The death of the VPN and the rise of identity-based access

Not long ago virtual private networks were the gold standard for secure remote access. VPNs have been the go-to method for providing employees with secure access to company systems from the outside for decades, but the concept of a clearly defined network perimeter is fading rapidly. The people accessing your data could be AI tools, third-party vendors or even malicious insiders – traditional remote access tools just aren’t built for that kind of complexity.

As a result, IT leaders are waking up to a new reality: the VPN is no longer fit for purpose. With hybrid workforces, cloud-native infrastructure, and an expanding threat landscape, security teams need to pivot to identity-based access models that authenticate who you are, not just where you’re connecting from.

VPNs: Built for a different era

VPNs were initially designed to provide employees with a secure means of accessing internal company systems from outside the office. By encrypting the connection between a user’s device and the company network, they create a secure tunnel that helps keep hackers and eavesdroppers at bay.

But that model is becoming increasingly problematic. 

First, VPNs implicitly trust any user who successfully connects, giving them broad access to the internal network regardless of their true identity. That’s a nightmare in the age of credential theft, lateral movement and ransomware.

Second, VPNs struggle to keep up in today’s cloud-first, distributed environments. Applications no longer live solely in central data centres – they’re hosted across SaaS platforms, public clouds and hybrid setups. Forcing all that traffic through a VPN can slow things down and make everything more complicated.

And third, from an operational standpoint, VPNs are a constant source of pain: connection issues, clunky user experiences and limited visibility into access behaviour all compound risk.

That’s not just theory. Attackers have repeatedly exploited VPN weaknesses to devastating effect. Pulse Secure VPN vulnerabilities have been linked to breaches of US government agencies, and more recently, Cisco warned of active exploitation of VPN flaws in its Adaptive Security Appliance (ASA), a reminder that attackers still view VPNs as low-hanging fruit.

Identity is the new perimeter

Enter identity-based access, a model built on the principle that access decisions should be based on who the user is, what device they’re on, what they’re trying to access, and the context around that request.

This approach, often delivered through Identity and Access Management (IAM) tools, shifts the security focus from the network layer to the identity layer. Rather than letting users onto the network and trusting them from that point forward, identity-based access continuously verifies their credentials and restricts access to only the apps and data they’re authorised to use.

Modern identity-based systems incorporate risk signals – such as geolocation, device health, login history and behavioral patterns – to flag anomalies and trigger additional verification.

They also support granular policies. Contractors may only have access to specific cloud environments for limited periods, for example, while full-time employees require step-up authentication to access sensitive HR or financial data.

6 Customer Identity Tips to Maximize Retail’s Peak Season

Holiday shopping is retailers’ most critical time; online sales jumped 22% from Q3 to Q4 in 2024. But with cart abandonment topping 70% and fraud attempts peaking during the holidays, retailers must deliver fast, seamless, and secure shopping journeys to win customer trust and sales. In this e-book, discover six proven identity strategies to reduce abandonment, fight fraud, personalize experiences, and convert seasonal shoppers into loyal customers.

The shift is already underway

According to Gartner, at least 70% of new remote access deployments will be served predominantly by IAM rather than VPN services, up from less than 10% in 2021. 

We’re already seeing large-scale migrations in sectors where risk tolerance is low. Financial institutions, healthcare providers, and government agencies are increasingly investing in identity-centric architectures, not only to reduce attack surfaces but also to simplify compliance with regulations such as NIS2 and HIPAA. 

Cloud-native businesses are further ahead. With little or no legacy infrastructure to worry about, they’ve embraced tools such as Okta, Azure AD, and Google BeyondCorp-style architectures from day one.

But even among traditional enterprises, the writing is on the wall. VPNs are being gradually phased out or relegated to niche use cases, such as legacy apps that can’t yet be modernised. In their place, businesses need to adopt modern alternatives such as single sign-on (SSO), multi-factor authentication (MFA), conditional access policies and device trust.

Challenges on the road to zero trust

The journey to IAM isn’t without its hurdles. Legacy systems can be complex to integrate with modern identity platforms, while cultural resistance within IT teams, who are accustomed to using VPNs and firewalls, can slow down adoption. And there’s the classic risk of “zero trust” becoming a buzzword more than a blueprint.

CISOs need to ensure that identity-based access isn’t just bolted on, but embedded into the wider IT strategy. That means rethinking everything from procurement and onboarding processes to incident response playbooks and employee education.

There’s also a need for cross-functional collaboration: IT, security, HR and business leaders all have a stake in shaping identity governance. Who should have access to what? When should access be revoked? How do you audit that access over time?

The end of the VPN is just the beginning

The decline of VPNs is part of a broader shift in how we think about trust, access and security. In a world where users, devices and workloads are constantly in motion, rigid perimeters no longer make sense. Identity-based access offers a more dynamic, context-aware alternative, aligning with the way people work today. It’s not a silver bullet, but it is a fundamental building block of modern security architecture.

For CISOs and IT leaders, the message is clear: if you’re still relying on VPNs as your first line of defence, it’s time to ask whether your access strategy belongs to 2025 or 2005.

About The Author

Carly Page
Carly Page

Carly is a freelance technology journalist and editor with a long string of credits to her name. Her bylines include Forbes, IT Pro, The Metro, Stuff, TechCrunch , TechRadar, TES, Uswitch and WIRED.
She has written about collaboration and innovation for TechFinitive.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.