---
title: 'Secure remote access (zero trust)'
url: 'https://triplepoint.org.uk/security/network/remote-access'
markdown: 'https://triplepoint.org.uk/security/network/remote-access.md'
date: '2026-09-28'
description: 'Zero trust secure remote access for UK businesses. Give staff access to the applications they need from anywhere, without a VPN opening up your whole network.'
---

# Secure remote access (zero trust)

The riskA traditional VPN connects a remote user to your whole network. If their password is stolen or their laptop is infected, the attacker gets the same access.

VPN devices facing the internet are also a favourite target for attackers, who scan constantly for ones that haven't been updated.

 What it does- Gives each person access to specific applications, not the whole network
- Keeps your applications invisible to the internet, so only authorised users can find them
- Checks identity with multi-factor authentication
- Checks the device is healthy, and automatically blocks one with an active threat
- Access to web applications, remote desktop (RDP) and SSH from a secure browser
- A gateway built into every Sophos Firewall, or available separately

 Who it's forBusinesses with staff who work from home but need systems in the office, businesses replacing an ageing VPN, and anyone who needs to give a contractor access to one system without giving them everything.

 How we supply itBy default we supply the licence and you (or your IT provider) deploy it. If you'd rather hand the whole job to us, we can configure and install it for you at our standard day rate — scoped and agreed with you up front, and invoiced separately.

 What's under the hood**Sophos ZTNA** — part of Sophos Workspace Protection, using the Sophos Protected Browser, and managed from Sophos Fusion. A ZTNA gateway is built into every Sophos Firewall.

 Questions What's wrong with a VPN?+Nothing, if it's well maintained and the people using it are trusted. The problem is that it gives access to the whole network, so one stolen password or infected laptop can reach everything. Zero trust access limits each person to what they need.

 Do we need a Sophos Firewall?+No. The gateway is built into Sophos Firewall if you have one, but it can also run separately.

 Do we have to move our applications to the cloud?+No. It's designed for applications that stay where they are, in your office or data centre, and makes them reachable only by the people who should be using them.

[← Back to Protect your network](https://triplepoint.org.uk/security/network)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Secure%20remote%20access%20%28zero%20trust%29) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Network security](https://triplepoint.org.uk/security/network.md)
- Previous: [Next-generation firewall](https://triplepoint.org.uk/security/network/firewall.md)
- Next: [Secure Wi-Fi & switching](https://triplepoint.org.uk/security/network/wifi-and-switching.md)
