Datanet » NEWS AND EVENTS » Industry Trends » Access is the new security perimeter. Why organizations are moving to Zero Trust and Cisco Secure Access
Access is the new security perimeter. Why organizations are moving to Zero Trust and Cisco Secure Access
Acces securizat de oriunde cu Cisco Secure Access și Zero Trust

Access is the new security perimeter. Why organizations are moving to Zero Trust and Cisco Secure Access

In recent years, some of the most costly cyberattacks in the world did not start with the exploitation of a zero-day vulnerability, but with the authentication of a legitimate user. A VPN account without MFA, a few compromised credentials, or an exposed remote service were enough to shut down oil pipelines, hospitals, and entire factories. Colonial Pipeline, the Irish Health Service, and University Hospital Düsseldorf are all on the list of attacks carried out by exploiting legitimate access that was insufficiently protected. In Romania there are no public cases, but that does not mean they do not exist. When users work from any location and applications are distributed between the cloud and data centers, access has become the new security perimeter. This is also why standards such as NIS2, ISO 27001, and ENISA recommendations place so much emphasis on securing privileged access and on multi-factor authentication.

For organizations in Romania, this shift is no longer just a technical discussion, but a compliance one. NIS2 requires demonstrable access control, multi-factor authentication, and continuous visibility over every user and every access point — precisely the areas where classic VPN-based models prove insufficient.

In this context, a Zero Trust architecture such as Cisco Secure Access becomes a natural answer, and its correct implementation makes the difference between a solution that works on paper and one that stands up to a real audit. Datanet Systems, the leading Cisco partner in Romania, with over 25 years of experience in integrating complex solutions for critical infrastructures, delivers exactly this correct implementation — from architecture to access policies aligned with NIS2 requirements.

Securitate Zero Trust pentru forța de muncă distribuită

From "breaking in" to logging in: how cybercriminals attack today

The shift happened gradually, but irreversibly. A decade ago, the IT world was simple: users worked from the office, applications ran on-premises, and a firewall was enough to secure the perimeter. Everything that mattered was inside, everything dangerous stayed outside, and compliance usually meant an annual audit.

Today, none of these assumptions hold. Remote work, SaaS applications, cloud infrastructure, hybrid environments, personal devices (BYOD), and access granted to partners and third-party vendors have dissolved the classic network boundary. The perimeter, as we knew it, simply no longer exists.

The VPN — the technology most organizations built their remote access on — was not designed for this context. Once connected through a classic VPN, a user typically gets access to an entire network segment, not just the application they need. The model relies on implicit trust: if you have authenticated, you are considered trustworthy for the entire session. Granular segmentation is hard to implement, continuous device posture verification is almost completely absent, and the user experience suffers, especially when tunnels have to be brought up manually.

Zero Trust – the new model for secure access

The industry’s answer to this reality is called Zero Trust, a model built on a simple principle: “never trust, always verify”. No access request is considered safe just because it comes from an internal network or because the user successfully authenticated an hour ago.

Cisco Secure Access, the gateway to Zero Trust

At the foundation of the journey to Zero Trust, Datanet places Cisco Secure Access, a cloud-native Security Service Edge (SSE) platform delivered entirely from the cloud, with no appliances to maintain at each location.

The difference from a VPN is most visible in the architecture. A VPN grants access to the network; Zero Trust Network Access (ZTNA) grants access only to the application. In Cisco Secure Access, ZTNA is complemented by a Secure Web Gateway for protecting internet access, a Cloud Access Security Broker (CASB) for controlling SaaS applications, Firewall-as-a-Service capabilities for uniform policies, and Digital Experience Monitoring for visibility into the user experience. All of these components integrate with the rest of the Cisco ecosystem — Duo for MFA, Secure Client, Secure Firewall, XDR, and Talos — which means one platform, one access policy, and one dashboard, instead of eight or nine point solutions, each with its own console.

From a technical standpoint, corporate devices can connect through three Cisco Secure Client modules — classic VPN, ZTNA, or web roaming — while unmanaged devices belonging to contractors or partners access resources through Clientless ZTNA, directly from the browser, with SAML authentication. The ZTA module uses a technology called Socket Intercept: traffic is intercepted at the socket level, directly in the kernel, before it reaches the classic routing layer (Layer 3), and a QUIC tunnel comes up automatically, without user intervention. Each device receives a unique certificate, stored in a TPM or hardware enclave, which cannot be exported or copied. This way, authentication combines the identity of the user with the identity of the device — not just a password.

Cisco Secure Access – the main components

Component What it does
ZTNA (Zero Trust Network Access) Application-level access, not network-level; continuous session verification
Secure Web Gateway Protects internet access and enforces security at the DNS/web level
CASB (Cloud Access Security Broker) Visibility and control over the SaaS applications used by employees
Firewall-as-a-Service Uniform security policies, delivered from the cloud
Digital Experience Monitoring Monitors performance and the user experience
Data Loss Prevention (DLP) Prevents the leakage of confidential data, including into generative AI applications
AI Access Guardrails Controls what information users feed into or extract from ChatGPT, Gemini, etc.
Integration with the Cisco ecosystem Duo (MFA), Secure Client, Secure Firewall, XDR, Talos

Cisco Secure Access: simplicity for users, efficiency for IT

For the end user, the promise is simple: an identical work experience, whether they are in the office or thousands of kilometers away, with no manually established tunnels and no added friction. For IT teams, the advantage is operational: fewer VPNs to administer, fewer physical appliances, a single policy console, global scaling without additional hardware investments, and, over time, fewer security incidents caused by inconsistent configurations across different tools.

The platform also provides visibility into the applications actually used across the organization, including shadow IT, with automatic risk scores for every SaaS application, granular action-level control (for example, access allowed to Gmail but uploads blocked, or access to Dropbox with downloads disabled), and Data Loss Prevention mechanisms that recognize patterns of confidential information, including when it is entered into generative AI applications such as ChatGPT or Gemini.

From securing the network to securing identity

Cisco Secure Access also makes an important positive contribution to alignment with the NIS2 Directive, which is no longer satisfied with a working firewall; it requires active risk management, demonstrable access controls, multi-factor authentication, continuous visibility, and the ability to report incidents within strict timeframes: an early warning within 24 hours, a notification with a severity assessment within 72 hours, and a final report within 30 days. Failure to meet these obligations can result in fines of up to 10 million euros or 2% of global turnover, plus the personal liability of management.

These requirements map directly onto the Zero Trust architecture. Access control is covered by ZTNA, multi-factor authentication through the integration with Cisco Duo, the least-privilege principle through application-level access, and identity management through context-based policies. Secure remote access is also delivered through ZTNA, visibility through a centralized dashboard, and logs can be integrated with existing XDR or SIEM solutions. Third-party access gets dedicated policies, and consolidating security tools into a single platform reduces the organization’s attack surface by eliminating publicly exposed VPNs.

When applications are distributed across private data centers, public cloud, and SaaS services, and users work from any location, the network is no longer the center of the infrastructure. User identity becomes the new security perimeter. Organizations that continue to rely exclusively on VPNs and traditional access models take on an ever-greater risk, while adopting a Security Service Edge and Zero Trust architecture provides finer-grained access control, extended visibility, and a superior level of protection against modern threats.

The right implementation matters as much as the right technology

A Zero Trust architecture that looks good on paper loses its value if it is configured incorrectly or only partially adopted. This is where the implementation partner’s experience comes in. Datanet Systems has over 25 years of experience integrating complex IT solutions for industries such as banking, telecom, air traffic control, retail, manufacturing, and the public sector, and is the first and longest-standing Cisco partner in Romania, with the largest market share and the largest team of Cisco-certified specialists in the country. For an organization evaluating a migration to Cisco Secure Access, exactly this kind of expertise in networking and security technologies makes the difference between a correct configuration, aligned with NIS2 requirements, and one that leaves gaps undiscovered until the first incident or audit.

For more information about how Cisco Secure Access works and how you can use this solution in your organization, contact us at sales@datanets.ro.