In the last 10 years, there have been huge changes in how businesses operate. Employees now work in offices, at home, in airports, at clients’ locations, and pretty much anywhere there is an online connection. Although employees have the flexibility of working remotely, this new business model has created new challenges regarding cyber-related threats.
For many years, Virtual Private Networks (VPNs) were regarded as the standard method for providing secure remote access to corporate networks, but with the emergence of new cyberthreats, the limitations of traditional VPNs have become apparent. Traditional VPNs provide excessive access to the corporate network; offer limited scalability; are difficult to manage; and have high susceptibility to cyber-related attacks.
What is a Traditional VPN?
The VPN Services provide an encrypted connection/”tunnel” between an employee’s computer/device and the agency’s internal network. Once a user is authenticated to the VPN, the user will typically have access to a lot of internal infrastructure.
The process of how a VPN operates is as follows:
1. A user launches the VPN client.
2. The user enters their username and password.
3. The VPN authenticates the user.
4. The VPN creates a secure/”encrypted” tunnel to the agency’s network.
5. The user has access to the agency’s network.
Although data is encrypted when traveling on the VPN, the users are assumed to not only be authenticated but also trustworthy.
This assumption creates many significant security vulnerabilities.
Limitations of Traditional VPNs
1. Widespread Access to Networks
The majority of modern VPNs allow network level access. Once a person logs into the VPN, he/she has access to multiple servers and applications (regardless of whether it is related to their job or not). This increases the amount of potential points of access for a cyberattack against your organization.
2. Trust by Default
Traditional VPNs trust a user once the user registers/logs in. Therefore, if the credentials of an attacker are compromised, that attacker will have as much network access as the legitimate employee whose credentials were compromised. Credential theft attacks that occur after a log-in are an especially dangerous threat due to this level of implicit trust provided by the traditional VPN system.
When one endpoint is compromised, an attacker can use that compromised endpoint to laterally move across the entire corporate network. This is one of the primary causes of ransomware outbreaks.
3. Poor Scalability
During the pandemic, organizations experienced VPN bottlenecks due to the fact that the many VPN concentrators used were never designed to handle thousands of employees logging into the same VPN multiple times within a day. As a result, overall performance suffered tremendously.
4. Complex Infrastructure
Deploying a VPN requires the creation and/or installation of the following items:
• VPN Gateways
• Hardware Appliances
• Client Software
• Firewall Rules
• Network Configuration
• Ongoing Maintenance
Managing the systems stated above adds to the already large workload placed on IT departments.
5. Poor User Experience
Employees experience many issues when using a VPN such as:
• Slow connections
• Failure to log-in
• VPN disconnecting
• Complicated client installation
• Compatibility Issues
When employees experience issues with their VPNs, they will frequently pursue unsafe alternatives to gain access to the resources needed for completing their job functions.
What is ZTNA?
Zero Trust Network Access (ZTNA) is a contemporary method of providing remote access by adhering to a Zero Trust approach.
Rather than giving an individual access to an entire network, ZTNA simply gives access to the software applications the user is permitted to access.
Access decision points are based on:
- Identity;
- Device status;
- Location;
- Risk rating;
- Type of authentication method;
- User behaviour; and
- Security policy.
ZTNA operates on the premise that no user or device can or should be trusted until proven.
Resources are continually verified every time a request is made for access.
How ZTNA Replaces Traditional VPNs
Identity Based Access Control
ZTNA uses identity-based authentication to verify users’ identities, rather than using the location of the network as a Trust Factor for authorizing or denying access.
Access control decisions are made based on:
– The Identity of the User
– The Identity of the Device
– The Organization Role of the User
– The Status of the Authentication
Application Based Access Control
Unlike VPNs, ZTNA does not expose the internal network to Authenticate access to an organization from the outside.
Users are connected directly to Approved Applications.
Examples of Users’ Access to Applications:
Marketing Team
– CRM
– Marketing Dashboard
Finance Team
– ERP
– Payroll
– Accounting
Engineering Team
– Git Repository
– Development Servers
– CI/CD Tools
All Employees can only access Resources Based on their Organization role.
Continuous Authentication
VPN authentication only takes place at the time of authentication, whereas ZTNA has an ongoing check of:
– Device Health
– IP Reputation
– User Behavior
– Logon Location
– Risk of the Session
If suspicious activity is detected the user’s access will be revoked or restricted automatically.
Advantages of adopting a ZTNA solution include:
– Reduced attack surface
– Improved protection against ransomware
– Protection against credential theft
– Support for secure remote work
– Continuous monitoring
– Reduced insider threats
– Strong identity verification
– Better security in the cloud
– Improved compliance
– Faster detection of threats
Benefits to implementing a ZTNA solution that go beyond cyber security:
Reduced infrastructure costs as organizations can eliminate costly VPN hardware.
– Simplified management of ZTNA solutions deployed in the cloud, resulting in reduced maintenance and simplified policy administration.
– Increased employee productivity, as users have faster, more reliable access to specific applications without having to use complex VPN clients.
– Enhanced scalability to easily support the growing number of remote employees, contractors and third-party vendors who require access to corporate resources.
– Increased compliance to help organizations manage and maintain compliance obligations through the enforcement of least privilege access; maintenance of accurate and complete audit logs; and consistent application of access policy.
Future of Secure Remote Access
Organizations need security models that constantly verify every user and device as cyber threats grow increasingly advanced and hybrid work becomes a way of life.
More organizations are retiring VPNs in favor of Zero Trust network access (ZTNA) because it better fits today’s modern, cloud-based working environment; supports employees who work from home; has less of an attack surface; and gives them granular access control based on user identity rather than trusting the network infrastructure as the source of trust in application security. Businesses can protect specific applications and create a better end-user experience.
A company looking to develop a long-term cybersecurity strategy should view adoption of ZTNA not as an upgrade, but rather as a core component to establishing an overall Zero Trust approach to security.
Conclusion
Organizations need security models that constantly verify every user and device as cyber threats grow increasingly advanced and hybrid work becomes a way of life.
More organizations are retiring VPNs in favor of Zero Trust network access (ZTNA) because it better fits today’s modern, cloud-based working environment; supports employees who work from home; has less of an attack surface; and gives them granular access control based on user identity rather than trusting the network infrastructure as the source of trust in application security. Businesses can protect specific applications and create a better end-user experience.
A company looking to develop a long-term cybersecurity strategy should view adoption of ZTNA not as an upgrade, but rather as a core component to establishing an overall Zero Trust approach to security.
FAQ
1. What’s the primary distinction between ZTNA and a standard VPN service?
After verifying a person’s identity on a Virtual Private Network (VPN), they can then be connected to a private network. Whereas Zero Trust Network Access (ZTNA) provides an individual only with access to applications based on their identity or job function, their device’s security settings and their continued verification automatic on a per-use basis.
2. Is ZTNA safer to use than VPN Service?
ZTNA enhanced security by enforcing limit based access, continuously verifying user/device identity, as well as preventing unauthorized lateral movement through your network by establishing a “least privilege” security model.
3. Will ZTNA replace a VPN client?
Although very few current ZTNA solutions require use of either the traditional VPN Client or any other downloadable software/installation. The majority of current ZTNA implementations can connect to a browser based system, or utilize lightweight connectors that do not necessitate use of traditional VPN Client software.
4. Does using ZTNA limit your ability to support hybrid and/or remote work models?
No, as ZTNA was initially created to secure the Cloud and hybrid workplaces especially when employees are working remotely from the corporate location.
5. Will ZTNA eventually replace all VPN based services?
Many Organizations are currently adopting ZTNA as their primary source for accessing remote resources while their legacy applications continue to operate under their existing VPN. As their legacy business applications create compatibility issues, these organizations will transition completely over to “Zero Trust”.