Cloud

ZTNA

Zero Trust Network Access (ZTNA) connects users securely to specific applications without exposing the entire network.

Zero Trust Network Access (ZTNA) grants access to individual internal applications, not entire networks. Every connection is verified based on identity, device, and context.

How it works

With a classic VPN, a device is inside the internal network after logging in. It can then reach many systems, including ones it does not need. With ZTNA, a service brokers the connection to one specific, approved application. The applications themselves are not visible from the internet. Access is continuously re-evaluated, for instance if the device's security status changes.

For example, an external service provider needs access to a maintenance interface. A VPN would have granted them access to the entire server network. With ZTNA, they only see this single application. If their laptop is compromised, the attacker cannot move further into the network.

What to look out for

  • First, catalogue which user groups require which applications.
  • Start with external partners and remote access, where the benefit is greatest.
  • Include the device's security posture in access decisions, such as an active EDR.
  • Check how legacy applications using special protocols can be connected.
  • Integrate the access logs into the SOC.

Why it matters

For years, vulnerabilities in VPN appliances have been among the most common entry points for ransomware and APT groups. ZTNA reduces this attack surface. It also limits an attacker's movement after they have compromised an account or device.

Differentiation

ZTNA is a building block of Zero Trust. It is often part of a SASE solution. Zero Trust also covers identities, devices, data, and segmentation within the network.

Typical mistakes

The old VPN is often left running in parallel "for emergencies". This means the old attack surface also remains. Therefore, set a clear date for its decommissioning.

How we implement it

We monitor access through your ZTNA solution in the SOC and detect unusual patterns. We are happy to discuss architecture questions as part of our Security Consulting.