KuppingerCole analysts expect the zero-trust network access (ZTNA) market will increase at a 17.4% compound annual growth rate through 2025, hitting $7.34 billion in sales, a prediction that runs parallel with messaging from vendors who have ZTNA at the center of their plans.

“The concept of zero trust is based on the assumption that any network is always hostile, and thus, any IT system, application, or user is constantly exposed to potential external and internal threats,” the firm said in a report. “This concept has gained popularity as a modern alternative to traditional perimeter-based security.”

KuppingerCole noted that a fundamental difference compared with legacy solutions – such as VPN – is that ZTNA separates control and data planes, which can be set up in different locations, but still enables a single point of management and visibility across complex deployments. This is a preferred architecture as the work-from-anywhere model continues to be the norm across verticals.

“ZTNA solutions with their [software-as-a-service]-based management tools provide significant advantages over traditional on-premises VPN solutions. These solutions are modern, more flexible, and scalable alternatives to aging VPN infrastructures,” the firm said.

SASE and ZTNA Are ‘Tied at the Hip’

With ZTNA being a requisite for Gartner’s secure access service edge (SASE) framework, the zero-trust architecture has become a focal point for vendors in the SASE space, who touted the architecture as essential to network security coming into this year.

A major trend in the 2022 SASE market was that "many [chief information security officers] and security architects finally started making concerted efforts to revise their security models to embrace zero trust,” Netskope’s VP Naveen Palavalli told SDxCentral.

Palavalli said he expects that in 2023, organizations will look to apply some of the evolutionary principles introduced by ZTNA, calling it “a fundamental part of SASE,” and apply them to the LAN.

Forcepoint VP Jim Fulton said zero trust has gone from “an academic theory to a best practice to simply how modern security is done,” adding that “zero trust and SASE are now tied at the hip.”

SASE has become the vehicle for delivering zero trust-based access to business resources, he said in an interview. ZTNA is a key element of a modern strategy as replacing VPNs with cloud-delivered ZTNA has become one of the “killer apps” of SASE.

“Today, the zero-trust credo of ‘trust nothing, verify everything’ is king,” Fulton explained. “No intellectual property or regulated data should be shared or downloaded against policy. Access to inappropriate websites should be controlled. Access to cloud apps from [bring-your-own-device] or unmanaged devices must be controlled as well. All content must be sanitized from threats automatically.”

SASE Vendors Knock Current ZTNA Approaches

SASE vendors like Palo Alto Networks and Fortinet have even criticized current approaches to ZTNA.

Palo Alto Networks said traditional ZTNA products “have proven more dangerous than helpful” in today’s hybrid work and cloud migration world, and has advocated for stricter requirements that would bring in what the vendor calls a “next-generation” of products it has dubbed ZTNA 2.0.

First-generation ZTNA products have “critical limitations” including providing too much access, “allow and ignore,” and little to no visibility or control over data, Palo Alto Networks founder and CTO Nir Zuk wrote in a blog post.

Fortinet VP Nirav Shah similarly told SDxCentral that most companies that deployed ZTNA during the pandemic have “likely come to the realization that remote ZTNA policies don’t fully meet their security expectations or standards because it’s cumbersome having one set of policies for on-premises and an entirely different set of policies for the cloud.”

Shah added that zero-trust initiatives that comprise disparate products have an “incredibly low rate of success” and the lack of consistency from a management and enforcement perspective has slowed the adoption of zero trust in the industry.

“Organizations must choose solutions that are integrated and consistent across on-premises and cloud if their zero-trust strategy is to succeed. This is why vendor consolidation is key to enabling zero trust,” he said.