VPN or ZTNA: Secure Remote Work in the Mittelstand
VPN or ZTNA: learn why classic VPNs become a security risk for your company and how you can roll out Zero Trust successfully in the Mittelstand.

The changing world of work: why the classic perimeter is obsolete
The days when your employees came into the office every morning to log in at their fixed desktop PCs are over. Today, mobile working is a firm part of everyday life in the German Mittelstand: a quarter of all working people in Germany now work at least part of the time from home[1]. For you as a managing director or IT lead, this shift means one thing above all: the classic security zone, also known as the perimeter, no longer exists. The physical boundaries of your company network have dissolved, and with them the traditional IT security concept loses its effect.
Network security used to work like a castle with a moat. Anyone inside the walls was considered trustworthy; anyone outside was not allowed in[2]. To give employees working from home access to internal servers, IT departments built a secure tunnel through the castle wall using a VPN. Once the VPN connection was established, however, the user often had unrestricted access to large parts of the network. In a modern, hybrid working world, where sensitive business data no longer sits only in your own data center but is spread across various cloud services, this implicit assumption of trust is an enormous risk.
- Mobile working and home office as the standard: your teams work from anywhere and use unsecured home networks or public hotspots.
- Use of cloud software: many of your business applications run directly in the browser, without the traffic ever touching your local company network.
- Use of personal devices: when employees access sensitive data with private laptops or smartphones, you often lack important controls over the security status of these devices.
- Vulnerabilities in VPN gateways: attackers increasingly focus on weaknesses in VPN software to gain access to your entire network with a single compromised login[3].
To protect your sensitive company data effectively today, you have to let go of the idea that internal access is automatically safe. The modern approach is Zero Trust: trust no one, verify everyone, and do so on every single access to a resource[4]. The user's identity and the security state of the device have to be verified continuously before access is granted. With flexible cybersecurity solutions or the support of a fully managed IT service, you can establish this security shift in your company without blocking your day-to-day business.
Moving to a modern access model is not a theoretical IT project but a concrete business necessity to prevent operational downtime and data loss. When you align your IT infrastructure with Zero Trust, you make sure your remote teams can work productively while the risk of ransomware attacks and data leakage drops drastically. In the next step you will learn why the classic VPN is no longer up to these demands and where the concrete weaknesses lie.
The VPN dilemma: why the tunnel becomes a security risk for SMEs
For many years the Virtual Private Network (VPN) was seen as the undisputed gold standard for secure remote work in the Mittelstand. But in a modern working world, where your employees work flexibly from home, on the train or in a cafe, this technology is reaching its limits. Classic VPNs were designed for a time when almost all data sat safely in the company's own data center and only the occasional field worker needed to connect from the road. Today, however, VPN connections increasingly prove to be risky entry points that can jeopardize the security of your entire company.
The principle of blind trust
The fundamental problem with conventional VPNs lies in how they work. They operate on the principle of perimeter-based security: the outside is controlled, the inside is trusted blindly. Once a user has successfully authenticated through the VPN client, they receive far-reaching access to the entire network behind it. If cybercriminals manage to steal an employee's credentials or compromise the VPN gateway itself, they can move sideways through the system unhindered. They dig deeper into your server structures, siphon off sensitive data or, in the worst case, encrypt your backups. That is exactly how devastating ransomware attacks in the Mittelstand begin.
This risk is made worse by the rapid rise in technical vulnerabilities. According to the current situation report from Germany's Federal Office for Information Security (BSI), an average of 119 new vulnerabilities in IT systems are disclosed worldwide every day. Many of these vulnerabilities affect the firmware of well-known VPN providers directly. Since IT staff in smaller and medium-sized companies often have their hands full and lack the capacity for seamless real-time monitoring, critical security patches frequently remain uninstalled for days or weeks. For attackers, that is an open invitation to scan for and exploit vulnerabilities automatically.
- Broad network access (lateral movement): after a successful login, the user is connected not just to a specific application but directly to the entire subnet.
- No check of the device: a classic VPN checks the credentials but rarely questions the security status of the connecting device, which means compromised private devices can smuggle malware into the company network.
- Central single point of failure: the VPN gateway is visible from the public internet and represents a permanent, attractive target for attacks.
- Reduced productivity: slow connections and frequent dropouts frustrate your employees and often lead them to bypass security rules so they can work without interruption.
As a managing director or IT lead in the Mittelstand, you can no longer rest on the illusion that an encrypted data tunnel alone provides sufficient protection. To effectively secure your hybrid teams and your sensitive company data in today's threat landscape, a fundamental rethink is required. A modern approach has to replace the rigid trust in network locations and instead check every single access request continuously.
What is ZTNA? The security principle 'trust no one, verify everyone'
Classic VPN connections are based on a simple principle: once a user has cleared the network barrier, they are considered trustworthy. Zero Trust Network Access (ZTNA) breaks radically with this outdated approach[5]. Instead, ZTNA follows the philosophy: trust no one, verify everyone and everything. For you as a managing director or IT lead in the Mittelstand, that means a completely new level of security for your hybrid teams. Under ZTNA, no device and no user is trustworthy by default, regardless of whether the access happens from a home office or your own building.
At its core, ZTNA shifts access control from the network layer to the application and identity layer. This means users are no longer let straight into the entire company network but are given targeted access solely to the applications they need for their daily work[6]. An employee from marketing therefore never even sees the accounting system or the servers of the IT infrastructure. This prevents attackers from spreading through the network unhindered in the event of a security incident.
The three pillars of an effective ZTNA model
- Continuous identification: the identity and context of every user and device are checked on every single request, not just once at login.
- Least privilege: access rights are kept as restrictive as possible, so that each employee can only reach the applications that have been released for them.
- No implicit trust: the user's location no longer matters. Access from your own company building is checked just as strictly as a connection from a public Wi-Fi network.
Through this consistent isolation of the individual resources from one another, unauthorized lateral movement in the network becomes almost impossible. Even if an employee's credentials are stolen through phishing, the damage stays strongly contained locally, because the attacker does not gain automatic access to the entire network. To protect your company data effectively against modern threats such as ransomware, moving to such restrictive security models is indispensable today.
For small and medium-sized companies, switching to ZTNA does not have to be an insurmountable hurdle. As part of holistic security strategies such as cybersecurity from CAVRIX, such a Zero Trust architecture can be implemented seamlessly and without disruption to ongoing operations. That keeps your IT protected while your teams can work in the home office or on the road in a completely secure and flexible way.
VPN vs. ZTNA head to head: security, performance and usability
If you offer remote work in your company, you often face a choice: VPN or Zero Trust Network Access (ZTNA)? Classic Virtual Private Networks were developed for a time when almost all employees sat in the office and only a few exceptions needed to connect from outside. Today your teams work flexibly from anywhere. VPNs reach their limits here, both in terms of security and speed. ZTNA takes a different path: it trusts no one by default, not even users inside the network, and checks every request individually. According to market analyses from Gartner, around 60 percent of companies will gradually retire classic VPN systems and replace them with modern ZTNA solutions[7].
The biggest difference lies in the security approach. When an employee logs in through a classic VPN, they usually receive full access to the entire network segment. Once attackers break into this VPN, they can move through the company network unhindered. With a modern cybersecurity approach using ZTNA, this is different. ZTNA grants access rights strictly according to the principle of least privilege access. Your employees only receive access to exactly the applications they actually need for their daily work. That reduces the attack surface drastically and protects your company from the uncontrolled spread of malware.
Performance and usability in everyday work
A VPN often routes all traffic through a central company network (backhauling), which leads to noticeable delays and frustration for your employees. ZTNA, by contrast, builds direct, encrypted connections to the respective application in the cloud or the data center. For your teams, that means a more stable connection and noticeably faster loading times. It also removes the tiresome manual dial-in that many people know from VPNs. Sign-in runs in the background and continuously checks security factors such as device status or location.
| Criterion | Classic VPN | Modern ZTNA |
|---|---|---|
| Network access | Full access to the entire network segment after a successful login | Precise access only to released, individual applications |
| Security principle | One-time trust at the network entrance (implicit trust) | Continuous verification of every access (Zero Trust) |
| Performance | Rerouting data through central servers often causes latency problems | Direct, optimized connections to cloud and on-premise applications |
| Usability | Manual dial-in required, frequent connection dropouts | Seamless connection in the background with user-friendly sign-in |
For small and medium-sized companies with remote teams, managing VPNs is often time-consuming and error-prone. A modern approach to IT security noticeably relieves your IT staff. With the right services in managed IT and cybersecurity, you can shape the transition from outdated VPN infrastructures to modern Zero Trust models in a secure and pragmatic way. That way you make sure your employees can work flexibly while sensitive company data stays optimally protected.
A pragmatic switch in the Mittelstand: rolling out ZTNA step by step
A sudden, complete switch from VPN to Zero Trust Network Access (ZTNA) is often not necessary for a mid-sized company and would put unnecessary strain on your IT department and ongoing operations. A modular, step-by-step transition is far more pragmatic and safer. You proceed strategically by not switching off existing VPN connections overnight but instead migrating critical applications and user groups to the new security concept one after another[8]. This way you minimize the risk of outages and make sure your teams stay productive.
The modular roadmap for SMEs
To make the transition run smoothly in your company with fewer than 500 employees, you should start with the biggest levers. Often it is external partners or employees in the home office who need to access very specific applications. Instead of giving them access to your entire network through a classic VPN, you restrict access via ZTNA to the applications they actually need[9]. This reduces your attack surface immediately, because these applications remain invisible to unauthorized users on the internet[9].
- Step 1: connect external service providers and partners. Start by giving external providers targeted access to individual applications such as ERP systems via ZTNA, instead of issuing a full VPN profile.
- Step 2: migrate critical cloud and web applications. Move access to sensitive internal cloud systems or web apps over to the new architecture.
- Step 3: bring in high-risk user groups. Gradually add departments that handle sensitive data, such as accounting, HR or management, to the ZTNA model.
- Step 4: retire the old VPN step by step. Once all core applications have been migrated and your employees have grown used to the new workflow, you can finally deactivate the old VPN access.
Integration into your existing IT infrastructure
A step-by-step switch does not require a complete replacement of your IT infrastructure. Modern ZTNA solutions integrate seamlessly with your existing identity management, such as Microsoft Entra ID, and can be combined with multi-factor authentication (MFA)[8]. If, as a managing director or IT lead, you are looking for support with planning and implementation, professional services such as cybersecurity or full support as part of managed IT from CAVRIX can help. That way you make sure your company is optimally protected against modern threats even in hybrid day-to-day work, while you effortlessly meet the requirements of relevant regulations.
Relief for your IT: how managed providers secure the transition
In many mid-sized companies, IT staff hit their capacity limits every day. Alongside ongoing operations and daily support, there is barely any time to plan and carry out complex migration projects such as the switch from a classic VPN to a modern Zero Trust architecture. The persistent shortage of specialists makes this situation even worse. According to recent studies, around 64 percent of German IT decision-makers report considerable difficulty finding qualified staff for network engineering and cybersecurity[10]. Without external support, the urgently needed modernization of the security infrastructure therefore often falls by the wayside.
Secure migration without pressure on your own staff
The move to a secure remote working environment does not have to overwhelm your internal IT department, though. A qualified partner takes on the entire complexity of the project, from the first analysis to ongoing operations. With our managed IT service and tailored cybersecurity offerings, we secure your operations while you can focus on your core business. This professional support makes sure that all new security structures are built to be NIS2-compliant from the start and that no security gaps arise during the transition.
The structured transition at a glance
So that the ongoing operation of your company is not put at risk during the changeover, the switch from VPN to ZTNA happens in clearly defined steps. Instead of a risky complete rebuild on the open heart, the new security architecture is introduced in parallel and without downtime.
- Precise inventory: analysis of your existing infrastructure, all cloud services in use and the active user roles.
- Gentle parallel phase: gradual rollout of the new ZTNA clients while the old VPN stays active as a fallback.
- Frictionless migration: successive transfer of access rights to the new, identity-based security structure.
- Continuous relief: permanent monitoring, automatic patch management and direct support from experts during ongoing operations.
Through this pragmatic approach, you not only minimize the risk of misconfigurations but also protect your team from unnecessary downtime. If you want to know what a smooth switch of your IT setup looks like in practice and what you should pay attention to, our guide tells you everything about the option of changing your IT service provider without taking on operational risks.
Frequently asked questions
What is the main difference between VPN and ZTNA?
While a classic VPN grants a user full access to the entire network after a successful login, ZTNA applies the principle of least privilege. Every access is checked continuously, and the user only receives access to exactly the applications they need for their work. The rest of the network stays invisible.
Why are classic VPNs now considered a security risk in the Mittelstand?
VPNs are based on outdated architectures that allow an attacker to move sideways through the network unhindered once they get in. VPN gateways themselves are also frequent targets of cyberattacks. Given the BSI report that around 119 new IT vulnerabilities are discovered every day, unprotected VPNs represent a massive point of entry.
How high are the costs of introducing ZTNA in an SME?
The costs are often lower than expected, because ZTNA is usually provided as a cloud service. You do not need expensive hardware on site and save administrative effort. Since, according to Bitkom, 87 percent of companies are affected by data theft or sabotage, the investment pays for itself extremely quickly through the downtime risk it avoids.
Can I run ZTNA alongside my existing VPN?
Yes, and for the Mittelstand this is even the recommended path. You can introduce ZTNA step by step for particularly critical applications or specific user groups such as external service providers, while other teams keep using the VPN for now. That way you prevent disruption to ongoing operations.
Does ZTNA need special software on all employee devices?
Not necessarily. Many ZTNA solutions can be used agentlessly through the web browser for SaaS applications. For comprehensive protection and deep device checks, however, a small software agent on the endpoints is recommended. In the Mittelstand you can have this distributed and managed automatically.