The Honest State of the VPN in 2026

The VPN in 2026 has become the security control the enterprise has been questioning, the control the Zero Trust pitch has been promising to replace, the control the recent breach has been quietly exposing as the control that the breach…

A single brass old key on a dark wood surface, dim warm amber side light, deep navy shadows, no people visible.

Picture the enterprise VPN in 2018. The user clicks the client, the tunnel opens, the corporate subnet is reachable from a hotel WiFi somewhere. It worked. IT did not have to think about it, and the security side did not have to talk to anyone. Then the breaches kept happening, the help desk kept forwarding the same packet captures, and the new model pitch kept landing better with the board. The VPN is still running in most estates. The honest question is whether it should be.

It still does three things well. It also does three things badly. The alternative now does all six. Here is the short version for the network and security sides that have the migration in their queue.

What the VPN still does well

Encryption stands as the obvious one. The VPN provides end to end encryption between the remote user and the corporate network, and any replacement has to provide the same thing by default. Legacy access is what most plans underestimate. The VPN grants direct access to the corporate subnet, which is exactly what the legacy application has been depending on for a decade, and the alternative has to grant the same access through an application proxy. User familiarity is what the migration plan usually forgets. Most employees have been clicking the same client for years, and IT has been deploying it without a training session. The new model has to match that baseline before the rollout goes anywhere.

What it does poorly

Lateral movement is the worst of the three. Whoever has the credential gets the same network access the legitimate user has, and the file share, the database, and the production system are all reachable from the same foothold. The VPN grants the network access, and the credential thief uses it. The always on exposure sits next. The client stays in the connected state whenever the laptop is open, which turns the personal device the employee uses for the personal browsing into a persistent on ramp to the corporate network. The detection gap is the part the SIEM cannot see. VPN traffic looks like the legitimate user, and that signal is exactly what the credential thief has been exploiting.

What the replacement looks like

Three pieces, and the difference between the old and the new model comes down to blast radius. The proxy layer. ZTNA connects the employee to a specific app, not to the network that app sits on. A stolen credential reaches the one resource it was scoped for, not the whole subnet. The device posture. The new model checks the endpoint before granting access, and unmanaged devices get blocked at the door. Continuous verification. Posture is rechecked throughout the session, which catches the compromise the old model could not.

Abstract VPN as glowing cyan aged tunnel on a dark navy surface, dramatic chiaroscuro lighting from above.
VPN in 2026: the encryption still works, the network access model does not, the replacement scopes access to the application.

The bottom line

Application proxy, device posture, continuous verification. The migration holds the remote access. The team defending the VPN for the modern workforce does not.



Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading