Yesterday’s Tech Can’t Stop Today’s Threats
VPNs were designed for a different era. Trusted employees occasionally working from home, accessing applications that lived on company servers or in data centres.
Both those assumptions are dead.
Your users work from home offices, client sites, co-working spaces, and airport lounges. Your applications live in Microsoft 365, Xero, Salesforce, and a dozen other cloud platforms. The corporate perimeter VPNs were built to protect dissolved years ago. And yet, the VPNs remain.
What Attackers See
When attackers compromise VPN credentials through phishing, credential stuffing, or purchased credentials from a previous breach, they gain the same broad network access your legitimate users have.
They can move laterally across your environment. They can probe internal systems. They can escalate privileges. All because VPNs were never designed to assume a breach has occurred. The access model is binary: you’re either outside the wall or inside it. Once inside, everything is reachable.
This is exactly how mid-market attacks unfold [Read: How Attackers Breach Mid-Market Organisations ←]. Most mid-market organisations have endpoint protection (EDR) and increasingly identity monitoring (ITDR), but network-layer visibility, the third layer, is where the gap is the widest. VPNs make that gap worse because they provide connectivity without visibility. Traffic flows through, but nobody’s inspecting what that traffic is doing or where it’s going.
A Viable Alternative to the VPN Problem
You know VPNs are a problem. Your IT team knows it. The challenge isn’t awareness but access to an alternative. Rebuilding your entire network architecture feels operationally impossible. The budget isn’t there. The expertise isn’t there. The disruption risk feels too high. So, the VPN stays, and the organisation accepts risk because the alternative seems out of reach.
That’s the security paradox faced by every organisation without an enterprise budget: knowing what needs to change but lacking the resources to enact it.
The Alternative Model; Accessible, Affordable and Available.
The alternative model is Zero Trust Network Access. The core principle: never trust a connection based on where it comes from. Verify every user, every device, every session, every time.
When implemented correctly, three things change:
- Broad network access becomes application-specific access. Instead of connecting users to your entire network, you connect them to the specific applications they need. Nothing else is visible or reachable. A compromised account can’t pivot across your environment because there’s no network to pivot across.
- One-time authentication becomes continuous verification. Identity, device posture, and context are validated throughout the session, not just at login. Access adapts in real time based on risk signals.
- Implicit trust becomes zero implicit trust. No user, device, or connection is trusted by default. Every access request is evaluated independently, regardless of whether the user is in the office, at home, or on a client site.
This isn’t a rip-and-replace exercise. Cloud-native Zero Trust architectures deploy alongside existing infrastructure and can replace VPN connections progressively, application by application, user group by user group.
The Clearest Path Forward
The VPN problem is the most tangible expression of the security paradox. It’s the gap you can point to, the risk you can feel, and the constraint you live with daily.
It’s also the gap with the clearest path forward. Zero Trust Network Access is operational at mid-market scale, at mid-market economics, without requiring mid-market organisations to become security specialists.
The question isn’t whether VPNs need replacing. It’s whether the replacement comes with the operational capability to run it, or whether it’s another platform you’re expected to operate yourself [Read: The SaaS Security Trap ←].
Continue the full series on the Security Paradox here [Read: The Mid-Market Security Paradox ←].
→ Zero Trust Detection & Response (ZDR): Learn More
→ Assess Your Organisation: Request a Security Assessment
→ Close Your Security Gaps: Book a Security Consultation
→ Follow Virtual IT Group on LinkedIn for ongoing insights on security
The question was never whether you need enterprise-grade security. The question is who will actually run it for you.



