
TL;DR
VPN still works well as a way to provide encrypted access to a corporate network, but it does not solve every challenge related to secure access. Depending on an organization’s needs, technologies such as ZTNA, Application Proxy, SASE, Bastion Host, VDI/DaaS or browser-based security solutions may be a better fit. The key question, therefore, is not “what should replace VPN?”, but rather what access and security problem the organization is trying to solve.
For years, VPN has been one of the basic tools used to provide employees with remote access to corporate resources outside the office. Its purpose is relatively simple: it creates an encrypted connection between the user and the organization’s infrastructure, allowing employees to access systems over the Internet that are not publicly available – such as file servers, business applications or other resources within the corporate network. VPN can also connect entire locations, for example the networks of two company branches.
In an environment where most applications were hosted within the organization’s own infrastructure and the main objective was to provide employees with remote access to the corporate network, this model met business needs well. In many organizations, it is still sufficient today.
Problems arise when we expect VPN to provide more than a secure connection. An encrypted tunnel alone does not answer questions such as which resources a user should be allowed to access, whether their device is secure, what happens if their account is compromised, or how data should be protected and threats detected. Before choosing a solution, it is therefore worth determining what problem the organization actually needs to solve and whether VPN is truly the best tool for the job.
Imagine a sales employee working from home who needs access to the company CRM. From a business perspective, their requirement is very specific: they should be able to open one application, sign in and perform their work.
In a traditional VPN model, however, access is often granted at the network level, which means the user may also gain access to other resources located within the same network segment.
This is not an unavoidable characteristic of VPN – access can be restricted through network segmentation and appropriate security policies. However, overly broad access can significantly increase the impact of a security incident. If an attacker compromises an employee’s account or computer, they may gain the same level of access as the legitimate user. The broader that access is, the greater the opportunity to explore additional systems and move laterally through the organization’s environment.
Instead of asking only how to securely connect a user to the corporate network, it is therefore worth first determining which specific resource they should be able to access and whether they actually need access to the network itself.
The second limitation stems from the very purpose of VPN. Its primary function is to create a protected connection between the user and the organization. This is an important element of security, but it should not be confused with comprehensive protection of the user, their device, applications and data.
A VPN connection alone does not protect against the consequences of phishing, malicious attachments or working from a compromised or infected device. Nor does it independently address the need to control the flow of confidential information, assess device security posture or detect malicious traffic, although VPN may of course be part of a broader solution that includes such capabilities.
In practice, it is therefore worth distinguishing a secure connection from secure access. The former primarily concerns how communication between the user and the organization is protected. The latter should also take into account who is trying to gain access, which device they are using, which resources they are authorized to access, whether they meet security requirements and what happens during their session.
As the number of users grows, the traditional VPN model may require increasingly extensive infrastructure. If remote employee traffic is routed through a central point within the organization, devices and network links must be sized appropriately for the scale of that traffic; otherwise, bottlenecks, performance degradation and access quality issues may occur. The rapid shift to remote work during the COVID-19 pandemic illustrated the scale of this challenge particularly well.
There is no single number of users beyond which VPN suddenly becomes inefficient – this depends on the hardware, architecture, configuration and type of traffic involved. From a business perspective, however, what matters is that as the organization grows, so can the costs of infrastructure, bandwidth, administration and ensuring high availability.
If access for a large group of users also depends on central infrastructure components, their failure may disrupt work across the organization. This risk can be reduced through redundancy, but doing so requires additional components and careful environment design.
The limitations of traditional VPN are becoming more visible not because the technology itself has become worse, but because the IT environment has changed. Applications today may reside in corporate infrastructure, in the cloud or be delivered as SaaS services, while employees, partners and suppliers access them from many different locations. In this environment, user identity, device posture, the type of resource being accessed and the context of the access request are becoming increasingly important.
There is no single technology that can serve as a universal “successor to VPN”. The right choice should depend on the specific problem the organization needs to solve. In one scenario, ZTNA may be the best answer; in another, Application Proxy, SASE or access through a bastion host may be more appropriate; and in yet another, the best approach may be to retain VPN while complementing it with additional security mechanisms.
ZTNA, or Zero Trust Network Access, changes the way access decisions are made. Instead of giving users broader access to a specific part of the network, an organization can grant access only to the particular applications and resources they need.
The access decision can take into account not only the user’s identity, but also the authentication method, device posture and other contextual factors. This makes access more precise and better aligned with the principle of least privilege: an employee, consultant or partner receives access only to the resources they genuinely need to perform their task.
ZTNA is therefore not simply a “more modern VPN”. VPN focuses on securely connecting a user to a network, whereas ZTNA focuses on whether a specific user should be allowed to access a specific resource under specific conditions.
If an organization wants to give external users access to one or several specific applications, Application Proxy may be an appropriate solution. It acts as an intermediary layer between the user and the system: the user does not connect directly to the application and does not need broader access to the network, but communicates with it through the proxy.
This means that the internal application does not need to be exposed directly to the Internet, while the organization can make only the required system available to the user. Depending on the solution, access may also be integrated with authentication mechanisms and security policies.
This approach is particularly useful for web applications used by employees, partners or contractors. However, Application Proxy does not provide as broad an access decision framework as ZTNA – its primary purpose is to securely publish an application and mediate communication with it.
If an organization wants not only to control access to applications, but also to assess devices, secure Internet traffic, protect data and enforce consistent security policies regardless of the user’s location, SASE (Secure Access Service Edge) may be an appropriate answer.
SASE combines networking and security functions within a cloud-delivered architecture. Depending on the solution, it may include ZTNA, traffic control and filtering, data protection and threat prevention. Before granting access, it may also take into account the user’s identity, authentication method and device posture.
From a business perspective, the most important change lies in how security is organized: it is no longer tied exclusively to the corporate headquarters and the devices located there, but can be applied regardless of where the user and application are located. SASE is therefore particularly relevant in environments where users and resources are distributed and the organization wants to simplify the management of multiple separate networking and security mechanisms.
If an external administrator or service provider needs access only to a specific system, the organization can use a Bastion Host or Jump Host, which serves as a controlled intermediary point. The user does not connect directly to the target resource and is not granted broader network access. Instead, they first connect to the bastion host and only then proceed to the required system.
This approach allows the organization to control the access path and scope more precisely, while the bastion host itself can provide a verified set of tools required to perform a particular task. Unlike traditional VPN, the emphasis is therefore not on granting access to the network, but on creating a controlled path to a specific resource.
Sometimes the problem is not how the user connects to an application, but the device on which the work is performed. This applies, for example, to environments where systems are used by contractors, temporary workers or people working from personal computers.
VDI and Desktop as a Service allow the working environment to be moved to infrastructure operated by the organization or a service provider. The user then works through a remote desktop instead of performing all work directly on the local computer.
This allows the user to work with corporate applications and data without moving the entire working environment onto their own device. VDI or DaaS is therefore useful where the organization wants not only to provide access, but also to reduce its dependency on the device the user is working from.
If a significant part of work is carried out through web applications, the browser itself can become an important element of user and data protection. Enterprise Browser allows an organization to centrally manage how web applications are used and enforce specific rules, for example around file downloads or access to selected services.
Browser Isolation runs web content in an isolated environment, reducing the risk that potentially malicious code will reach the employee’s device directly.
These solutions do not need to replace VPN across the entire organization. They are particularly useful where the browser is the main point of access to applications and data, and where the organization wants to better control how it is used or reduce the risks associated with malicious web content.
Not necessarily. VPN still works well where an organization requires remote network access, relies primarily on resources hosted within its own infrastructure or needs to connect branches and other environments.
Much depends on how the organization works and where its resources are located. An organization operating mainly on-premises may require different mechanisms from a company migrating to the cloud, while a cloud-first environment may need something different again. In practice, a hybrid model often works best, with VPN continuing to support some scenarios while more specialized technologies address others.
Instead of asking only “what should replace VPN?”, it is worth first determining what problem needs to be solved. Does the user need access to the network or only to a specific application? Do contractors use company resources? Where are applications and data located? Does the organization need to assess device posture, control information flows or analyze user traffic?
The answers to these questions help determine whether the organization needs VPN, an expanded VPN environment, or technologies such as ZTNA, SASE, application-level access or another solution. The key is to match the mechanism to the specific type of access and risk, rather than expecting a single technology to solve every security problem.
If your VPN infrastructure was designed several years ago and the way your organization works, the number of users, the applications you use or your cloud environment have changed since then, it may be worth revisiting its original assumptions. 4Prime experts can help assess your current access model, identify where VPN still performs its role effectively and highlight scenarios where more specialized solutions may be a better fit.

