Skip to Content

Why is the VPN becoming extinct in companies?

December 11, 2019 by
Why is the VPN becoming extinct in companies?
Kleber Leal by Zamak Portal
The venerable VPN, which has provided remote workers with a secure means to the corporate network for decades, is becoming extinct. This shift is happening as companies migrate to a more agile and granular security framework called Zero Trust, which is better suited to today's digital business world. VPNs are part of a security strategy based on the notion of network perimeter: trusted employees are inside and untrusted employees are outside. But this model no longer works in a modern business environment, where employees access the network from various locations and where corporate assets are no longer behind the walls of a data center, but in multi-cloud environments. Gartner predicts that by 2023, 60% of companies will eliminate most of their VPNs in favor of Zero Trust network access, which can take the form of a gateway or broker that authenticates the device and the user. There are a variety of flaws associated with the perimeter security approach. It does not address insider attacks, and it does not do a good job accounting for contractors, third parties, and supply chain partners. If an attacker steals someone's VPN credentials, they can access the network and move freely. At an even more fundamental level, today, anyone observing corporate security understands that what we are doing is no longer working.

Trust no one

With the Zero Trust policy, the idea is simple: trust no one. Verify everyone. Enforce strict identity control and management policies that restrict employees' access to the resources necessary to perform their jobs and nothing more. Zero trust is not a product or a technology; it is a different way of thinking about security.

Security vendors adopt Zero Trust

Although the zero trust framework has existed for a decade and generated considerable interest, only in the last year or so has the adoption of the solution begun to take off. According to a recent survey by the 451 Group, only about 13% of companies have started using zero trust. One of the main reasons is that vendors have been slow to advance. Despite the delay, the approach is gaining traction. Source: ComputerWorld

Frequently asked questions

What is the Zero Trust model, and why is it replacing VPNs in companies?

Zero Trust is a security framework built on the principle of "trust no one, verify everyone," enforcing strict identity control and management policies that limit each employee's access to only the resources needed for their job. Unlike VPNs, which rely on a network perimeter logic where inside is trusted and outside is not, Zero Trust fits a modern digital business environment where employees access the network from multiple locations and corporate assets sit in multi-cloud environments rather than behind a data center's walls.

What are the main flaws of perimeter-based security (VPN) driving companies toward Zero Trust?

The perimeter model doesn't address insider attacks and does a poor job accounting for contractors, third parties, and supply chain partners who also need network access. On top of that, if an attacker steals a user's VPN credentials, they can access the corporate network and move freely inside it, since trust is granted to anyone considered to be "inside" the perimeter.

How fast is Zero Trust adoption moving among companies?

According to Gartner, by 2023, 60% of companies are expected to eliminate most of their VPNs in favor of Zero Trust network access, typically in the form of a gateway or broker that authenticates the device and the user. A 451 Group survey, however, found adoption was still early, with only about 13% of companies having started using Zero Trust at that point, a lag partly attributed to security vendors being slow to advance their solutions.

Why is the VPN becoming extinct in companies?
Kleber Leal by Zamak Portal December 11, 2019
Share this post
Tags
Archive