Ask an infrastructure team what broke in March and you will hear about the VPN. Concurrent licence ceilings reached by nine in the morning. Concentrators at full load. Video calls crawling because the traffic went from a living room in Sharjah to a data centre in Jebel Ali and back out to the internet. Help desks fielding hundreds of calls that all amounted to the same sentence: it is slow. Three months on, the industry has decided that the answer is zero trust, and a great deal of what is being sold under that name this quarter is traffic engineering wearing a security costume. That is not an argument against the direction. It is an argument for being honest about which problem you are solving, because the VPN did not fail as a security control. It failed as a routing architecture.
What actually broke
The corporate VPN was designed on an assumption that held for twenty years: most people are in the office most of the time, and remote access is an exception used by a minority for a few hours. Everything about the design follows from that. Capacity was sized for the exception. Licences were bought for the exception. And crucially, all traffic was routed back through the corporate network, because when remote access was rare, hairpinning was cheap and gave the security team a single inspection point. Remove the assumption and each of those decisions inverts. Capacity becomes the binding constraint. The single inspection point becomes a bottleneck that the entire company's video conferencing has to squeeze through. And the argument for routing a user's cloud email through a building they are not in becomes very difficult to make to a finance director looking at the bandwidth bill. None of this is a statement about whether the tunnel is secure. It is a statement about where the traffic should go.
Triage the traffic before you buy anything
The useful first exercise takes a week and costs nothing. Divide what your remote users do into three categories. Traffic with no business on the corporate network. Cloud email, the collaboration suite, video conferencing, the hosted applications you already bought as services. This is usually the majority of the volume and almost none of the risk that the tunnel was protecting. Sending it directly to the internet, with split tunnelling, is the single highest-value change available to most organisations right now, and it can be done this month. Internal web applications. The intranet, the expense system, the ticketing tool, the internal reporting portal. These do not need network access; they need to be published, individually, through a gateway that authenticates the user and checks something about the device before proxying the request. This is the part that genuinely deserves the zero trust label, and for most organisations it is six to eighteen months of steady work, application by application. The residue that genuinely needs the network. Thick clients, file shares over legacy protocols, remote desktop to an office workstation, administrative tools, anything the vendor restricts by source address. This will still be on a tunnel in three years. Accept that, inventory it precisely, and shrink it deliberately rather than pretending it away. The number worth tracking is the proportion of remote sessions that still require the tunnel. If it is ninety per cent today and forty per cent in a year, the programme is working.
| Category | Path to review | Control question |
|---|---|---|
| Cloud services | Direct access where justified | What replaces inspection and logging? |
| Internal web applications | Individual identity-aware gateway | Who is entitled and which device checks apply? |
| Network-level residue | Narrow retained tunnel or controlled jump path | Which protocol, users and egress restrictions still require it? |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
The trap in this quarter's purchases
The most common mistake being made right now is replacing an on-premises concentrator with a cloud-delivered access service, keeping the same policy, and reporting a zero trust milestone. If, after authentication, the user's device is still placed on a network segment from which it can reach hundreds of systems it has no business reaching, nothing about the trust model has changed. The tunnel moved to somebody else's infrastructure and got faster. That is a worthwhile capacity and performance outcome; it is not a reduction in implicit trust. The control that matters is the one nobody enjoys building: per-application access decided at the moment of the request, based on who the user is, what they are entitled to, and the state of the device in their hands. Device state is the hardest part this year, for an obvious reason: for three months nobody could touch the hardware. A realistic posture policy in 2020 checks a small number of things you can actually verify remotely, encryption, patch level, endpoint agent presence, and treats unmanaged personal devices as a separate class that gets browser-based access to specific applications and nothing else. Start there rather than with the perfect policy, and phase it: identity and strong authentication first, because they are the only controls that work regardless of location; then publish the top ten internal applications; then posture; then shrink the residue.
Practical Guidance for Zero Trust Roadmap
- Classify remote traffic into the three categories and publish the numbers. Volume and session counts per category turn a philosophical debate into a sequencing decision.
- Split-tunnel the obvious cloud services now. Email, collaboration and conferencing to the internet directly. The performance gain is immediate and the risk is manageable with endpoint and DNS-layer controls.
- Replace the lost inspection point explicitly, not implicitly. If traffic no longer passes the perimeter, decide what enforces policy on the endpoint and what it logs, and write it down.
- Publish internal web applications one at a time through an identity-aware gateway. Ten applications properly published beats a platform purchase with nothing behind it.
- Inventory the network-level residue precisely. Protocol, system, users, business justification, source-address restrictions. This list is the actual scope of the multi-year work.
- Make strong authentication universal before anything else. It is the only control that travels with the user, and every subsequent step assumes it.
- Define a minimal, remotely verifiable device posture, plus a separate class for unmanaged devices. Perfection here delays the whole programme for a year.
- Track the proportion of sessions that still need the tunnel, quarterly. One honest metric prevents the programme becoming a series of product launches.
The Regional Angle
Four constraints shape how far this can be taken from here, and the first stops the programme dead in several organisations. A large amount of the work a Gulf back office does every day happens on external portals that restrict access by registered source address: customs and trade systems, labour and immigration platforms, tax filing, several bank portals, some insurer and government procurement systems. The company's registered address is the office internet connection, so the user must egress from the corporate network whether or not anything sensitive is involved. Inventory these deliberately, because they are the reason the tunnel survives, and consider a narrow published solution for them, a controlled jump environment egressing from the registered address, rather than keeping the whole workforce tunnelled for the sake of a dozen portals. Second, split tunnelling moves the policy enforcement point out of the building, and in this region central enforcement was doing more than security work. Content filtering and acceptable-use controls were applied at the corporate gateway partly to satisfy the organisation's own obligations about how its connectivity is used. Send user traffic direct and that enforcement disappears unless you replace it. Decide consciously whether the replacement is an endpoint agent, a DNS-layer control or a cloud gateway, and record the decision, because "we removed the tunnel and nobody noticed the filter was gone" is not a position you want to explain to an auditor. Third, if identity becomes the front door, then the identity service becomes the single point of failure for the entire company, and that deserves the attention a data centre used to get. Work out what happens when it is unavailable, keep a small number of break-glass administrative credentials on a documented offline path, and be ready for a regulator to ask where authentication and access logs are stored, because in a published-application model those logs are the audit trail for everything. Fourth, watch the double hairpin that regional group structures create. A typical arrangement puts the ERP in one group data centre in one country, with branches in four others connected over private circuits. A remote user in Muscat now tunnels to the country hub, traverses the private network to the data centre, and comes back the same way. The fix is rarely a bigger circuit; it is publishing the application closer to the user or moving to a browser-based access path for the people who only need to read and approve.
The objection worth taking seriously
The honest objection is that zero trust, as an architecture, is out of reach for most of the organisations being sold it this year. Doing it properly requires a mature identity platform, managed devices, an application inventory, and the licences that go with all three, and the total is well beyond the budget of a mid-sized regional group that spent its contingency on laptops in March. Telling that organisation its VPN is obsolete is unhelpful advice delivered with great confidence. The second objection is more technical and more serious. Some of what is happening this quarter will make security worse. Split tunnelling has been enabled in a hurry, with no replacement for the inspection and logging that the gateway provided, and the people doing it are recording a performance win rather than a control change. In eighteen months some of those organisations will investigate an incident and find they have no record of where a device went for the whole of 2020. The resolution is sequencing rather than scale. Every organisation can afford strong authentication everywhere, a traffic classification exercise and an honest residue inventory, and those three things capture most of the benefit. Publishing applications individually is incremental by nature and can be funded a few at a time. What is not affordable is the middle position: removing the perimeter for convenience, declaring the architecture modern, and never building the controls that were supposed to replace it.
Common Questions
Is split tunnelling safe?
For traffic to well-known cloud services, with endpoint protection and DNS-layer controls in place, it is a reasonable trade and a large performance gain. For everything else, decide case by case and log what you decided.
Do we still need the VPN?
Yes, for years, for the network-level residue. The goal is to shrink what depends on it, not to switch it off on an announcement.
Where should we start with a small team?
Strong authentication on everything, split tunnelling for cloud services, and publishing your three most-used internal applications. That is a quarter's work and covers most of the exposure.
What should we expect over the next twelve months?
Expect every network and security vendor to re-label its remote access product as zero trust, and expect the analyst category names to multiply faster than the capabilities. Expect more exploitation of internet-facing access appliances, because the attackers have noticed where everyone's front door moved. Expect device posture to become practical again as hardware refreshes catch up. And expect the organisations that quietly did the traffic classification in June to be the ones with a credible architecture next summer, while the ones that bought a platform are still on application number two.
Zero Trust Roadmap — we classify the traffic, publish the applications that can be published, and inventory the residue that genuinely needs a tunnel, so the programme has a sequence instead of a slogan.
