Skip to content

Securing a workforce that works everywhere: why zero trust network access has replaced the office perimeter

Latest Insight

A district nurse opens a patient record from a car outside a house in a village with patchy signal. A social worker updates a case file from a family home at eight in the evening. A council officer joins a safeguarding meeting from a shared workspace in another borough. None of them are sitting behind the office firewall, and none of them should have to be.

This is not exceptional, and it is not temporary. It is simply how NHS and local authority work is now delivered, and it has been for several years. Community-based care, integrated working across agencies, and flexible arrangements for office-based staff have all pushed the work outside the building for good.

That creates a tension every public sector organisation has to manage. Staff need to reach the systems that let them do their jobs from wherever the work takes them, and the data they are reaching, clinical records and resident case files, is among the most sensitive any organisation holds. At the same time, assurance expectations continue to rise, from the NHS Cyber Assessment Framework to the governance obligations councils carry for resident data, and those expectations increasingly have to be evidenced rather than asserted. A security model designed for a world where everyone came through the front door each morning cannot resolve that tension. It was built for a different problem.

The hidden risk: the perimeter that no longer exists

The traditional network perimeter rested on a simple assumption. Inside the building meant trusted, outside meant untrusted, and the firewall marked the line between them. It was a reasonable model when the work happened in one place. It stopped matching reality some time ago, and yet a great many networks are still built around it.

Most organisations bridged the gap with a VPN, and it is worth being fair about that decision. It was a sensible answer to the question being asked at the time, and VPNs still have a legitimate role. The weakness lies in how they typically work in practice. A user is authenticated once at the point of connection and then placed on the network with access far broader than their role actually requires. A community nurse who needs two clinical systems may be able to reach a great deal more than that, not because anyone intended it, but because the model grants access to the network rather than to specific resources.

That matters because of what happens when a single set of credentials is compromised. Phishing remains the most common route into public sector organisations, and it does not need to be sophisticated to work. Once an attacker holds valid credentials, broad network access becomes their access, and moving laterally from one system to another becomes straightforward. The scale of the exposure is set not by what the legitimate user needed, but by what the network allowed them.

There is a second gap that receives less attention. Many organisations now apply a stricter standard to remote workers than to anyone plugging into a desk in a hospital corridor or a civic building. A device connecting on campus is often trusted largely because of where it is, which is precisely the assumption that has already failed everywhere else. If location is no longer a reliable indicator of trust outside the building, it is no longer a reliable indicator inside it either.

The practical consequence is an attack surface wider than most organisations intend. Not because of any specific failing, but because the model itself no longer matches how people work.

What zero trust and SASE actually mean

Zero trust is a principle rather than a product, and the principle is straightforward. Nothing is trusted by default, whether it sits inside the building or outside it, and every request for access is verified before it is granted. The shift is from trusting a location to verifying an identity.

Identity-first security is what this looks like in practice. Access is granted to a specific person, using a specific verified device, for a specific resource, rather than to anyone who has managed to reach the network. The community nurse gets the clinical systems her role requires and nothing else. The finance officer gets the finance platform and nothing else. This is what reduces the attack surface in a meaningful way, because a compromised account no longer opens the wider estate. It opens only what that individual role was scoped to reach.

Verifying the person is only half the job. Device posture checks establish that the endpoint requesting access meets defined standards before it is allowed near sensitive systems, so an unmanaged or non-compliant laptop cannot reach clinical or corporate data even when the credentials entered are entirely legitimate. In a sector where staff work across multiple settings and devices, this matters considerably.

SASE is the model that brings network access and security together into a single consistent service, so that protection travels with the user rather than living in a building. Network Access Control extends the same standard to the physical campus, verifying a device plugging into a desk exactly as carefully as one connecting from a car. Taken together, these produce what is often called a unified security fabric, which in plain terms means one consistent security model applied across every edge, rather than one set of rules for people working remotely and another for people working on site.

How TNP approaches this for NHS and local authority organisations

We work as a security consultancy and strategic design partner, implementing zero trust and SASE architectures for public sector organisations. That covers the identity-based perimeter, Network Access Control across the physical estate, and the design work that makes those elements coherent rather than a set of separate additions layered on top of one another.

We design and implement these unified security fabrics on Fortinet technology, and we hold the engineering depth and accreditation to deliver them properly rather than at surface level. It is worth being clear about how we treat that relationship. We remain independent of any single vendor, and we recommend technology on merit against each organisation's requirements. Fortinet is our partner of choice for this work because the platform fits the demands of public sector estates well, not because a commercial arrangement obliges us to lead with it.

Our experience across the NHS and local government runs deep, and that shapes how we deliver as much as what we design. We understand the assurance frameworks both sectors are held to, and we understand the operational reality of introducing a change like this into a live clinical or civic environment. Delivery is phased by site, service, or user group, with continuity protected throughout and clear communication built into the plan, because a security improvement that disrupts frontline services has not improved anything.

This is a long-term partnership rather than a project with an end date. The architecture is maintained, monitored, and evolved as working patterns and threats continue to change.

Bringing it back to what matters

A zero trust approach delivers against all three of the pressures we started with. Staff can work from wherever the job takes them, with access that is straightforward and consistent rather than obstructive. Clinical records and resident data are protected by verified identity and device posture rather than by an assumption about location. And the organisation carries a materially smaller attack surface, so a single compromised credential no longer exposes the wider network.

It also puts leadership in a stronger position. Where access is scoped to role and verified at every request, that can be evidenced in audits and assurance reviews rather than described in general terms. Boards, regulators, and information governance colleagues can be shown a security model that matches how the organisation actually operates.

If you are unsure where your own organisation stands, three questions are a useful starting point. When staff connect from outside the building, are they granted access to the specific systems their role requires, or to a much broader slice of the network than they will ever need. Do we verify the device as well as the person. And does the same standard apply to someone plugging into a desk on site as to someone working from a community setting. The answers usually make the priorities fairly clear.

Frequently asked questions

What is zero trust network access? Zero trust network access is a security model in which nothing is trusted by default, regardless of whether it sits inside or outside the organisation's buildings. Every request for access is verified before it is granted, and users are given access to specific resources rather than to the network as a whole, which limits what any single compromised account can reach.

What is the difference between ZTNA and a VPN? A VPN typically authenticates a user once at the point of connection and then places them on the network with broad access. Zero trust network access verifies both the user and their device at every request and grants access only to the specific resources their role requires. The practical difference is the scale of exposure if credentials are compromised.

What is SASE and do we need it? SASE brings network access and security together into a single consistent service, so protection travels with the user rather than residing in a building. It is particularly relevant to organisations with a substantially distributed workforce, where staff regularly work from homes, vehicles, community settings, and partner premises rather than from a fixed base.

How do NHS organisations secure remote workers? The most effective approach is to verify identity and device posture at every access request and to scope access to the specific clinical or corporate systems each role requires. This replaces the assumption that location indicates trust, and it applies the same standard whether a member of staff is working from a ward, a vehicle, or a patient's home.

Is a VPN still secure for remote access? VPNs still have a legitimate role, but they carry a recognised weakness in that they often grant broad network access once a user is connected. Where sensitive clinical or resident data is involved, an identity-based approach that limits access to specific resources provides a considerably stronger position, particularly against phishing and credential compromise.

What is Network Access Control and how does it work? Network Access Control verifies devices connecting to the physical network, so that a laptop plugging into a desk on site is checked to the same standard as one connecting remotely. It ensures that unmanaged or non-compliant devices cannot reach sensitive systems simply because they are inside the building.

How do I reduce my organisation's attack surface? The most significant reduction comes from moving away from broad network-level access towards identity-based access scoped to each role. When a user can only reach the specific resources their job requires, a compromised credential exposes far less, and the scope for lateral movement across the estate is substantially narrowed.

How do you implement zero trust in the public sector? Implementation begins with understanding how staff actually work and which systems each role genuinely requires, then designing access around those requirements rather than around network location. Rollout is normally phased by site, service, or user group so that clinical and frontline continuity is protected throughout, with clear communication to staff about what is changing.

What does identity-based security mean? Identity-based security means access decisions are made on the basis of who the user is and whether their device meets required standards, rather than on where they are connecting from. Access is granted to specific resources for specific verified users, which is what allows the same security standard to apply consistently across every location.

How do we secure staff working from community settings? Staff working in community settings need verified, role-scoped access that works reliably from anywhere, including locations with variable connectivity. A zero trust approach delivers this by verifying identity and device at each request and granting access only to the systems that role requires, so security does not depend on the member of staff being in a particular place.