SURVEY REPORT · 2023

The State of Zero Trust Security 2023.

Where enterprises are on the road from perimeter to Zero Trust, what is pushing them, and what they are asking for first, from a survey of enterprise IT and security leaders.

Adoption has started. The VPN has not left.

the findings

Zero Trust stopped being a concept and became a programme. Most enterprises surveyed have begun, usually with a few use cases rather than a rebuild, and the reasons are concrete: third parties reaching private applications without control, internet-facing exposure, and a VPN that is both a security concern and a latency complaint. The features asked for first are the ones that verify the person and the device. And the telling number is the overlap: most respondents are running the VPN and a Zero Trust solution side by side, with the intent to finish the move.

86%name unsecured third-party access to private applications as a top concern
63%have started adopting Zero Trust, usually with a few use cases
72%run both a VPN and a Zero Trust solution and intend to move fully
75%are confident Zero Trust will significantly reduce security incidents
  • Third-party access leads the concerns.Contractors and partners reaching private applications without governed access is the risk most respondents want Zero Trust to close first.
  • MFA and device binding lead the shopping list.Of the capabilities asked for, the two that verify the person and tie the account to approved hardware rank highest.
  • Security and latency are the VPN's two problems.Respondents cite both: the concentrator as an exposed target, and the hairpin as a daily cost. The alternative has to fix both.
  • Better security and better experience, together.The benefits sought are not a trade-off. The expectation is that the same change makes access safer and faster.
Cover of The State of Zero Trust Security 2023 survey report

the report

What is inside.

  • Where enterprises are on the adoption curve, and which use cases they started with
  • The security concerns behind the move: third-party access and internet-facing exposure
  • The features buyers rank first: MFA and device binding ahead of everything else
  • Why the VPN is being replaced: security and latency, in that order
  • Confidence in outcomes, and how many are running both models while they migrate

PDF · survey of enterprise IT and security leaders · InstaSafe, 2023

What each finding points to.

The survey asked what enterprises want. These are the parts of the platform that answer each one.

  • THIRD-PARTY ACCESSScoped, time-boxed, recorded access for outside teams: exactly the systems in scope, from devices you do not manage.More
  • MFASix authentication methods, standing alone or inside every access decision.More
  • DEVICE BINDINGEvery account tied to hardware you have approved, through a device certificate.More
  • VPN SECURITYA gateway that stays dark until an authenticated request arrives, and nothing that listens on the public internet.More
  • VPN LATENCYDirect, per-application connections with no hairpin through a concentrator.More
  • RUNNING BOTHThe staged migration: the VPN alongside, application by application, until there is nothing left on it.More
FAQ

the report, answered.

Tap a question. If yours is not here, a specialist can answer it.

Talk to a specialist

//Ready when you are//

The findings, against your own estate.

A 30-minute walkthrough on the three things the survey says everyone is worried about: third parties, unmanaged devices, and the VPN.

Regulated, air-gapped, or on-premise? See deployment options