Remote access grows by accretion: a VPN for contractors, another for a legacy ERP, a third “temporary” tunnel that outlives the project. Sprawl is rarely a tooling failure. It is an ownership failure—nobody owns the catalogue of paths, expiry dates, or the standard that new requests must meet.
Mid-market organisations can consolidate without a multi-year zero-trust programme if they sequence identity and device posture first, prefer application-level access where it fits, and write down when a full-network VPN still belongs. This guide reflects how Calystron approaches remote-access rationalisation with IT and security leads.

Why VPN sprawl happens
Each exception feels cheaper than a standard. A vendor needs a quick tunnel. A team prefers a familiar client. A legacy system only works “on the network.” Months later you have overlapping profiles, unclear MFA coverage, and logs nobody correlates during an incident.
- No inventory of remote paths with named owners
- Temporary exceptions without expiry or review
- Full-network VPN used for apps that only need one HTTPS service
- Separate contractor and employee stacks that drift out of policy sync
Consolidate first, then harden
Hardening a mess multiplies work. Catalogue paths before you buy another gateway. Then put strong checks in front of high-risk apps and retire duplicates on a written schedule.
- Inventory every remote path—VPN profiles, jump hosts, vendor tunnels, and “temporary” reverse proxies.
- Classify by user class: employee, contractor, vendor, break-glass admin.
- Put MFA and device posture in front of high-risk apps before adding new tunnels.
- Prefer application-level access for SaaS and internal web apps; reserve full-network VPN for systems that require it.
- Retire duplicate profiles with named owners and change windows.
Identity and posture before network membership
Membership on a flat VPN often grants more than the ticket requested. Identity-aware access asks who the user is, whether the device meets policy, and which application they need—before opening a wide network path.
Start with privileged and customer-impacting applications. Expand to lower-risk tools once the pattern is operable. Device posture does not need to be perfect on day one; it needs to be enforced on the routes that matter most.
A minimal remote-access standard
- One primary pattern per user class, documented in the IT handbook
- MFA required for all remote interactive access
- Exceptions logged with owner, reason, and expiry date
- Central logging readable by both security and IT operations
What “done” looks like
Done is not “zero VPN.” Done is a short list of sanctioned patterns, a shrinking exception register, and the ability to answer who accessed what when something looks wrong.
- One primary remote-access pattern per user class (employee, contractor, vendor)
- Documented exceptions with expiry dates—not permanent special cases
- Logging that security and IT can both read during an investigation
- A quarterly review that retires unused profiles and expired exceptions
Sprawl returns the moment exceptions are cheaper than standards. Treat remote access like any other estate control: sequenced, owned, and reviewed.
Frequently asked questions
Is zero-trust the same as removing all VPNs?
No. Zero-trust is a set of access principles—verify explicitly, least privilege, assume breach—not a ban on tunnels. Many organisations keep a constrained VPN for legacy protocols while moving web apps to identity-aware access.
How do we handle vendor remote access without another VPN profile?
Prefer time-boxed, identity-brokered access to specific applications or jump hosts with MFA, session logging, and an expiry date. If a vendor tunnel is unavoidable, register it as an exception with an owner and review date.
What should we inventory first?
Start with production and admin paths: VPN profiles that reach domain controllers, ERP, jump hosts, cloud consoles, and any “temporary” reverse proxy. Low-risk tools can wait until the high-risk catalogue is clean.
How long does consolidation usually take?
A credible first pass—inventory, MFA on high-risk apps, and a retirement plan for duplicates—often fits a ninety-day window for mid-market estates. Full legacy elimination can take longer and should be sequenced, not rushed into outages.
Own the catalogue
Remote access is estate control. Sequence identity and posture, prefer application access where it fits, keep VPN where it still earns its keep, and make exceptions expensive to renew. That is how sprawl stops growing.
Calystron helps organisations map remote paths, design identity-first standards, and retire unsafe exceptions without theatre. If your VPN catalogue has outgrown its owners, start with an access inventory and a ninety-day consolidation plan.
