Five Reasons Your Organisation Needs ZTNA, And Why Now.

July 8, 2026

Share:

Zero Trust Network Access has been a topic in security circles for long enough that many IT teams have heard the pitch. The question most of them are actually asking isn’t whether ZTNA is a good idea in theory — it’s whether the case for change is strong enough to justify the disruption of doing something about it.

Here are five concrete reasons the case has moved from “interesting” to “urgent”.

1. Cyber Insurers Are Starting to Require It 

The cyber insurance market has hardened significantly since 2021. Insurers have responded to rising claims costs by tightening their requirements — and the questionnaires they send to prospective policyholders reflect the technical controls they now expect to see in place.

Multi-factor authentication is now a near-universal requirement. Endpoint detection and response is increasingly expected. And more recently, a growing number of insurer questionnaires are asking explicitly about remote access controls, specifically whether access is limited to what each user needs (least-privilege), whether device compliance is checked before access is granted, and whether remote access relies solely on VPN.

Organisations that cannot demonstrate modern access controls are seeing higher premiums, reduced coverage, or, in some cases, difficulty obtaining cover at all. ZTNA is no longer just a security improvement. It’s increasingly becoming a commercial necessity for most organisations.

The 2025 IBM Cost of a Data Breach Report adds urgency: 16% of breaches now involve attackers using AI — most commonly AI-generated phishing (37% of AI-driven attacks) and deepfake impersonation (35%). IBM previously found that generative AI cut the time to craft a convincing phishing email from 16 hours to five minutes. The attack volume this enables is not theoretical.

2. Your Attack Surface Has Changed 

The attack surface most organisations are managing today looks nothing like the one their security architecture was designed for. The workforce is hybrid. Applications are distributed across cloud platforms and SaaS services. Contractors, suppliers, and partners access internal systems alongside employees.

VPN was designed for a world where the network perimeter was a meaningful boundary. In 2026, it isn’t. Every VPN credential is a potential pivot point for an attacker — and once through, a flat network gives them room to move.

ZTNA addresses this structurally. By granting access at the application level rather than the network level, it limits what any single compromised credential can reach. An attacker who obtains a valid login still can’t access systems they’re not authorised to use. Lateral movement becomes significantly harder.

3. The NCSC Has Given You a Framework 

The National Cyber Security Centre’s Zero Trust Architecture guidance — published in 2021 and updated in 2023 — provides a clear, practical framework for moving toward a ZTNA model. It isn’t prescriptive about which product to use, but it is clear about the principles: verify explicitly, use least-privilege access, and assume breach.

For public sector organisations, alignment with NCSC guidance isn’t optional. It’s expected — and increasingly referenced in procurement specifications, security assurance requirements, and audit frameworks. Government bodies that can demonstrate a coherent response to the NCSC ZTA guidance are in a materially stronger position than those that cannot.

The NCSC guidance is built around seven architecture principles: know your architecture and identities, assess device and user health, use policies to authorise every request, authenticate and authorise everywhere, monitor users and devices continuously, and trust no network — including your own. Each one maps to a gap that VPN leaves open.

4. The User Experience Argument Has Flipped 

For years, the objection to replacing the VPN was partly a UX argument: users know how it works, they’ve learned to tolerate the friction, and rolling out something new creates support overhead. That argument has expired.

Modern ZTNA implementations are transparent to the end user. The FortiClient agent connects automatically when a user accesses a protected application; there’s no manual connect step, no choice of server, and no disconnection to manage. For the user, it simply works. The experience is typically faster than VPN because traffic is not hairpinned through a central gateway.

The support burden associated with VPNs, such as troubleshooting connection failures, managing client updates, and resetting credentials, is a real and often underestimated cost. ZTNA reduces it.

5. You Can Start Without a Full Programme 

One of the more persistent myths about ZTNA is that it requires a large, multi-year transformation programme before any benefits are realised. That’s not how it works in practice.

A ZTNA implementation can begin with the highest-risk access scenarios — external contractors accessing sensitive systems, privileged users with broad access rights, and applications that are currently exposed to the internet — and expand progressively. Each application migrated from VPN to ZTNA reduces your attack surface immediately.

For organisations already running Fortinet infrastructure, the path is much shorter. FortiClient EMS and the ZTNA capabilities built into FortiOS mean the technical components are either already deployed or can be activated without new hardware. The work is configuration and policy design — not infrastructure procurement.

The most effective starting point is also the lowest-commitment one: a structured readiness assessment that tells you exactly where your current model leaves gaps and what a realistic migration looks like for your environment.


Syntura offers a free Zero Trust Readiness Assessment that is scored across seven dimensions, mapped to NCSC guidance and comes with no obligation. Most organisations complete it in under an hour. 

Get your free assessment → Get in touch →