The legacy tunnel was designed in 1996, and the network perimeter the VPN was designed to protect has not existed in most enterprises since 2010. The remote work landscape is not 1996. The user is working from a coffee shop on a public network, accessing applications that are not in a corporate data centre but in a SaaS provider’s infrastructure. The VPN was designed to solve a problem that no longer matches the problem the enterprise is trying to solve, and the enterprise is moving to four other approaches that match the problem better.
This piece is for the security teams that are looking at their VPN renewal and asking whether to renew, and for the engineering teams that are being asked to support the migration to whatever comes next. The answer, as is usually the case, is “it depends” with a long footnote.
1. Zero trust network access (ZTNA)
ZTNA runs as the direct replacement for the VPN, and the direct replacement is what most enterprises are converging on. The premise is that the user authenticates to an identity aware proxy, the proxy checks the device posture, the proxy grants access to the specific application the user is allowed to reach, and the proxy does not grant access to the rest of the corporate network.
ZTNA fixes the two things the VPN got wrong. The first is over granting: the VPN grants access to the whole network, the ZTNA grants access to the specific application. The second is implicit trust: the tunnel trusts the user once they have authenticated, the ZTNA re authenticates on every request. The result is a posture that is closer to the way the modern enterprise actually works, and a posture that the compliance team can defend in the audit.
Cloudflare Access, Zscaler ZPA, Palo Alto Prisma Access, Tailscale, and the open source equivalents are the vendors to evaluate. The buying decision is more about the integration with the rest of the stack than about the technology. The technology is mature across the field.
2. Browser based isolation (RBI)
Remote browser isolation runs the user’s browsing session in a remote container, streams the pixels back to the user, and prevents any code from the remote site from running on the user’s device. The use case becomes the user who needs to access a legacy application that the enterprise cannot expose to the internet, or the user who needs to access untrusted content, or the user who needs to be protected from malicious content.
Menlo Security, Authentic8, and the island enterprise browsers are the vendors to evaluate. RBI sits as the right answer for a specific set of use cases, and RBI sits as the wrong answer as a general purpose replacement for the VPN. The general purpose replacement is ZTNA.
3. Software defined perimeter (SDP)
SDP sits as the closest cousin of ZTNA, and the difference is mostly about the deployment model. SDP is typically deployed as a controller and a set of clients, with the controller dynamically granting access to specific resources based on the user’s identity and the device’s posture. Zscaler, Cisco, and the open source equivalents (WireGuard based meshes) are the vendors to evaluate.
SDP is a strong choice for the enterprises that have the in house networking expertise to manage the controller, and a less strong choice for the enterprises that would rather buy the management as a service.
4. The hybrid approach
Most enterprises are not picking one approach. They are picking a hybrid, and the hybrid usually looks like ZTNA for the new applications, RBI for the legacy applications that cannot be exposed, and the tunnel for the long tail of resources that nobody has gotten around to migrating. The hybrid stands as the right answer for the next three years, and the right answer for the year after that runs as the long tail finally being migrated off the VPN.
What to do about it
If you are evaluating a VPN renewal, the right move is to start a parallel ZTNA deployment for the highest value applications, and to migrate the user base over the course of the renewal period. The migration is not free (the licensing is different, the support model is different, the integration with the rest of the stack takes work), and the migration pays off in the year the renewal comes up.
If you are running a ZTNA already, the right move is to retire the tunnel for the applications that have been migrated, and to keep the tunnel for the long tail. The hybrid stands as the answer, and the hybrid is not a permanent answer. The hybrid runs as the bridge to the post tunnel world.
If you are still buying a new tunnel, the right move is to think hard about whether you actually want to be in the tunnel business for the next three years, or whether you want to be in the ZTNA business. The cost difference is smaller than the marketing decks suggest, and the operational difference is large.
The bottom line
The patterns the post covers have been showing up in production for long enough that the patterns have names, the failures, the mitigations, the gaps. The work the security team and the engineering team and the operations team are quietly doing today sits as the work that decides whether the practice the post names sits as a tool the team uses or a liability the team is paying for.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.


