For enterprise security teams, replacing the VPN is no longer a question of if, but how. Gartner positions zero-trust network access (ZTNA) as a scalable alternative to traditional VPNs, and Verizon’s 2026 Data Breach Investigations Report found that, for the first time in the report’s history, vulnerability exploitation is now the leading initial access vector, accounting for 31% of breaches. Notably, edge devices and VPNs jumped from 3% to 22% of exploitation-driven cases in a single year.
But the rush toward zero trust creates a question that gets less attention: what happens when modernization starts dictating the infrastructure enterprises can use today?
For organizations operating across regions, supporting third parties, or relying on IP-based controls, capabilities such as stable regional connectivity and flexible gateway options remain operational necessities. Removing them in the name of modernization can simply move complexity somewhere else.
The zero-trust transition trap
Not every VPN reassessment starts with zero trust. Some start with the vendor.
Enterprises are moving off VPN platforms for a reason that has little to do with the technology itself: the capabilities they depend on—shared gateways, flexible IP configurations, regional infrastructure, responsive support—are quietly being retired underneath them. That’s a different problem than modernization, and it deserves a different conversation.
The paradox is that a security architecture meant to reduce complexity ends up creating a new layer of it when enterprises are pushed into migration before they’re ready.
The hidden cost of going “ZTNA-only”
For an enterprise operating across multiple countries, access infrastructure carries requirements that go well beyond connecting users to applications. Regional requirements influence everything from performance and IP-based access controls to regulatory obligations and third-party connectivity.
Consider a multinational organization whose security team has allowlisted specific IP addresses, built regional workflows around existing gateways and designed access policies around local requirements. Removing those capabilities rarely simplifies the environment. In practice, it forces teams to reconfigure cloud services, security policies, network rules and compliance processes.
None of this is an argument against taking VPN security seriously. The DBIR numbers are real, and unpatched edge devices are a legitimate risk. But the risk comes from how VPN infrastructure is managed—patch cadence, exposure of admin interfaces, credential hygiene, segmentation. VPN connectivity itself isn’t the problem. Replacing a well-managed VPN with a rushed ZTNA rollout won’t eliminate the risk—it will simply move it somewhere else.
Performance matters, too. Security teams need to know how technology performs for actual users, in actual locations, accessing actual business resources. An architecture that looks elegant on paper but introduces latency in a key region is still an operational problem—and when problems arise, teams need a provider that can help troubleshoot and understand the environment.
Modernization shouldn’t mean disruption
Zero trust still belongs in the picture—for the risks the DBIR flags, it’s a genuinely useful layer. The question is whether organizations need to abandon their existing connectivity model to adopt it.
For many enterprises, a more practical approach is transitional: maintain reliable VPN connectivity where it still makes sense, while introducing zero-trust controls where they provide a clear advantage. That’s particularly valuable during hybrid-work expansion, third-party access growth, or cloud migration.
Running VPN and zero trust in parallel
NordLayer combines business VPN connectivity with zero-trust network access capabilities in one platform, letting organizations maintain the infrastructure they still depend on under a single set of controls, patch cadence and policy while progressing toward a more granular access model.
Organizations don’t have to abandon their existing VPN infrastructure overnight, nor do they have to force a migration project to adopt a zero-trust initiative. They can continue using VPN access for network-level scenarios while adopting zero-trust controls for applications, users, devices and policies that require more granular protection.
This gives enterprises a modernization timeline they set themselves, and running VPN and zero trust side by side offers something a single-track migration can’t: choice.
Don’t let modernization create a new perimeter problem
Zero trust is changing how enterprises think about secure access, and that change is unlikely to reverse. But the DBIR numbers cut both ways: the same data that argues for tighter controls also warns against leaving VPN infrastructure half-managed during a rushed migration.
Framing this as a choice between “legacy VPN” and “zero trust” misses the point. The real work is building an access strategy that supports today’s requirements while creating a practical path toward tomorrow’s architecture.
Enterprises shouldn’t have to sacrifice reliable connectivity to move forward.