Skip to content
FioSec Consulting

Network Access · Case study

Retiring the VPN that let everyone go everywhere

An aging VPN gave staff and contractors the run of the network when most needed a single application. FioSec replaced it with Zero Trust Network Access, so people connect to what they are entitled to, and nothing else is even visible.

The situation

The organization

An organization whose remote access had outlived its design: one VPN, built for a handful of remote staff, now carrying employees, contractors, and vendors alike.

What prompted it

The VPN treated every connection the same: once you were in, you were on the network. A contractor hired to work on one system could, in practice, reach far more, and nobody was comfortable with how much trust a single set of VPN credentials carried. The organization engaged FioSec to modernize remote access around a simple principle: access to applications, not to the network.

What FioSec did

Each step maps to a layer of the Layered Defence model: vendor-agnostic by design, described by the control it delivers rather than any one product.

  1. Map who needs what

    We started by mapping who actually connects remotely and which applications each group uses. Most people needed far less than the VPN granted them, which is exactly the problem.

  2. Zero Trust Network Access

    ZTNA replaced the VPN: users authenticate and get access to specific applications based on identity, instead of being placed on the network. What they are not entitled to is not just blocked, it is invisible.

  3. Contractors, contained

    Third parties now reach exactly the systems their engagement calls for and nothing else, and their access ends when the engagement does instead of living on in a forgotten VPN account.

  4. Retire the old gateway

    Groups were migrated in stages so nothing broke mid-transition, and once the last group moved, the legacy VPN was switched off for good.

The outcome

A compromised remote credential no longer hands an attacker the network, only the applications that identity is entitled to.

Contractor and vendor access is scoped to the engagement and expires with it.

Remote access is governed by identity and policy instead of one shared gateway, and the aging VPN is retired.

Facing something similar?

Tell us where you are today and we’ll help you map the right next step. No obligation.