Organizations should think about making the shift away from VPNs if they hope to increase resiliency, agility, and flexibility, Enterprise Strategy Group (ESG) Senior Analyst John Grady said at Palo Alto Networks’ SASE Converge event.
VPNs present challenges in the current hybrid work and cyberthreat landscape, Grady added. ESG research found that about 35% of devices used for accessing applications are "bring-your-own-device" (BYOD), and about 35% of users accessing internal resources are third-party sources, further complicating the equation.
VPNs have typically been the way organizations have supported remote access, he noted. “In that model with fewer users and centralized resources it worked to a certain extent, but there are some significant issues with this approach," Grady said.
VPN PitfallsThe “most glaring” issue is the level of security VPNs provide. Grady pointed out that because VPNs are visible on the internet, they're highly accessible to attackers. Coupled with the fact that vulnerabilities are regularly disclosed by VPN providers, it means that attackers don't have to work “particularly hard” to find an entry point onto the network.
VPNs deployed as hardware appliances, which requires capacity planning and puts a ceiling on the number of users who can connect through the network gateway, also limits scalability.
The user experience can also be diminished with VPNs, as “just the act of having to connect to the VPN can be intrusive,” Grady said. He noted VPNs often require agents, which makes providing access in scenarios with a high volume of third-party users difficult. Additionally, traffic is backhauled to a centralized location where it can be an impact on performance, which is especially true when accessing cloud-based applications.
“Some SaaS applications actually recommend that you not connect via VPN for this reason,” he added.
On the IT side, VPNs typically operate in a silo. That said, Grady indicated the industry trend toward convergence and consolidation for stronger security and easier management cannot be easily facilitated by VPNs.
“There's not typically any inherent threat prevention or other security capabilities that come with VPN, so that makes it hard to achieve any of those objectives,” he said. “Cost comes into play as well, both from a solution perspective in terms of capital expenditures related to VPN appliance purchases, and the backhauling model itself.”
Still, ESG research shows only 7% of organizations say they've made significant progress on the path to VPN replacement, while 13% are actively expanding zero-trust network access (ZTNA) usage to replace VPN.
“The reality is that it's a really big project and typically isn't done all at once. It's really more about VPN augmentation to start, with an eye toward replacement down the road,” Grady said, adding “even that may not be realistic for a lot of organizations.”
Why ZTNA?Grady said a major appeal of ZTNA is that the technology is usually cloud-delivered. This means traffic destined for cloud applications doesn't have to be backhauled to the corporate data center, but instead is routed through the most efficient path.
ZTNA also supports a much stronger security model than VPNs by hiding applications from public view, meaning only those with specific permissions have the ability to access them. This least-privilege approach is coupled with contextual access, which includes checking the health of devices being used and assessing where and when requests are made.
ZTNA tools often provide both agent and agentless deployment models, which support some of the third-party access use cases VPNs have “struggled to address,” Grady said. These include providing access for partners and contractors, supporting merger and acquisition activity, and making BYOD scenarios “a bit easier for the security team to manage, at least from an access perspective.”
ZTNA to Realize SASEGrady explained that while the trending secure access service edge (SASE) and zero-trust frameworks are separate, they are complementary and increasingly interconnected.
“You need to understand and plan for how ZTNA can support broader initiatives, and specifically I mean SASE and zero trust,” he said.
ESG found that 61% of organizations with a broad zero-trust initiative underway had begun to implement SASE. “That essentially means that as you start to do one, you're much more likely to do the other,” Grady noted. “Which means you have a lot to think about and coordinate across different projects and a lot of stakeholders and personas to work with across the organization.”
The group also found ZTNA is at the top of the list and was selected by 58% of respondents as the most common starting point among organizations that have already begun implementing a SASE project.
Grady said most ZTNA projects should be fairly focused to start, but still done with both short- and long-term perspectives in mind. While organizations might pursue SASE for a specific purpose, like securing cloud-based applications, if they focus only on tools specialized for one use they may have difficulty broadening things out to other use cases down the line.
Ultimately, both SASE and ZTNA adoption are processes that require thoughtful planning and oversight.
“SASE can be oversold at times relative to how quickly organizations – especially at the enterprise level – are going to be able to roll things out because it's a big initiative in totality,” Grady said, adding that starting a SASE journey with the right ZTNA tools is something “just about every organization should be thinking about.”
Comments