From Perimeters to Identity

The Evolution of Private Access

Network transports, access architectures, identity controls and standards evolved in parallel — and most remain in use today.

Technology & architecture Ideas, standards & adoption
  1. Perimeter Era

    Keep threats outside; trust the network inside.

  2. Network technology

    IPsec standardises protected IP traffic

    IPsec brought authentication and encryption to the IP layer, enabling protected host-to-host and site-to-site communication across untrusted networks.

    What changed: Private traffic could cross the public Internet without a private carrier network.

  3. Access technology

    Remote-access VPN becomes the default

    PPTP, IPsec and later SSL/TLS VPNs made encrypted remote access broadly deployable. Users were commonly placed onto the private network, extending its implicit trust to remote devices.

    What changed: The enterprise perimeter stretched to wherever an authenticated user happened to be.

  4. 1997
  5. 1998
  6. 1999
  7. 2000
  8. Defence in Depth Era

    One control will fail, so put another behind it.

  9. Network technology

    MPLS reshapes the enterprise WAN

    MPLS used labels to steer traffic across carrier networks with predictable routing and service quality.

    What changed: Private access became a managed wide-area network rather than isolated sites.

  10. 2002
  11. Identity control

    Network Access Control checks devices

    802.1X introduced port-based authentication. NAC products added device checks before granting access, although admission often still led to broad network reachability.

    What changed: Identity and device state began influencing whether a connection reached the LAN.

  12. Security principle

    De-perimeterisation challenges the castle

    The Jericho Forum argued that cloud services, collaboration and mobile users were dissolving the enterprise boundary. Security needed to move closer to data and systems.

    What changed: The perimeter was recognised as an unreliable basis for trust.

  13. 2005
  14. 2006
  15. Access architecture

    Software-Defined Perimeter hides services

    Work associated with DISA's Black Core initiative helped shape an architecture in which policy brokers authenticate access before protected services become reachable.

    What changed: Authorisation could precede network reachability instead of following it.

  16. 2008
  17. 2009
  18. Cloud Security Era

    Security must follow users, applications and data beyond the corporate network.

  19. Security model

    Zero Trust becomes an explicit model

    Zero Trust gave a name to the principle that network location should not grant implicit trust. Decisions instead consider identity, device state, context and the requested resource.

    What changed: Trust moved from a network property to an evaluated access decision.

  20. 2011
  21. 2012
  22. 2013
  23. Identity Era

    Identity becomes the control plane for access beyond the corporate network.

  24. Field implementation

    Google publishes BeyondCorp

    Google described removing the privileged intranet and using user- and device-aware controls. BeyondCorp demonstrated the model at enterprise scale.

    What changed: Application access no longer had to depend on a traditional VPN.

  25. Network technology

    Software-defined policy reaches the WAN

    SD-WAN applied central policy and dynamic path selection to commodity Internet links, reducing dependence on fixed MPLS circuits.

    What changed: WAN routing became software-directed, application-aware and easier to change.

  26. 2015
  27. 2016
  28. 2017
  29. Assume Breach Era

    Attackers may already be inside; limit movement and impact.

  30. Access architecture

    Mesh overlays remove the central gateway

    Identity-governed overlays established encrypted peer-to-peer paths through NAT, falling back to relays where direct connections failed.

    What changed: Private connectivity could follow identity without backhauling every session.

  31. Architecture model

    Networking and security converge at the edge

    Secure Access Service Edge brought SD-WAN and cloud-delivered security services into one model, placing policy enforcement nearer users and applications.

    What changed: The network path and its security controls could be designed and operated as one service.

  32. Zero Trust Era

    Never trust implicitly; verify every request and limit every connection.

  33. Standard

    NIST defines Zero Trust Architecture

    NIST SP 800-207 defined Zero Trust independently of any vendor and rejected implicit trust based on location or ownership.

    What changed: The industry gained a durable, vendor-neutral vocabulary and logical model.

  34. Adoption catalyst

    Remote work becomes the default overnight

    Mass remote working exposed VPN concentration limits and brittle perimeter assumptions. ZTNA adoption accelerated as organisations needed application access from anywhere.

    What changed: Remote access changed from an exception into a primary access pattern.

  35. Public policy

    Zero Trust becomes federal policy

    US Executive Order 14028 directed federal agencies to plan for Zero Trust Architecture.

    What changed: Zero Trust became a funded transformation programme rather than an optional strategy.

  36. Architecture model

    Cloud security separates from the WAN

    Security Service Edge grouped ZTNA, secure web gateways and cloud access controls as cloud-delivered security, without requiring customers to replace their WAN.

    What changed: Organisations could modernise access and security independently of network transport.

  37. Continuous Verification Era

    A decision made at login is not good forever.

  38. Policy evolution

    Access decisions become continuous

    ZTNA platforms increasingly re-evaluated device posture, identity risk and session context after login instead of treating authentication as a one-time decision.

    What changed: Access could be restricted or revoked as risk changed during a session.

  39. Implementation guidance

    Maturity models broaden the programme

    CISA's model organised progress across identity, devices, networks, applications and data.

    What changed: Adoption became a measured, multi-pillar capability—not a product purchase.

  40. Cloud-native standard

    Zero Trust reaches cloud-native workloads

    NIST SP 800-207A extended the model to application and service identities across hybrid and multi-cloud environments.

    What changed: Workload identity joined user and device identity as a first-class signal.

  41. EU regulation

    Cybersecurity resilience becomes a duty

    The EU's NIS2 Directive required essential and important entities, MSPs among them, to adopt proportionate risk-management measures, including access-control policies — though it applies only once each Member State writes it into its own law, and most were late.

    What changed: Secure access became part of an enforceable resilience and governance obligation across more sectors.

  42. AI & Agentic Identity Era

    Autonomous agents act for users and services; identity must capture authority, delegation and intent.

  43. Emerging practice

    Non-human identities enter access policy

    Ephemeral workloads, service accounts and AI agents increased the need for short-lived credentials and policy based on workload identity rather than a human user.

    What changed: Zero Trust policy began treating machines and autonomous agents as first-class subjects.

  44. 2025
  45. 2026
  46. Now

    Proxies, overlays, microsegmentation and PAM all persist. No single architecture fits every application, protocol or risk model. If comparing them feels difficult, that's because it is.