Logo Teldat
Zero Trust Remote Access – Identify, context & verification

Remote Access (Zero Trust Remote Access) has become a key element for any organization. Remote work, employee mobility, and collaboration with third parties are now the norm rather than the exception. However, the way many companies grant access to their corporate applications remains rooted in a model designed for a different era. Rethinking how we grant that access has become a security priority. For more than two decades, the virtual private network (VPN) has been the go-to remote access solution. Its logic is simple: an encrypted tunnel is established, and the user can operate as if they were physically inside the corporate network. And that is where the problem lies. Once authenticated, the user is typically given broad access to the network (often beyond the applications they use or need).

That perimeter-based model, the classic “castle and moat” approach, assumes that everything inside the network is trustworthy. In an environment where applications reside in the cloud, devices aren’t always managed and the use of stolen credentials is widespread. In this scenario, implicit trust has become a risk. Compromised VPN credentials are now among the most common attack vectors, and a single breach can open the door to lateral movement attacks that jeopardize the whole infrastructure.

Zero Trust Remote Access - ZTNA - VPN replacement - Teldat

From perimeter to identity: the Zero Trust principle

The Zero Trust model is based on a radically different approach: trust nothing and no one, regardless of whether the request comes from inside or outside the network. The NIST SP 800-207 publication, a foundational reference on the subject, sums it up with the maxim “never trust, always verify.” The distinction between a “secure” internal network and a “dangerous” external network disappears. Each user, device, and request is individually validated and continuously reassessed based on risk.

 

What do we mean by Zero Trust Network Access (ZTNA)?

Zero Trust Network Access is the manner in which this principle is implemented in Zero Trust Remote Access. Instead of giving the user broad access to the network after log-in, ZTNA only grants access to the specific applications or resources the user is authorized to use (and only for as long as the conditions established are met). Before the connection is enabled, a trusted broker evaluates each request based on the user’s identity, other context-based factors, and the posture and location of the device. Critically, applications remain hidden from unauthorized users. Since they are not exposed to the Internet, they are invisible to potential attackers and cannot be discovered or scanned for vulnerabilities.

How Zero Trust Remote Access actually works?

Access is governed by a “deny-by-default” strategy. Nothing is permitted until the required level of trust is proven beyond doubt. Then, strong authentication comes into play (typically integrated with the corporate identity provider and single sign-on and reinforced with multi-factor authentication). Device posture is verified (i.e., the real-time security and compliance status of a device) before access is granted. The principles of least privilege and microsegmentation are also applied, meaning users are only given access to what is strictly necessary to prevent lateral movement attacks between systems. All of this is verified not just once, but continuously throughout the session.

In addition, ZTNA provides flexible access and cloud or on-premise deployment. A lightweight agent installed on the device can be used, or it can all be agentlessly implemented (a particularly practical approach for unmanaged devices or third-party access).

 

Outperforming the VPN Model

The main difference between ZTNA and a traditional VPN is not encryption, but  the scope of access. A VPN authenticates the user once, at the start of the session, whereas ZTNA verifies each request individually and grants access to the application, not to the network. This results in a much smaller attack surface and effectively curbs lateral movement. If credentials are compromised, the potential damage is limited to a specific resource rather than the whole infrastructure.

There are also operational advantages. By connecting the user directly to the application, which is often already in the cloud, this implies that there is no need to route all traffic through the corporate data center. This improves performance and user experience. Additionally, ZTNA provides granular visibility into each access event, making it easier to detect anomalous behavior and generate compliance reports.

 

A paradigm shift that is already a trend

Leading consultancy firms specializing in telecommunications estimate that most new remote access deployments now rely on ZTNA with Zero Trust Remote Access. Just a few years ago, this number was negligible. Hybrid work, cloud migration, and collaboration with third parties have really pushed this strategy. However, it is important to understand this is a gradual process and that migration generally occurs in phases, meaning specific user groups or applications will play a leading role before ZTNA with Zero Trust Remote Access is integrated into a broader edge security strategy (SASE/SSE).

Conclusion

Secure Zero Trust Remote Access is no longer just a matter of connectivity. It has become a matter of trust: who is accessing what, from which device, to which resource, and in what context. Zero Trust Remote Access replaces traditional VPNs by granting application-level access based on continuous user and device verification (effectively replacing implicit trust and drastically reducing the impact of potential attacks).

Teldat rises to the challenge with its own ZTNA solution with Zero Trust Remote Access. Centered around identity, continuous verification, and granular control, it offers flexible cloud and on-premise deployment and, by not relying on VPNs, makes applications invisible to the Internet. Moreover, it incorporates agentless access designed for unmanaged devices and third-party access.

September 01, 2026
Carlos Franco

Carlos Franco

Graduate in Computer Engineering with a Master’s in Cybersecurity, specializing in monitoring systems, the design of detection and incident response architectures. Combining strong technical expertise with experience in both channel and direct cybersecurity sales. Currently Cybersecurity Business Line Manager at Teldat.

Related Posts 

Secure SD-Branch SASE Convergence

Secure SD-Branch SASE Convergence

For years, branch networking and enterprise security evolved independently, each with its own infrastructure, devices, and management consoles. However, widespread cloud adoption, the rise of SaaS applications, and the shift to remote work have...

read more
Open XDR Ecosystem Integration

Open XDR Ecosystem Integration

Introduction Modern enterprise networks rely on dozens of security technologies from different vendors. There's EDR for endpoint protection, SIEM to collect and retain logs for regulatory compliance, cloud services such as AWS, Google Cloud, and...

read more