The corporate VPN was built for a world that no longer exists. It assumed a single company network, a perimeter worth defending, and a workforce that logged in from a fixed office. Today staff connect from airports and home offices, applications run across multiple data centres, and outside contractors need narrow access to single systems rather than an entire network segment. The gateway that once protected this arrangement has become one of the most attractive targets on the internet.
That shift in risk is not theoretical. Remote-access gateways from major vendors have repeatedly appeared on the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue, and in two notable cases CISA issued emergency directives ordering federal agencies to act immediately: one in January 2024 concerning Ivanti, another in September 2025 concerning Cisco. The pattern is consistent rather than vendor-specific. Any device sitting at the internet edge, accepting connections before authentication and parsing complex protocols, becomes a high-value target regardless of who built it. Organisations reassessing their exposure are increasingly comparing architectures and providers, and some are even checking current promotional pricing as part of a broader cost-benefit review before committing to a migration.
Why "Zero Trust" Changes the Question
The US National Institute of Standards and Technology captured the underlying principle succinctly in SP 800-207: no implicit trust should be granted based solely on physical or network location. Being inside the corporate network no longer means a device or user is automatically trustworthy. CISA's Zero Trust Maturity Model organises this into five pillars - identity, devices, networks, applications and workloads, and data - while Germany's Federal Office for Information Security has stated that zero-trust approaches secure application access more effectively on a preventive basis and limit the damage when an attack succeeds.
In practical terms, this produces four requirements for any remote-access replacement: identity verification through a central service with multi-factor authentication; access policies defined per application or system rather than per network segment; device posture checks before a connection is granted; and a complete, traceable log of who accessed what and when. None of this demands abandoning VPN technology outright. A mesh VPN, for instance, can satisfy zero-trust principles if policies are enforced per identity and per destination rather than by simply admitting a device to a shared network.
Self-Hosted, Cloud, or a Mix
The central architectural choice is where the control plane and connection data actually live. Cloud-based Zero Trust Network Access keeps both with the vendor. Self-hosted solutions keep them on infrastructure the organisation controls, or with an operator of its choosing. Neither option is inherently more secure; what matters is whether updates, monitoring and incident response are properly resourced, whether that responsibility sits in-house or with a service provider. A cloud control plane does not necessarily mean losing control of data, since payload traffic can still be encrypted end-to-end independently of who manages the management layer.
Licensing models vary considerably. Some self-hosted platforms allow unlimited users and devices in their community editions, charging only for enterprise features such as high availability or provisioning. Per-user commercial pricing, by contrast, scales with every employee and external contractor added, which changes the economics significantly as an organisation grows. In practice, many organisations settle on a hybrid: a mesh VPN for staff, administrators and service providers, paired with direct tunnels between data centres and selectively published web applications that never require a VPN client at all.
Migration Without Disruption
The hardest part of replacing a VPN is rarely the new product. It is discovering every access path that nobody wrote down - forgotten service accounts, legacy integrations, a contractor's standing access from years earlier. A careful inventory of what the current VPN actually permits has to come before any technology decision. Migration then proceeds group by group, in parallel with the existing system, with the old gateway decommissioned only once every group has moved successfully.
There is a regulatory dimension too. The EU's NIS2 directive requires organisations to demonstrate that access to critical systems is restricted to authorised people and devices, and that this access is logged. A properly implemented zero-trust or mesh-VPN architecture produces that evidence as a natural byproduct of normal operation, rather than as a separate compliance exercise bolted on afterward.