RealVNC logomark

RealVNC Viewer

Productivity

icon close circle

Zero Trust Cannot Stop at the Point of Access

Contents

Emerging Threats in Remote Access Security

Why privileged remote access needs protection from the first access decision to the final endpoint

Security teams do not need another reminder that the threat landscape is changing.

What they may need is a better way to judge whether their current controls are actually working.

The 2026 RealVNC® Emerging Threats in Remote Access Security report surveyed 323 IT professionals across seven industries. Nearly half, 47%, said their organisation had experienced a remote access security incident in the past 24 months.

More concerning is what happened when confidence was compared with outcomes.

Among respondents who described themselves as very or extremely confident in their current remote access security, 55% had still experienced an incident.

That disconnect matters because remote access is becoming more important at exactly the same time the environments surrounding it are becoming more distributed, interconnected, and difficult to govern.

Third-party vendors need access. Administrators need access. Engineers need access to plant systems and operational technology. Hybrid work has expanded where connections originate. Legacy devices remain in production long after the architectures around them have changed.

The security question is no longer simply: Can this person connect?

It is: Should this person connect, to this specific resource, from this device, under these circumstances, with these permissions, for this amount of time?

And once that decision has been made: How is the connection to the endpoint itself controlled and secured?

That is where Zero Trust and secure remote access meet.

Organizations understand Zero Trust. Implementing it is another matter.

Zscaler defines Zero Trust around a simple principle: no user, device, workload, or system should be inherently trusted simply because it sits inside a network. Every request should be verified, and access should be limited to only what is necessary. Its model emphasises identity and context, adaptive controls, segmentation, direct resource access, and continuous verification.

RealVNC’s research found that 58% of respondents consider implementing Zero Trust architecture a top priority.

Yet only 28% have actually implemented it.

That gap between intention and execution is one of the defining findings of the research.

The issue is not a lack of awareness. It is the complexity of turning that intent into consistent controls.

The same study found that 85% of organisations use two or more remote access tools. Among organisations using just one remote access tool, 28% reported an incident. Among those operating four to five tools, that figure rose to 67%.

More tools do not automatically produce more security.

In some environments, tool proliferation creates more credentials to manage, more policies to reconcile, more configuration points to maintain, and more opportunities for gaps to emerge.

That is why Zero Trust needs to be understood as an architecture rather than another security product added to the stack.

Zero Trust changes what access means

Traditional remote connectivity has largely been built around network access.

A VPN establishes a path into an environment, after which security controls attempt to determine what the user can do from there.

ZTNA changes that model.

Instead of granting broad network access, Zero Trust Network Access evaluates identity, device context, policy, and the resource being requested. Access can then be granted specifically to that application or service while preventing unnecessary lateral movement. RealVNC’s own explanation of ZTNA notes that this differs substantially from traditional remote access, which is focused on allowing someone to interact directly with a workstation or endpoint desktop.

That distinction is important.

A privileged user may successfully pass every identity and policy check required to reach an application or remote resource.

But eventually, somebody may still need to interact with an actual machine.

  • An administrator may need to control a server.
  • An external engineer may need to troubleshoot an HMI.
  • A vendor may need to service production equipment.
  • A support technician may need to remotely operate a workstation.

At that point, the security challenge has moved from whether access should be granted to how the authorised interaction with the endpoint should occur.

From Zero Trust architecture to the last mile

This is where Zscaler and RealVNC address complementary parts of the same privileged access problem.

At the access layer, Zero Trust principles can determine whether a user should be permitted to reach a particular resource at all.

That can include identity verification, device and contextual checks, least-privilege policy, segmentation, time-limited access, and prevention of unnecessary lateral movement.

At the endpoint layer, secure remote access must then provide the connection that allows an authorised user to interact with the machine.

RealVNC describes remote access as serving that endpoint interaction, while ZTNA creates the identity- and context-based access boundary around the resource.

The distinction becomes particularly important when privileged access extends beyond conventional cloud applications into servers, industrial systems, engineering workstations, and operational technology.

Register for the Zscaler and RealVNC Joint Webinar – Securing Privileged Remote Access: Zero Trust from Landscape to Last Mile

Live Webinar | September 24th | 11:00 AM EDT · 60 min

Register for the webinar here. 

NCSC guidance brings this exposure into sharper focus

Recent guidance from the UK’s National Cyber Security Centre makes the issue much more immediate.

The NCSC says it has observed increased targeting of operational technology systems across multiple sectors, including activity that has resulted in limited real-world disruption. It specifically warns organisations not to assume OT systems are inaccessible from the internet without verifying that assumption. Misconfigurations, legacy connections, and unmanaged assets can all create unintended exposure.

Its recommendations include strengthening administrator authentication, enabling MFA where supported, strictly controlling access from external or untrusted networks, maintaining supported remote access appliances, monitoring connectivity into and within OT, and segmenting OT, management, and business networks.

That guidance is broader than remote access alone. No single vendor or technology solves every part of it.

It does, however, reinforce a central point:

Privileged remote access cannot be treated as a simple connection between two machines.

Identity, authorisation, network exposure, segmentation, session security, monitoring, and endpoint control all matter.

Manufacturing shows how wide the Zero Trust gap can become

The problem is particularly visible in operational environments.

RealVNC’s research found that 74% of manufacturing respondents identified Zero Trust as a top security priority.

Only 29% had implemented it.

At the same time, manufacturing reported a 53% remote access incident rate, while 56% said platform upgrades were being deprioritised. Budget and lack of skilled personnel were major obstacles.

The challenge is not a lack of intent. It is the combination of ageing infrastructure, constrained budgets, and limited specialist capacity.

Security teams understand the architectural direction they need to take, but the environments they are protecting may contain legacy infrastructure that cannot simply be replaced or taken offline.

The result can be partial modernisation: a stronger identity layer added to one part of the environment, an existing remote access tool retained elsewhere, and legacy systems left in place because production cannot stop.

The intention may be Zero Trust, but the operating reality can still be a collection of access paths built at different times, for different purposes, and under different security assumptions.

That is precisely why securing privileged remote access end to end matters.

Confidence is not the same as assurance

Perhaps the most important finding in RealVNC’s research is not simply that incidents are common. It is that organisations experiencing them often believe they are already well protected.

The report describes this as the confidence paradox.

Security teams may measure how many controls have been deployed, how many audits have been completed, or how many security tools are in place.

Those are useful operational measures, but they are not necessarily evidence that the architecture will hold under real-world conditions.

The study found that 55% of highly confident respondents had still experienced a remote access incident. Among CIOs and CTOs who described themselves as very or extremely confident, that figure reached 77%.

The implication is that a Zero Trust strategy should do more than add authentication controls. It should reduce assumptions:

  • Do not assume that being inside the network makes someone trustworthy.
  • Do not assume that authentication alone means the user should reach every resource.
  • Do not assume that granting access means the resulting remote session is automatically secure.
  • And do not assume that a large security stack means every remote access pathway is equally governed.

From landscape to last mile

This is ultimately why the relationship between RealVNC and Zscaler is important.

The problem spans more than one layer.

Zscaler’s Zero Trust approach focuses on verifying users, devices, context, and access requests before granting the minimum access required. Its framework is designed to reduce implicit trust and limit lateral movement.

RealVNC focuses on the remote interaction with the endpoint itself, where an authorised administrator, engineer, or support professional needs to securely operate the system.

One helps govern whether and how the resource is reached.

The other helps secure the interaction with the machine once the authorised connection reaches it.

That combination is what it means to think about privileged remote access from the security landscape to the last mile.

Learn more on this topic

Control your Raspberry Pi from your phone or tablet. Follow our step-by-step guide to setting up remote access with RealVNC...
Improving IT service delivery starts beyond ticket closure. Find the bottlenecks, measures, and handoffs shaping user trust - and the...
Need to access your Mac from a Windows PC? Follow our step-by-step guide to setting up secure, cross-platform remote access...

Try RealVNC® Connect today for free

No credit card required for 14 days of free, secure and fast access to your devices. Upgrade or cancel anytime