What you need to know
Modern network-access guidance asks organizations to examine broad remote connectivity and compare risk-based, resource-level approaches without assuming every VPN requires replacement.
Potentially affected
Organizations using remote-access VPNs, cloud applications, hybrid networks, partner connectivity, remote administration, operational technology, SSE, SASE, or zero-trust access.
DSE recommendation
Inventory current access, map required resources, assess VPN and modern alternatives, design least-privilege policy, pilot operational behavior, and remove obsolete broad reachability.
A remote-access design created for an on-premises network may grant more reach than a user needs in a hybrid environment. Modernization should begin with required business transactions and risk, not an assumption that a new service category is automatically safer.
What the joint guidance says
Source fact: CISA, FBI, and international partners published Modern Approaches to Network Access Security to help organizations understand vulnerabilities, threats, and practices associated with traditional remote access and VPN deployment, including business risk from misconfiguration.
Source fact: The guidance encourages businesses of all sizes to evaluate approaches such as zero trust, Secure Service Edge, and Secure Access Service Edge. These architectures can provide greater activity visibility and more granular, risk-based access control through policy decisions. The guide addresses hybrid and cloud transitions and considers both IT and operational-technology networks.
The agencies do not state that every VPN is inherently insecure or order every organization to replace one. They call for careful analysis of changing security needs and the risks of broad or misconfigured remote access.
Map access at the resource level
DSE recommendation: inventory every remote-access path, gateway, exposed management interface, VPN product, version, support state, authentication method, user and service identity, reachable route, privileged function, logging source, and emergency dependency. Identify unused paths and access that is broad only because the existing architecture makes narrowing difficult.
- Map users, devices, partners, administrators, and services to the specific applications and transactions they require.
- Document security, privacy, data-location, latency, availability, offline, safety, support, inspection, and logging requirements.
- Compare a hardened retained VPN, resource-level zero-trust access, SSE, SASE, and hybrid combinations against those requirements.
- Define least-privilege and context-aware policy, strong authentication, device expectations, session controls, and independent telemetry.
- Preserve a tested emergency and rollback path that does not silently restore unnecessary broad access.
Pilot the operating failure modes
DSE recommendation: pilot with bounded users and resources. Test ordinary and privileged workflows, unmanaged or noncompliant devices, provider outage, identity outage, policy error, application incompatibility, latency, failover, investigation visibility, help-desk recovery, and rollback. Review denies and exceptions before expanding.
After migration, remove obsolete routes, accounts, gateways, split tunnels, and firewall rules through change control. Continue monitoring vulnerabilities, support status, policy drift, unexpected destinations, and access that no longer has a business owner.
Applicability and limits
SSE and SASE describe architectural approaches, not guaranteed outcomes or certifications. Some environments will retain VPN connectivity because of application, availability, OT, performance, or support constraints. Vendor features and CISA’s dated vulnerability counts can change; use the current KEV catalog and current vendor information for decisions.
Official reference
Modern Approaches to Network Access Security — joint guidance on VPN risk and resource-focused alternatives.
Review the official source
CISA and partners: Modern Approaches to Network Access Security · Published June 18, 2024
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE