412-444-7768Careers
Pittsburgh · Since 198924/7 Monitoring
Back to Blog
October 6, 2026

VPN vs Zero Trust (ZTNA): What Firms With 50 to 500 People Should Do

CybersecurityLatest blog
William Palmer
William Palmer6 min read
Stay Ahead of Downtime

IT and security insights for manufacturers — straight to your inbox.

VPN vs Zero Trust (ZTNA): What Firms With 50 to 500 People Should Do

Why zero trust is the safer choice for a 50 to 500 person firm, what it costs per user, and how to move off your VPN in about a quarter.

Stay Ahead of Downtime

IT and security insights for manufacturers — straight to your inbox.

VPN vs Zero Trust: Which Should You Choose?

For most firms with 50 to 500 people, the answer in the VPN vs zero trust debate is zero trust. The VPN box that faces the internet is one of the first doors attackers try. Zero trust lets you close that door for a few dollars per user each month. Plan the move over about a quarter, and keep a VPN only in the few places it still belongs.

A VPN lets remote staff onto your whole office network once they sign in. Zero trust network access, or ZTNA, connects each person only to the apps they need, and checks the person and the device every time. That is the core idea in NIST's federal zero trust guidance.

  • Reach: Zero trust opens only the apps you approve. A VPN opens the whole office network.
  • Exposure: Zero trust leaves no VPN door at your office facing the internet. A VPN leaves a box you must keep patched.
  • Checks: Zero trust checks the person and the device every session. A VPN checks once, at sign-in.

Why Are VPN Gateways Such a Common Way In?

One flaw in the VPN box can open your whole network, and attackers often use those flaws before a fix exists. That turns the box into a race you cannot always win, even with a careful IT team.

Cyber insurer Coalition says 58% of its 2024 ransomware claims started with a hacked VPN or firewall. The federal cyber agency CISA keeps a list of flaws attackers have already used. That list includes 60 flaws in the firewall and VPN boxes sold by Fortinet, Cisco, Ivanti and Palo Alto Networks. Half of them were used in ransomware attacks.

When Ivanti's boxes were hit in early 2024, CISA ordered federal agencies to disconnect every one and rebuild it. Your office firewall stays and still needs patching. Zero trust removes the VPN login page your remote staff use today. On Monday, ask your IT provider which VPN box you run and when it was last patched.

Where Does a VPN Still Belong?

A VPN still belongs in three narrow places, and none of them is a reason to put off the move.

  1. Your offices can stay linked. A site-to-site VPN, the always-on link between two of your own offices, is a different tool and can stay.
  2. Plant machines may still need one. Federal guidance says a plant machine that must be reached from outside should stay off the open internet. That VPN should need a physical security key or similar multi-factor authentication (MFA) to get in. So a plant may keep one small VPN for its machines, while office staff, managers and sales move to zero trust.
  3. A short bridge is fine. A small group can stay on a patched VPN with MFA until their apps have moved.

Everyone else, from the office manager to the field engineer, is better off on zero trust.

What Does Zero Trust Cost?

Zero trust costs a few dollars per user each month, and you can pilot it for nothing on Cloudflare's free plan. If your Microsoft 365 plan supports it, Microsoft's version, Entra Private Access, costs $5 per user per month. For 120 people, that is roughly $7,200 a year. That is small next to an average ransomware claim of $269,000 at insurer Coalition in 2025.

Start with Microsoft's version if your plan supports it, and with Cloudflare if it does not. Our Microsoft 365 services team can check your plan, and we can price WolfCare, our own zero trust service, beside both. If your VPN runs on its own separate box, retiring it also ends that box's yearly support fee.

How Do You Move Off a VPN Without Disrupting Work?

Treat the VPN replacement as a project of about a quarter, moving one team at a time while the VPN keeps running. Nobody loses access on a Monday morning, and Wolf can run the whole move for you.

  1. Turn on MFA for the VPN now, for staff, contractors and vendors.
  2. List who connects from outside and which apps they use.
  3. Move one team and one app first, then fix what the pilot turns up.
  4. Move everyone else in waves, then switch the VPN off.

Wolf moved its own staff to zero trust first, with a product from Duo, then set up the same thing for a client. After that, a stolen Wolf password alone could not reach our files, because they opened only on Wolf computers.

What About Vendors Who Support Plant-Floor Equipment?

Treat outside vendors like your own staff, with their own login, MFA, and access to only the machine they support. CISA warns that giving vendors remote access without strict limits adds risk to your network.

Federal guidance for plant equipment asks that remote access be limited to the specific machine and the person's job. It also asks you to switch off accounts nobody uses. Our short note on ransomware in manufacturing explains why ransomware crews target plants. On Monday, ask your plant manager which vendors can connect today, and how.

Questions Owners Ask Before Replacing a VPN

In short, a VPN carries risks that MFA cannot fix, and zero trust costs a few dollars per user.

Is a VPN still secure in 2026?

Only if it is patched fast and someone watches for new flaws every week. Even then, there may be no fix to install. Mandiant's investigators found that three of the four flaws attackers used most in their 2024 cases were hit before any fix existed.

If our VPN already has MFA, are we safe?

You are safer, so keep it while you move. Some VPN flaws let attackers skip the login completely, as one of Ivanti's did in January 2024. Our engineers have also seen accounts taken over with MFA turned on.

"MFA is a great tool, but it's not an end-all, be-all."

Cliff Lashawn, vCTO Technical Services Manager at Wolf Consulting

What will our cyber insurer ask about remote access?

Expect to confirm MFA on every remote path, including contractors and outside vendors. Travelers' 2023 MFA form asks whether MFA is required for "all remote access to the network," contractors and service providers included. Once every path runs through zero trust with MFA, that answer becomes a clear yes.

Is zero trust too expensive for a firm our size?

No, and here is what most firms pay per user each month:

  • A pilot team under 50 users: free on Cloudflare's free plan.
  • Microsoft 365 Business Premium, E3 or E5: $5 for Microsoft's version.
  • Other Microsoft 365 plans: $7 for Cloudflare's paid plan, billed yearly, or $12 for Microsoft's version once you add the Entra ID P1 license it requires.

Can we run the VPN and zero trust side by side?

Yes, and you should while you move. Shrink the VPN group as each team moves, then switch the VPN off.

Where Should You Start?

Start this week by listing everyone who connects from outside, and what they reach. That list shows how big the move is and who goes first.

Send the list to our cybersecurity services team, and we can tell you which option fits and what it costs. Get our free guide, Cybersecurity From Zero, which covers what insurers ask, or book a call. You can also call us at 412-444-7768.

Wolf provides managed IT and security to firms across Pennsylvania, Ohio and West Virginia from our Monroeville office. If AI tools are next on your list, our four steps to becoming an AI-powered business begin the same way, with a list of what is already in use.

Source note: our count of CISA's catalog on September 30, 2026 covers Fortinet FortiOS (including five entries CISA files under "Multiple Products"), Cisco ASA, Ivanti Connect Secure (including its older Pulse name) and Palo Alto Networks PAN-OS. You can check it in CISA's public data feed.

Wolf Consulting
Want to see if we’re a fit?

Schedule a no-pressure consultation with our team.

Get started
Get Started

Step into a safer, Stronger Business.

When you’re ready to move beyond “good enough,” we’re here to help. Reach out to schedule a no-pressure consultation and find out whether we’re a fit.