centralised approach to user identity and access control, simplifying access management and making it easy to accommodate a growing number of users and devices.
Advanced security unifying several functionalities
ZTNA includes several technologies such as Identity and Access Management (IAM), multi-factor authentication (MFA) and segmentation, to ensure that only authorised users with trusted devices and secure connections can access resources.
Furthermore, the ZTNA approach — which takes applications and resources into consideration — allows the integration of single sign-on, increasing productivity and enhancing user experience.
Advanced traceability
ZTNA goes beyond securing access by providing advanced traceability. Through secure logs that record all access attempts and contextual information, sessions can be analysed in real time, or used after an incident to investigate a security breach. ZTNA therefore gives a high degree of visibility over the organisation’s data and critical resources.
No port opening: a double barrier architecture
ZTNA grants no port opening, through a double barrier architecture. It relies on two components: a broker server, and one or more gateways — one on each LAN where the resources are located. The gateway connects out to the broker server, and belongs to a site which indicates the resources it can provide access to. A user authenticates on the broker server, which verifies their identity against the company’s directory and decides whether access can be granted. After identity validation, the user sees a list of applications they can request a connection to. When the user requests one, the broker server communicates with the gateway to create the connection towards that application. The session is therefore established with the application, not with the network.

ZTNA vs VPN: what is the difference between the two?
The ZTNA architecture is by default significantly more secure than the VPN’s. A VPN acts at the network level, whereas ZTNA acts at the level of users and their contexts — their identities — and at the level of applications and resources. ZTNA therefore provides a higher level of access granularity. VPNs can only identify who connected to the network and when; ZTNA traces who connected to which resources, in which context, and in which environment. ZTNA can also carry Privileged Access Management features, allowing advanced levels of access control and monitoring: it traces who connected to what, to do what.
ZTNA architecture provides a superior alternative to VPNs, offering more granular access control, better traceability, and increased flexibility to enhance business performance.
| VPN | ZTNA | |
|---|---|---|
| Perimeter | Organisation’s network | User’s context |
| Access level | Network | Application |
| End user terminal software | Mandatory client | Clientless possible |
| Access control granularity | Devices–network services | Identities–applications |
| Mobility and cloud | 1:1 connection | Anywhere/anything |
| Resource location | 1 site / VPN | Multi-sites, multi-VLANs |
| User experience | Poor | Best (1 portal, SSO, …) |
| Computing resources and scalability | Heavy and costly | Light, cost-effective |
| Security | Client software update, limited traceability | No software update if clientless, full traceability |
| Architecture | Single barrier, IT system exposure | Double barrier, IT system unexposed |
To sum up: even though VPNs have been widely used in the past to connect one site to another, they are no longer secure enough. With the rise of cloud services and remote access, ZTNA has proven the more efficient solution. The network is no longer the security perimeter — identity and access are. And since it can adapt to evolving security threats and technologies, ZTNA provides long-term value.
Do not let your organisation fall behind with an outdated VPN. It is time to go VPN-less with cyberelements.io, the ZTNA platform to secure access to all your resources. Schedule a demo and see why many organisations are making the switch to ZTNA.
Tags
- Articles
- ZTNA
- Defence & Critical Infrastructure
- Healthcare
- Industrial & Manufacturing
- MSPs
- Public Sector
- Financial Services
- Secure Remote Access
- Third-Party & Vendor Access
- Securing AI
- OT & Industrial Security
- Audit & Compliance
Check other relevant resources

Meurthe-et-Moselle Departmental Council
Delivering a seamless remote working experience for employees.

Hautes-Alpes Departmental Fire and Rescue Service
Securing and simplifying volunteer firefighters’ access to operational applications.

Bièvre Isère Regional Authority
Bièvre Isère authority chose cyberelements to streamline employee integration and enable staff to be fully operational on their first day.
View All
