Editorial

The Great VPN Rethink

When organisations change how they grant access

Friday, August 07, 2026 | 5 MINS

For years, remote access was a relatively straightforward conversation. Users worked outside the office, they connected through a VPN, authenticated themselves and gained access to the corporate network. 

The model served organisations well because the network was where the applications, data and users were expected to be. but that assumption no longer reflects how most organisations operate.

Business applications increasingly reside in SaaS platforms, workloads are distributed across multiple cloud providers, and employees expect to move seamlessly between office, home and customer sites without thinking about how they are connected. The corporate network has become just one destination among many, rather than the centre of the enterprise. This has prompted many security leaders to rethink what remote access is actually trying to achieve.

What's the new requirement?

The objective is no longer to provide users with a secure route onto the network. It's to give the right person access to the right application, at the right time, from a trusted device and under the right conditions. That may sound like a subtle distinction, but it has significant implications for how organisations design their security architecture.

Traditional VPNs remain an important part of many environments. They continue to provide reliable connectivity for infrastructure administration, site-to-site networking, operational technology and legacy applications that were never designed for internet-facing access. For these use cases, they remain entirely appropriate.

What changed?

What has changed is the expectation that every remote user should first connect to a network before reaching the applications they need.

Modern access strategies are increasingly centred on identity, device posture and continuous verification rather than network location. Whether a user is working from home, an airport lounge or a corporate office is becoming less relevant than whether they can demonstrate an acceptable level of trust throughout the session. Access decisions are becoming dynamic, taking account of factors such as user behaviour, endpoint health, location, authentication strength and current threat intelligence.  his shift is also helping organisations reduce unnecessary exposure.

Longstanding criticism

One of the longstanding criticisms of traditional remote access has been the level of implicit trust granted once a connection is established. Even well-segmented environments can create opportunities for attackers who obtain valid credentials or compromise an authorised endpoint. Limiting access to specific applications, continuously validating trust and reducing unnecessary connectivity all help narrow the options available following an initial compromise, but the transition is rarely immediate.

Few organisations have the luxury of replacing established infrastructure overnight, particularly where business-critical legacy systems remain in operation. Most are gradually introducing Zero Trust Network Access, Secure Service Edge and broader identity-driven controls alongside existing remote access technologies, allowing architectures to evolve without disrupting day-to-day operations.

This means remote access is becoming less about selecting a particular technology and more about adopting a different operating model. The technologies involved will continue to evolve, but the underlying principle is becoming increasingly consistent: trust should be earned continuously rather than assumed at the point of connection.

For security teams, that represents one of the most significant architectural shifts of the past decade. The organisations making the greatest progress are not simply replacing VPNs with something newer. They are redesigning access around identity, context and risk, recognising that the network is no longer the natural boundary it once appeared to be.

Community Note

Remote access continues to evolve as organisations embrace Zero Trust, cloud-first architectures and identity-led security. If you have experience modernising remote access, implementing ZTNA or securing hybrid workforces, we'd like to hear your perspective.

Please contact our Community Editor, Sam Redwood, at sam.redwood@myredfort.com.


Section Heading

Also in this section