Blog | Cybersecurity, Cloud & IT Trends | Manux Solutions

The End of the VPN: Why Remote Access Is Being Rebuilt Around Identity

Written by Manux Solutions | Aug 23, 2026, 8:30:00 PM

24 August 2026

For years, the VPN was the answer to a simple question: how do we let people work securely from somewhere other than the office. It did that job well when the office was the centre of everything and most of the systems people needed sat inside it.

That world has changed. Work is now spread across homes, sites, and devices, and the applications people rely on live in the cloud rather than behind the office walls. The way remote access was built for the old model is starting to work against businesses in the new one.

At Manux Solutions, we work with New Zealand businesses that have quietly outgrown their VPN. It still connects people, but it is harder to manage, harder to secure, and increasingly out of step with how the business operates.

Why the VPN became the standard

A VPN creates an encrypted tunnel between a remote user and the corporate network. Once that tunnel is open, the user is treated as if they are sitting inside the office, with access to the network as a whole.

When nearly everything a person needed lived on that internal network, this made sense. The tunnel was the front door, and getting through it was the point.

Where traditional VPNs now fall short

The problem is what happens after someone is through the door. A traditional VPN tends to grant broad access to the network rather than to the specific applications a person needs. That widens the attack surface, because anyone or anything that reaches the tunnel can potentially move across everything behind it. (Source: WatchGuard, The End of the VPN)

This matters because remote access infrastructure has become a favourite target. Attackers know that compromising a single set of VPN credentials can open the whole network, so they aim for it directly. One stolen login can become access to systems that the user never needed to touch.

On top of the security exposure, VPNs are simply harder to run as businesses grow. More users, more devices, and more cloud applications mean more to configure, more to monitor, and more that can go wrong.

The shift to Zero Trust Network Access

The direction the industry is moving in is Zero Trust Network Access, or ZTNA. The idea behind it is straightforward: no user or device is trusted by default, and access is granted to individual applications rather than to the network as a whole. (Source: WatchGuard, The End of the VPN)

Instead of asking whether someone is inside the tunnel, ZTNA asks who they are, what they are allowed to reach, and whether this specific request should be permitted. Access is tied to verified identity, not to a position on the network.

What identity-based access changes in practice

Rebuilding remote access around identity changes the everyday reality of security in a few practical ways:

  • A compromised account reaches only the applications that account was allowed to use, not the entire network
  • Access decisions are made per application and per request, so trust is verified continuously rather than granted once at the door
  • People connect straight to the tools they need, which usually feels faster and simpler than routing everything through a tunnel
  • The business gains a clearer view of who is accessing what, which makes both security and compliance easier to demonstrate

This is not a rip and replace

Moving away from a legacy VPN does not mean tearing everything out overnight. In practice it is a transition, and it works best when it is planned around the applications and users that carry the most risk first.

The sensible starting point is visibility: understanding who currently has remote access, what that access actually reaches, and where broad network-level permissions could be narrowed to specific applications. From there, the shift to identity-based access can be staged in a way that fits the business.

How Manux supports your business

At Manux Solutions, we help New Zealand businesses work out whether their remote access is still serving them, or holding them back.

We look at how people connect today, where a traditional VPN is widening your exposure, and what a move toward identity-based access would involve for your environment. The goal is practical: reduce the attack surface, keep access simple for the people who need it, and make sure remote work is not the weakest point in your security.

Take the next step

If your team is working from more places and more devices than your remote access was ever designed for, it is worth reviewing where things stand.

Get in touch with the Manux Solutions team, and we can walk through how your remote access works today and where a shift toward Zero Trust could strengthen it.