Zero Trust Security Architecture
Zero Trust for Remote Work: Securing Distributed Workforces
Zero trust for remote work replaces VPN with direct, secure, per-application access. Key capabilities: strong identity verification (MFA regardless of location), device health assessment (managed and patched before access), per-application access (not broad network), location-independent policies (same security at home, office, or coffee shop), direct-to-cloud access (no VPN hairpinning), and continuous session monitoring. Zero trust is inherently location-agnostic — the same controls apply whether the user is in the office or at home.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
Remote Work Broke the Perimeter
The shift to remote and hybrid work didn't just stress the traditional security perimeter — it made it irrelevant. When users, data, and applications are distributed across homes, offices, cloud providers, and SaaS platforms, the concept of a "trusted internal network" no longer applies.
Organizations that pivoted to remote work during 2020 experienced this firsthand: VPNs buckled under load, split-tunnel configurations created security gaps, and users began accessing cloud applications directly — bypassing security controls entirely.
Why VPN Fails for Remote Work
Architecture Mismatch
VPN was designed for a different era — when applications lived in the data center and users occasionally worked remotely. In a cloud-first, remote-first world:
- Bandwidth bottleneck. All remote traffic routes through the data center VPN concentrator, creating congestion
- Hairpin routing. Users access cloud applications by VPNing to the data center, then routing back out to the cloud — doubling latency
- All-or-nothing access. VPN grants broad network access, not granular application access
- Poor user experience. Connection drops, slow performance, split-tunnel complexity
- Scaling challenges. VPN infrastructure wasn't designed for an entirely remote workforce
Security Gaps
- Once connected to VPN, users have broad network access — mimicking "inside the perimeter"
- Compromised VPN credentials grant the same broad access to attackers
- Personal devices on VPN extend the trust boundary to unknown endpoints
- VPN doesn't assess device health before granting access
Zero Trust Remote Access
Location-Agnostic Security
Zero trust doesn't distinguish between office and remote users. The same verification applies everywhere:
- Identity verification. MFA required regardless of location
- Device assessment. Device health checked regardless of network
- Contextual evaluation. Location, time, behavior analyzed for risk
- Per-application access. Specific resource access, not network access
- Continuous monitoring. Session monitored for anomalies throughout
Whether a user is at company headquarters or a home office, the security posture is identical.
Direct Application Access
Instead of routing through VPN to reach cloud applications:
- Users authenticate to the identity provider
- Access is verified and authorized for the specific application
- Connection is established directly to the application (cloud or on-premises)
- No data center routing, no VPN tunnel, no bandwidth bottleneck
For on-premises applications, a ZTNA connector/broker provides secure access without exposing the application to the internet.
Device Trust for Remote Devices
Remote devices are diverse — company laptops, personal devices, phones, tablets. Zero trust assesses each device:
- Managed devices:
- OS version and patch status verified
- Endpoint protection running and current
- Disk encryption enabled
- Company security policies enforced
- Full application access granted (conditional on compliance)
- Unmanaged/BYOD devices:
- Limited access through browser-based (agentless) ZTNA
- No company data stored on device
- Access restricted to specific applications
- Virtual desktop infrastructure (VDI) for sensitive workloads
- Non-compliant devices:
- Access denied until remediation (patching, enabling encryption)
- Or limited to low-sensitivity resources (email, chat)
- Self-service remediation guidance provided
Secure Collaboration
Remote work depends on collaboration tools — video, chat, file sharing, document editing. Zero trust for collaboration:
- SSO integration for all collaboration platforms
- DLP policies preventing sensitive data sharing in unauthorized channels
- Conditional access restricting collaboration tool access based on device and risk
- Session monitoring for unusual data sharing patterns
Home Network Security
Zero trust acknowledges that home networks are untrusted — and designs accordingly:
- Encryption everywhere. All traffic encrypted end-to-end, regardless of network
- DNS security. Cloud-based DNS filtering for remote devices
- Endpoint protection. Security on the device, not the network
- No network trust. Access decisions based on identity and device, never network location
Hybrid Work Model
For organizations with both office and remote workers:
- Consistent controls. Same zero trust policies whether in-office or remote
- No VPN for office users. Office network treated as untrusted (same as remote)
- Location-aware policies. Office location may reduce friction (fewer MFA prompts) but doesn't eliminate verification
- Flexible device policies. Support both managed and BYOD devices with appropriate access levels
How SeqOps fits
Zero trust starts with knowing where you're exposed. SeqOps gives you that view for your cloud accounts and servers: misconfigurations, excessive access and unpatched software, ranked by severity. It doesn't enforce access policies.