Many enterprises today rely on traditional virtual private networks (VPNs) for remote access, but the legacy technology is ill-suited for an environment where so many applications have migrated to the cloud, Dell’Oro Research Director Mauricio Sanchez said during a webinar this week.

Traditional remote-access architectures have relied on what Sanchez calls a “classic perimeter style of approach,” where all or most data and users lived inside a private corporate network, and Internet Protocol Security (IPSec) VPN or VPN technologies allowed access to the network while a security stack prevented access from the outside.

But Sanchez said that from a security perspective, the perimeter approach has never been perfect, and only worked with fewer remote users, when applications and data were largely centralized, and Application bandwidth requirements and the volume of internet-traffic were low.

Since the pandemic began, he added “the increase in attacks really went off the charts” because older edge devices, VPN concentrators, or firewalls couldn’t keep up with web-enabled applications and increased traffic in and out of the network.

“The question then arises, is it possible to have better days ahead?” Sanchez continued. “And I'm here to say that yes, there is an opportunity for that class of Enterprise that is on that journey to become cloud-first, mobile-friendly — to be able to have their applications accessible over the Internet.”

Cloud-Delivered ZTNA

Like many in the space, Sanchez sees cloud-delivered zero-trust network access (ZTNA) as a better alternative to VPNs in many cases of remote network access. Sanchez clarified ZTNA isn’t a product as much as its “a security philosophy and framework for how to approach the IT architecture.”

He noted ZTNA looks at the security question from three different perspectives: never trust, always verify; enforce least privilege access; and an “assume breach mindset,” driving a need for continuous monitoring.

ZTNA applies to any domain, including users, devices, applications, data, and network traffic. In the case of network traffic, he said cloud-delivered ZTNA acknowledges that in today’s hybrid world “the Internet is the corporate Local Area Network.”

Sanchez said that unlike VPNs, ZTNA eliminates central outbound chokepoints and traffic backhauling. ZTNA Proxy clouds also cloak applications and all remote access is shifted off the hardware edge to a cloud services.

He added this leads to better Application experience, improved security, lower network cost, and less pressure on IT teams who are able to “reinvigorate and update the network on the fly.”

VPNs won’t completely be replaced, with Sanchez expecting “they will still be around the fringes,” because there are still use cases in which the technology makes sense over ZTNA.

The areas that need to be contemplated, or what Sanchez said are the “tradeoffs” to ZTNA, include a greater Application management burden, different cost structures, a need for higher intra-IT team collaboration, and the simple fact that moving to cloud-based architectures can be a large and daunting change for many enterprises.

But in many cases, he added, the net benefits of adopting ZTNA should “outweigh the drawbacks.”

ZTNA: Part of the security services edge (SSE)/SASE Puzzle

Sanchez pointed out that ZTNA is just a piece of the puzzle that is the SSE, a cloud-delivered security suite that also includes cloud-access security broker (Cloud Access Security Broker), secure web gateway (SWG), and firewall-as-a-service (FaaS).

Dell'Oro predicts SSE market revenue to experience a compounded annual growth rate (Compound Annual Growth Rate) of nearly 30% from 2021 to 2026, with ZTNA and FaaS estimated to “flourish at a faster rate.”

And SSE is just the security piece of the even larger puzzle that is secure access service (SASE), Gartner’s term for the convergence of SD-WAN and security as a cloud-delivered service.

Enterprise Strategy Group (ESG) found ZTNA is at the top of the list and was selected by 58% of a survey's respondents as the most common starting point among organizations that have already begun implementing a SASE project.

Sanchez suggests enterprises consider ZTNA as “part of a larger whole,” adding, “the takeaway here is think about the puzzle pieces. Think about whether SSE is the path forward in this journey of VPN replacement.”

By 2025, Gartner predicts 80% of enterprises will have adopted a strategy to unify web, cloud services and private Application access using a SASE/SSE architecture.