If your team is working remotely and you’re running a traditional VPN, it’s probably doing its job. For a 5-person office, a VPN is a perfectly reasonable solution. But once you start adding employees, contractors, cloud apps, and shared credentials, that VPN starts to show its limits โ€” and most businesses don’t realize it until something goes wrong.

This post breaks down what Zero Trust Network Access (ZTNA) actually is, how it compares to a traditional VPN, and how to know when it’s worth making the switch.


What a VPN Actually Does (And Where It Falls Short)

A VPN creates an encrypted tunnel between a remote user and your network. Once connected, that user typically has broad access โ€” file shares, internal apps, sometimes everything on the subnet.

That made sense when offices were physical and everyone inside the building was trusted by default. It works less well when:

  • You have contractors or temporary staff who only need access to one or two systems, not your whole network
  • An employee’s laptop gets compromised โ€” their VPN session gives the attacker the same access they had
  • Your team uses a mix of SaaS apps and on-prem systems, so the VPN tunnel adds latency without adding much protection
  • You’re using a shared VPN credential that never gets rotated

A frustrated employee waiting on a slow VPN connection

For small offices โ€” say, under 15 users with a stable team โ€” these issues might never surface. A well-configured VPN with MFA and limited subnet access is often good enough. The problems tend to compound as the team grows and the environment gets more complex.


What Zero Trust Network Access Does Differently

ZTNA flips the model. Instead of “connect to the network, then access resources,” it’s “prove who you are and what device you’re on, then get access to this specific app or system โ€” nothing else.”

The core difference: the network perimeter disappears. There’s no tunnel to the whole subnet. A user gets access to exactly what they need โ€” Salesforce, your internal billing system, a specific file share โ€” and nothing more. Every session is verified. Access can be scoped by user, device health, location, and time of day.

The practical effects for a growing small business:

  • A contractor gets access to the project management tool and nothing else
  • A compromised device triggers a policy check and gets blocked before it can move laterally
  • Remote employees connect directly to cloud apps without VPN hairpinning, so performance improves
  • Offboarding is cleaner โ€” revoke access at the identity layer, not by hunting down VPN credentials

Secure server infrastructure with ZTNA access controls


Cloudflare Access: A Realistic Option for Small Business

Enterprise ZTNA platforms can be expensive and complex to deploy. Cloudflare Access is a notable exception โ€” and it just got more accessible.

Cloudflare Access is free for up to 50 users and integrates with your existing identity provider (Microsoft Entra ID, Google, Okta) without requiring you to replace your existing infrastructure. Cloudflare recently announced that dashboard SSO is now available on any plan โ€” not just enterprise โ€” and GitHub login for the Cloudflare dashboard was added at the same time. They’ve also committed to making future feature releases self-service by default rather than holding them back for enterprise customers.

For a business running Microsoft 365 and Entra ID, this makes Cloudflare Access a realistic starting point with no upfront cost commitment. It’s not click-and-done โ€” you need to publish internal apps through Cloudflare’s tunnel, configure access policies, and set up your identity provider correctly โ€” but it’s well within reach for a team with the right IT support.

For a full breakdown of what Cloudflare’s free tier actually covers for small businesses, see our separate post: What Cloudflare’s Free Tools Actually Cover for a Small Business.


When to Make the Move

You don’t need ZTNA on day one. Here’s a simple way to think about it:

Stick with a well-configured VPN if:

  • You have fewer than 15 users and a stable, known team
  • All your critical systems are on-prem and access is managed tightly
  • You have MFA enforced and VPN credentials are per-user, not shared

Start planning for ZTNA if:

  • You’re regularly onboarding contractors or temporary staff
  • You’ve moved most of your workloads to SaaS or cloud (Microsoft 365, Azure, AWS)
  • You’ve had a security incident โ€” or a near miss โ€” related to excessive access
  • You’re approaching 20โ€“30+ employees and access management is getting messy

The practical path is usually: clean up and document your current VPN setup now, then plan a ZTNA migration as part of your next IT roadmap cycle. You don’t have to rip and replace โ€” many businesses run both in parallel during the transition.


How LineSight Digital Can Help

We work with Bay Area businesses at every stage of this journey โ€” from getting a solid VPN in place for a 5-person office to planning a Zero Trust rollout for a team that’s outgrown what it has.

If you’re not sure where your current setup stands, our IT Assessment is a good starting point. We’ll look at your remote access setup, document what you have, and give you a clear picture of your risk and your options.

You can also use our IT Cost Estimator to get a ballpark on what a network security upgrade might cost for your team size.

Questions? Get in touch โ€” we’re based in San Jose and work with businesses across Silicon Valley.