A traditional VPN puts a remote laptop on your internal network. If that laptop or account is compromised, so is everything it can reach. Zero Trust flips the model: nothing is trusted because of where it connects from, and every request is checked for who is asking, on what device, for which application.
What changes in practice
| Flat VPN | Zero Trust access | |
|---|---|---|
| Access granted to | The whole network | One application at a time |
| Identity check | Once, at connect | On every request |
| Device checks | Rare | Required: patched, encrypted, managed |
| If an account is stolen | Wide exposure | Limited to what that user may reach |
A practical rollout
- Put every user behind single sign-on with MFA, preferably phishing-resistant passkeys or security keys.
- List your internal applications and who needs each one.
- Publish them through an identity-aware access service such as Cloudflare Access, with policies per application and group.
- Add device posture checks so only managed, up-to-date devices can reach sensitive systems.
- Keep a narrow VPN only for the few systems that cannot be published, and review it regularly.
- Log access centrally and alert on unusual sign-ins.
Pair it with the basics
- Firewalls and segmentation inside the office so a single compromised device cannot roam.
- Sandboxed analysis of suspicious files before they reach staff, as covered in our cyber threat assessment work.
- Fast offboarding: removing a person from the directory should remove every access at once.
