The VPN quietly ran remote work for two decades. It has now become the door attackers knock on first, and the fix isn't a newer tunnel.

On July 24, 2026, CSO Online reported ransomware operators were hammering the vulnerable VPN and network-edge appliances that keep remote work running behind the scenes, with one group exploiting an authentication-bypass flaw in a widely used VPN gateway while parallel campaigns probed firewalls and remote-access controllers across the industry. For anyone who has managed remote access, the pattern is familiar and exhausting: a critical flaw surfaces, a patch ships, and defenders race the clock before attackers get there first. According to Verizon's 2026 Data Breach Investigations Report, exploitation of software vulnerabilities has, for the first time in 19 years, overtaken stolen credentials as the top way into a breached organization, accounting for 31% of breaches. The reflex is to patch faster, and that instinct is sound, yet speed alone cannot fix a surface that was exposed by design. The VPN was built to extend a perimeter that no longer describes where work happens, and its always-on tunnel into the corporate network has become one of the most attractive entry points attackers have. There's a more durable way to think about access, and it's one Island has been building toward for years.
For two decades, the VPN did exactly what we asked of it. It stretched the corporate network out to wherever an employee happened to be sitting, and for a workforce that was mostly inside the building with a few travelers dialing in, that model made sense. Then the building emptied out. Work moved to SaaS, to unmanaged devices, and to home offices, while the VPN kept doing the one thing it knows how to do, which is drop a remote user onto the internal network and trust them once they arrive.
That trust is exactly what attackers have learned to exploit. The same Verizon report found that edge devices, including VPN gateways, accounted for 22% of the breaches that began with exploitation, up from roughly three percent a year earlier, close to a sevenfold jump in a single year. These aren't obscure targets. They sit at the internet's edge, they're reachable by anyone, and a single unauthenticated flaw can hand over a foothold inside the network. The July campaigns reported by CSO Online are the predictable result: when an appliance is both exposed to the internet and trusted by the network, it becomes the front door worth breaking down.
.png)
The natural objection is that a well-run VPN, promptly patched, is perfectly safe. It's a fair point, and in a world where remediation kept pace with exploitation it might even hold. That world no longer exists. According to the same Verizon research, the median time to remediate a known exploited vulnerability has grown to 43 days, up from 32, and only 26% of the vulnerabilities on the CISA Known Exploited Vulnerabilities catalog were fully remediated by the organizations studied, down from 38% the year before.
Meanwhile, attackers move in hours, sometimes even faster with the advent of AI-enabled exploit kits. The edge appliances themselves illustrate the mismatch: in early 2025, Cybersecurity Dive reported that critical, actively exploited flaws in a widely deployed VPN product were added to the CISA catalog within months of each other, used by a state-linked espionage group before many organizations had patched. Espionage and ransomware are different missions, but the lesson holds either way. When the window to exploit is measured in minutes or hours and the window to remediate is measured in weeks or months, patching speed is not a contest you can win. The exposure is structural, and structural problems need structural answers.
Here is the reframe worth sitting with: the problem isn't the VPN protocol or any single vendor's appliance, it's the premise that access should be granted to a network at all. Swap an aging VPN for a shiny new gateway and you've moved the choke point, not removed it. Trust still hinges on network location, and location tells you nothing about who the user really is or whether their device is safe.
This is the shift NIST described years ago in Special Publication 800-207, its foundational guidance on zero trust. Static, network-based perimeters are insufficient, NIST wrote, because once an attacker is inside, lateral movement goes largely unhindered. The proverbial “blast radius” can become the entire network, not just the compromised device or system. The Verizon data shows how that plays out in practice: half of ransomware victims experienced a credential-compromise or infostealer event within 95 days before the attack. Get onto the network, move laterally, and the perimeter you trusted becomes the thing working against you.
Island starts from the opposite premise. Rather than tunneling a user onto the network and trusting them, Island verifies identity, device posture, network/geolocation, and session context, then routes access to only the specific applications that user is entitled to. Those context-aware, granular policies run where work actually happens, across the browser, the desktop, and the network, so access no longer depends on dropping anyone onto a broad corporate tunnel.

The principals behind zero trust were sound—identity-driven, least-privileged access—and they still hold. But identities alone are insufficient. Human identities provide context on group membership and permissions, but what about non-human identities assigned to agentic AI sessions? The policy enforced when the user is connecting from a trusted network location shouldn’t be the same one used when that device/user connects from a WiFi hotspot at a Starbucks. The only way to ensure effective data protection is to leverage dynamic policies that adapt to changes in context.
Nowhere does the network-tunnel model do more damage than with contractors and third parties. According to Verizon's 2026 report, third-party involvement now factors into 48% of breaches, a 60% jump year over year. Not all of those run through a VPN, but the pattern is consistent: outside users need access, the fastest way to grant it is a tunnel, and every tunnel widens the blast radius. Beazley Security's Q3 2025 threat report, covered by the HIPAA Journal, found compromised VPN credentials were the initial access vector in 48% of the ransomware claims it handled that quarter, up from 38% the prior quarter.
The alternative becomes concrete when access is verified at the point of work instead. Landis+Gyr, a global energy technology company, faced exactly this problem, with roughly 400 contractors from about 80 different suppliers, each needing access to specific systems. Using Island, the company consolidated that sprawl into what it calls one door, a single controlled entry point where access is scoped to the application and governed at the executable level rather than handed out as network reach. Global VPN usage fell by 80%. A contractor gets precisely the access and data protection their work requires and nothing more, while the enterprise gains visibility and control it never had when everyone shared the same tunnel.
Step back and the through-line is clear. The appliances at the edge will keep getting exploited, because anything both exposed to the internet and trusted by the network will always be worth attacking. What can change is whether that exposure stays the enterprise's exposure. When access control is embedded where people actually do their work, across the browser, the desktop, and the network, a compromised gateway stops being a master key to everything behind it. This is the shift NIST pointed to when it moved defenses away from static network perimeters, and it's the shift the last two decades of remote access have been quietly demanding. The VPN earned its place in an era when work lived inside a building, and now that work has moved on, access and granular data protection must move with it.
Is a ZTNA gateway enough to replace a VPN?
It's a step, but on its own it can relocate the problem rather than solve it. A gateway still concentrates access at a piece of infrastructure that has to be reachable, maintained, and patched, and it still tends to grant reach into network segments rather than specific applications. The more durable model verifies the user and device and scopes access to the exact resource at the point of work, so there's no broad network reach to inherit in the first place.
We patch our VPN promptly. Isn't that enough?
Diligent patching genuinely reduces risk, and it's worth doing well. But the industry data shows remediation timelines running into weeks while exploitation happens in hours, so even a strong program leaves a window open. Reducing how much you depend on an internet-facing tunnel shrinks the consequences of that window, no matter how fast your team moves.
Does retiring the VPN mean ripping out our whole remote-access stack at once?
No, and framing it that way tends to stall good decisions. Most organizations start by moving their highest-risk access, such as contractors, third parties, and privileged sessions, off the broad tunnel first, then reduce VPN reliance over time. The aim is architectural change at a sensible pace, not a disruptive rip and replace.
How is contractor access different under this model?
Instead of issuing a VPN client that drops an outside user onto your network, you grant access to specific applications after verifying who they are and what device they're using. Access is scoped, logged, and revocable in one place, which is why organizations consolidating dozens of suppliers describe the result as a single controlled door rather than hundreds of tunnels.
If you're rethinking what comes after the VPN in your environment, we're happy to walk through how Island verifies and routes access at the point of work. Schedule a demo: https://www.island.io/schedule-demo