By Andrew Beynon, Chief Solutions Architect.
For many years, enterprise networks relied on a basic premise: establish robust perimeters, verify users, assign roles, and allow them to perform their tasks. Firewalls, access control lists, VLANs, VRFS, VPNs, and Role-Based Access Control (RBAC) systems formed the foundation of this strategy.
However, as organisations evolved and began adopting cloud computing, hybrid work practices, BYOD (bring your own device), and the recent surge in IoT prevalence, this model has revealed its weaknesses. The perimeter has dissolved. The network has expanded beyond the walls of the enterprise and, crucially, the threat landscape has become more agile and far, far more persistent. We now live in a world with borderless networks, seemingly the new Wild West.
A Structural Shift in Network Security
I think it’s fair to say that what we’re seeing now is more than just a flash in the pan security upgrade, we are witnessing a structural shift in design implementation and support. The network security is no longer just a connectivity with a policy overlay or a set of standalone appliances. Security is becoming deeply embedded in the network stack itself, and this change is forcing a fundamental rethinking of how access control should work, the control points and methodologies we employ.
Every day, I find myself discussing requirements, solutions, and products. My role as a Network Architect likely drives this, but also because the boundaries related to servers, clients, applications, and security have broadened, significantly expanding the audience. No longer is it just the network teams that consider network security.
Being an Extreme Networks partner and member of their Technical Advisory Council, I have for many months watched their Universal Zero Trust Network Access (UZTNA) capabilities develop. This solution modernises security and transforms our understanding of access, trust, and enforcement within the enterprise. This is not another bolt-on, it’s a bolt-in and fundamental to the ubiquitous security stack we now seek to rely upon.
The Problem with Legacy Approaches
It is unlike traditional network security, which has often been added as an afterthought. You determined the ports, locations, speeds, and necessary transport capacities, then integrated security appliances such as firewalls, intrusion prevention systems (IPS), VPN concentrators, etc., along with various access controls to limit access. In a gardening practice, this would be similar to growing leaves only to trim them back. It was often implemented without proper care or thought; it was neither nurtured nor maintained. In this legacy environment, each technology required its own management interface and policy framework, creating yet another layer of management complexity.
Don‘t get me wrong; these approaches are still applicable. However, they once did jobs, and they did them well. However, the jobs were different, and they weren’t designed with today’s dynamic, cloud-first, work-from-anywhere environment in mind.
A Post-Covid Reality: Networks Without Borders
I suppose one of the positives of the Covid era was that it changed how we work, where we work from, and when we access our data, wherever that now happens to reside. The negative is that the legacy model we once relied upon assumes a relatively static network and predictable user behaviour.
But modern environments are fluid. Users move across locations and devices. Applications span on-premises and multiple cloud providers. Threats originate from both outside and inside the organisation. In this context, traditional perimeter-based models are no longer sufficient, especially when the inside is the new outside and applications and collaboration are elastic.
This is why we are seeing security become embedded in the network stack itself, not as an accessory but as a core feature. In fabric-based architectures, for example, policy enforcement is distributed throughout the network on switches, access points, and virtual edges. Security becomes native to the network, not layered on top.
The Real Meaning of Zero Trust
Enter a world of Zero Trust or should I say Never Trust, Always Verify, where the Zero Trust security model has gained tremendous traction in response to the shortcomings of traditional approaches. For me, this means we should assume the network is already compromised, and we are now merely restricting the attack surface and trying to minimise the risks.
At its core is a simple but powerful principle, never trust, always verify, and permit the least possible amount of access. Where RBAC grants access based on static roles it is often tied to job titles or departments, Zero Trust on the other hand introduces dynamic, context-aware access control. Yes, users identity still matters, but it’s just one attribute among many.
Access decisions depend on several factors, such as:
- Device posture: Is it up to date? Does it have antivirus installed?
- Location: Are you connecting from a recognised safe area?
- Network behaviour: Are you accessing resources at unusual times or showing suspicious patterns?
- Risk scoring: Have your recent actions triggered threat alerts?
In the new world order, Zero Trust environment, every access request is evaluated continuously. This real-time assessment is crucial in modern environments, where lateral movement by compromised accounts or devices can be devastating.
Universal ZTNA
Universal ZTNA represents the intersection of Zero Trust and Network Intelligence. This next-generation ZTNA, Universal ZTNA, integrates identity-based security into the network architecture. In contrast to traditional ZTNA solutions that depend on centralised brokers or cloud gateways, Universal ZTNA spreads enforcement throughout the infrastructure, positioning it nearer to the user, application, and data.
It enables Contextual Access at the Edge where UZTNA does not just authenticate once at login and then forgets. It continuously monitors, allowing the network to revoke or limit access if a device becomes non-compliant or if behavioural anomalies are detected. This access control is applied at the network edge, such as an access point or a switch port, which reduces the need to route traffic back through centralised appliances or cloud security gateways. That is a performance win and a security upgrade.
In contrast to traditional networks that typically use VLANs or ACLs for traffic segmentation, which are static and difficult to scale in complex setups, UZTNA offers dynamic micro segmentation. This technology enforces policies at the individual user or device level, allowing for logical isolation of devices even within the same VLAN or subnet. Consequently, if one device is compromised, lateral movement is restricted.
Unified Policy Management with UZTNA allows for the centralised development of policies along with their distributed enforcement. Administrators only need to define policies once, taking into account elements such as identity, device posture, location, and application requirements; these policies consistently follow users. Whether users access a campus network, connect remotely through a VPN, or utilise cloud resources, the same Zero Trust principles are upheld.
Universal ZTNA leverages the network’s intelligence to deliver comprehensive visibility. Rather than depending on separate monitoring systems, it observes every device, every session, and every anomaly within the network fabric. This enables security teams to detect and respond to threats more quickly and with greater context.
Reassessing Role-Based Access Control (RBAC) as a key element of enterprise security is essential. Despite its popularity, easy management, and alignment with organisational structures, RBAC can be cumbersome due to over-provisioning. Users often receive excessive access because roles are too broadly defined or outdated, complicating the corrective process. Universal ZTNA resolves this by offering dynamic, just-in-time access. Instead of broad access based on job title, it provides precise, conditional access tailored to real-time needs and security conditions.
Security That Moves with You
The rise of cloud services, hybrid work environments, and edge computing is rendering static, role-based security increasingly ineffective. Attackers are becoming more sophisticated, utilising credential theft, exploiting supply chain weaknesses, and employing lateral movement techniques that bypass perimeter defences. By integrating Zero Trust principles into the network infrastructure with technologies like Universal ZTNA, organisations can achieve:
- Agility: Security policies adjust as users and devices transition between environments.
- Granularity: Access control is specific, conditional, and grounded in real-time context.
- Resilience: Micro segmentation and ongoing verification minimise the impact of breaches.
- Simplicity: Unified policy management lowers operational overhead and ensures consistency.
This isn’t merely an evolution; it’s a complete reinvention. We are transitioning from a world where the network served just as a conduit to one where it actively participates in enforcing security policies. Network devices are evolving into smart enforcers that can make decisions typically reserved for centralised security tools.
In the future, the most secure organisations won’t depend solely on edge firewalls or RBAC. Instead, they will rely on the network to assess every access request from every device, at every moment, based on context rather than assumptions. This is the capability that Universal ZTNA provides.
It’s not just Zero Trust, it’s Zero Trust everywhere
In closing, I believe the necessity to consider these changes in security posture is not just industry-driven; they are now being mandated by regulation. The European Union has made it clear that cyber security and digital resilience are not optional. The bar has been significantly raised with the introduction of the Digital Operational Resilience Act (DORA) and the NIS2 Directive.
DORA mandates include:
- Embedding operational resilience into organisational culture.
- Comprehensive ICT risk management frameworks.
- Continuous monitoring of systems and services.
- Direct accountability from executive leadership.
NIS2 requirements include:
- Incident reporting within 24 hours.
- Active supply chain risk management.
- Strengthened governance and cyber resilience across critical sectors.
The move towards integrated, intelligent, and continuously adaptive security architectures is driven not only by evolving threats but also by regulatory necessities and sound business practices. At ARO, we believe that solutions like Extreme’s Universal ZTNA are not only well-suited to this shift; they have been specifically designed for it. Extreme’s Universal ZTNA provides the precise type of granular, policy-driven, real-time access control, and network-native enforcement envisioned by both DORA and NIS2 as essential for modern digital resilience. Again, in this context, adopting embedded Zero Trust access control is not just strategic, it’s a compliance imperative.

With over 25 years in the networking industry, working alongside leading vendors like Cisco, Dell, Aruba, and Extreme, Andrew has led enterprise-scale transformation projects, forging trusted partnerships and delivering strategic initiatives in network architecture, NAC, and Zero Trust (ZTNA).
His deep technical expertise is reflected in his many certifications and commendations within this industry, including nine core Extreme Networks accreditations and his role on their prestigious Technical Advisory Council, a select group of experts who work closely with Extreme’s leadership to shape innovation, guide product strategy, and provide thought leadership across the global networking landscape.
Andrew will join Extreme Networks next week at Extreme Connect, the company’s flagship global user conference, where customers, partners, and industry leaders come together to explore the future of networking. His attendance reinforces a strong, ongoing relationship with Extreme and ensures he remains at the forefront of emerging technologies and industry trends.
By engaging directly with product leaders and peers, Andrew continues to strengthen his ability to help organisations design and deliver cutting-edge networking solutions aligned to their evolving business needs.
