IT emergency?+352 20 60 12 44
    Back to the blog
    Cybersecurity
    08 May 2026
    6 min read

    Zero Trust: why VPN alone is negligent in 2026

    One click in the home office, one open VPN tunnel — and the whole network stops. Why classic VPN security is obsolete and what Zero Trust really looks like in SMEs.

    Frank Schenkewitz
    CEO & IT-Security Experte

    A scenario that keeps repeating itself in one form or another across the Greater Region: an employee working from home clicks a link in a seemingly internal email one morning. Their laptop is connected to the company network via VPN — and that single connection is enough. A few hours later, file servers are encrypted, the ERP is down, dispatch is working with Excel and the phone. Days of downtime, substantial damage — and the real problem wasn't the click. It was the architecture behind it.

    The problem: VPN trusts too much

    VPN was a good idea — for 2010. It opens a tunnel, and everything on the other side counts as "inside". Inside means: trusted. Inside means: access to file servers, databases, all internal systems. But a modern attacker only needs a single compromised endpoint with an active tunnel — then they're in, with everything "inside" implies. Ransomware then moves laterally through the network, because it can.

    The idea behind Zero Trust: trust no one, always verify

    Zero Trust is not a product; it's a posture in three sentences: no one gets automatic trust — not the employee in the office, not the CEO in a hotel, not the server in your own data center. Every access is checked individually — who is asking, from which device, in what state, to what? Assume attackers are already inside — so build the network so they can't get any further. It sounds paranoid. It is the realistic answer to the 2026 threat landscape.

    What this really looks like in an SME

    You don't need an enterprise stack with 14 tools. In SMEs, Zero Trust usually rests on three pillars:

    Pillar 1: Identity as the new perimeter. Instead of "who is inside the network", the question becomes: "who is the person, on which device, in what context?" Concretely: Microsoft Entra ID with enforced multi-factor authentication for every login; Conditional Access — a login from Luxembourg at 9:00 is normal, one from Singapore at 3:00 is not; privileged access only time-limited and with extra verification.

    Pillar 2: The endpoint must prove itself. The device is the second key. If the laptop isn't patched, has no running EDR, or shows suspicious behaviour, there is no access — no matter who signs in. Typical building block: Microsoft Defender for Endpoint, combined with device compliance policies and — where needed — a Securepoint UTM as a second line of defence on site.

    Pillar 3: Think of the network in zones. The most demanding but most effective measure: instead of one flat company network, build zones — accounting, production, guests, servers — that may only talk to each other where genuinely needed. In a segmented network, ransomware gets stuck in the first zone instead of encrypting the whole company.

    A realistic roadmap

    This is what adoption looks like in a typical two-site SME: Month 1 — MFA for everyone, Conditional Access for the critical apps, an inventory of "who actually accesses what?". Months 2–3 — roll out EDR, enforce device compliance, clean up old admin accounts. Months 4–6 — segment the network, ZTNA for remote access instead of VPN, centralise logging. After that, the quarterly audit is often a glance at a dashboard instead of a week of paperwork.

    When to start

    Before the call comes. If everything still hangs on one VPN today, plus a domain admin with access everywhere, you are exactly what Zero Trust is meant to replace. The good part: you don't have to do everything at once — setting up MFA and Conditional Access within four weeks already reduces your risk noticeably. The rest comes in stages.

    Let's talk for 30 minutes

    The free Zero Trust quick check: no sales pitch, but an honest assessment of where you stand and the two or three most important steps for your company. — 📞 +352 20 60 12 44 · 📧 mail@local-it-partner.lu

    Tags:
    Zero Trust
    IT security
    MFA
    Ransomware
    VPN

    Questions about this topic?

    We are happy to advise you personally on Cybersecurity and other IT topics.

    Matching services from Local-IT-Partner