The corporate VPN was built for a world that no longer exists: one shared network, a single perimeter, and a gateway that trusted anyone who got through the front door. Staff now work from anywhere, applications are scattered across multiple data centres, and outside contractors need narrow access to specific systems rather than an entire network segment. Meanwhile, the gateways meant to protect all of this have become some of the most actively exploited devices on the internet.
That shift is not theoretical. Security agencies have repeatedly flagged remote-access gateways as high-value targets precisely because they sit at the internet edge, accept connections before authentication, and process complex protocols that are difficult to secure perfectly. When organisations decide to retire or replace one of these systems, the transition itself matters: understanding what happens when you cancel an existing VPN contract, including how access is revoked and what logs or data remain, is often overlooked until it becomes an operational headache. Planning for that moment early avoids gaps in coverage during migration.
Why the Old Model Breaks Down
The traditional VPN gateway checks a sign-in once and then opens a broad segment of the network. That made sense when everyone and everything lived inside the same walls. It makes far less sense when a contractor needs access to one application, an employee connects from a personal device on public transit, and critical infrastructure is distributed across several regions. The gap between what the VPN grants and what the user actually needs has become the primary weakness attackers exploit. Several documented vulnerabilities in widely used remote-access gateways, tracked in CISA's Known Exploited Vulnerabilities catalogue, illustrate a consistent pattern rather than an isolated failure: a device that accepts unauthenticated traffic at the edge is a target regardless of which vendor built it.
Zero Trust as a Practical Alternative
NIST's SP 800-207 framework states the principle plainly: no implicit trust is granted based solely on physical or network location. Being inside the corporate network no longer means being authorised. CISA's Zero Trust Maturity Model organises this into five areas - identity, devices, networks, applications and data - and Germany's BSI has noted that zero trust approaches tend to prevent incidents rather than merely contain them. In practical terms, this means identity verification before any access is granted, policies tied to specific applications rather than entire networks, checks on device health, and a reliable log of who accessed what and when. None of this requires abandoning VPN technology altogether; it requires rethinking what triggers access.
How Organisations Are Actually Migrating
Few companies replace everything at once. A common pattern combines a mesh VPN for staff, administrators and external providers with direct tunnels between data centres and selectively published web applications, avoiding a full VPN client for every internal service. The choice between self-hosted and cloud-based zero trust network access often comes down to where the control plane and connection data reside - on infrastructure the organisation controls, or with a vendor. Self-hosting is not automatically more secure; it shifts responsibility for updates, monitoring and incident response onto the organisation or its chosen operator. Cloud-based models, in turn, do not necessarily mean losing control of data, since traffic can remain end-to-end encrypted even when the vendor manages the control plane.
What Actually Determines Success
The hardest part of any VPN replacement is rarely the new technology. It is discovering every access path that was never documented: forgotten contractor accounts, legacy integrations, or systems nobody remembers connecting to the VPN in the first place. A careful inventory of current access, followed by a phased rollout group by group with the old gateway switched off last, tends to succeed where a single cutover fails. Regulatory pressure adds urgency: frameworks such as NIS2 now require organisations to demonstrate that access to critical systems is restricted to authorised people and devices, with logs to prove it. A properly configured zero-trust or mesh VPN architecture produces that evidence as a natural byproduct, rather than as an added burden.