
The End of the VPN: Why SASE and ZTNA Are the Future of Secure Remote Access in Saudi Arabia
The castle-and-moat model is finished. Why Saudi enterprises are replacing legacy VPNs with SASE and ZTNA for faster, zero-trust remote access under Vision 2030.
The castle-and-moat model is finished. Why Saudi enterprises are replacing legacy VPNs with SASE and ZTNA for faster, zero-trust remote access under Vision 2030.

For decades, corporate security in Saudi Arabia ran on the castle-and-moat model. Staff worked inside a physical office — the castle — and a perimeter firewall — the moat — kept intruders out. Remote workers tunnelled back into the castle through a VPN. Simple, and for its era, effective.
Vision 2030 tore up that map. With giga-projects like NEOM and the Red Sea, and a permanent shift toward hybrid work in Riyadh and Jeddah, the castle doesn't have walls anymore. Users are everywhere. Applications have moved to the cloud. In that world, the traditional VPN has quietly become the weakest link — slow, offering all-or-nothing network access, and sitting near the top of every modern attacker's target list.
So the leading Saudi enterprises are moving to SASE (Secure Access Service Edge) and ZTNA (Zero Trust Network Access). We're deep in that transition with our clients, helping them shift from implicit trust to zero trust.
What ZTNA is: never trust, always verify
ZTNA is a security framework that treats every user and device as a potential threat until proven otherwise. That sounds harsh. It's actually just honest about how breaches happen — the overwhelming majority of serious incidents involve a legitimate credential used illegitimately.
The contrast with a VPN is the whole point. A VPN authenticates you once and drops you onto an entire network segment. Once you're in, you can see a great deal — file shares, servers, systems you have no business reaching. The VPN's job was to get you onto the network, and it does that job faithfully, including for the attacker holding your phished password.
ZTNA grants access to individual applications instead. If an accountant in Dammam needs the payroll software, ZTNA gives them that application and nothing else. They can't see the server room, the R&D files, or the executive directory, because none of it was ever exposed to them in the first place. The applications aren't merely blocked — they're invisible.
This is least privilege in practice, and it's what stops a minor endpoint breach from turning into a company-wide disaster. The attacker who compromises that accountant's laptop reaches payroll and hits a wall everywhere else. On a VPN, that same compromise is a foothold on your whole network.
What SASE is: the architecture that delivers it
If ZTNA is the framework, SASE is the architecture that delivers it. SASE converges two worlds that used to live apart: wide-area networking (SD-WAN) and network security delivered from the cloud. [2]
The practical win is about where inspection happens. Instead of hairpinning traffic from a remote site all the way back to a central data centre — which piles on latency for no security benefit — security happens at the edge, closest to the user.
Consider the everyday case. A user in Jeddah opens Microsoft 365. On the legacy model, that traffic travels to the Riyadh data centre, passes through the security stack, exits to the internet, reaches Microsoft, and returns the same way. Every packet takes a round trip that serves no purpose. Under SASE, the traffic is inspected at a nearby edge point and goes straight to Microsoft. Same policy, same inspection, a fraction of the latency.
As a SASE provider in Riyadh, we deliver this from the cloud, so your people get security and speed rather than being asked to pick one.
Why Saudi businesses are fast-tracking adoption
Interest in SASE and ZTNA across the Kingdom has accelerated sharply, and the drivers are specifically local.
Vision 2030 expansion means organisations are opening sites faster than traditional WAN and VPN designs can absorb. Hybrid work has settled in as a permanent pattern rather than a temporary accommodation. Cloud migration continues across every sector, moving applications outside the perimeter the VPN was built to protect. And NCA expectations keep pushing organisations toward identity-centric, zero-trust architectures.
Put together, they make the legacy VPN look less like infrastructure and more like exposure. [1]
Implementing ZTNA is an architecture project, not a plug-in
ZTNA isn't plug-and-play, and anyone who tells you otherwise is setting you up for a bad rollout.
It takes real architectural work. You map your applications — which is itself revealing, since most organisations discover applications nobody remembered. You define access policies by identity and context: who, on what device, in what posture, for which application. You integrate with your identity provider, because ZTNA without solid identity is a house on sand. And you phase the cutover so users aren't disrupted mid-transition.
Done properly, it's methodical and boring, which is what you want. Done casually, it either blocks legitimate work — and gets rolled back — or leaves gaps, which is exactly the outcome you were trying to escape.
The ITBuilders advantage: dual SASE and SD-WAN specialisations
We're one of the few partners in the region holding dual Fortinet specialisations in both SASE and SD-WAN, and that combination matters more than it might sound.
SASE is the convergence of those two technologies. A provider who understands security but not networking leaves your users crawling through slow connections, and they'll route around the controls to get work done. One who understands networking but not security gives you a fast network with holes in it. Holding both badges means we deliver the convergence the way it's meant to work — fast and secure, not one at the expense of the other.
Frequently asked questions
Does ZTNA completely replace our VPN? In most cases, eventually. Organisations typically run both during transition, moving applications to ZTNA in phases and retiring the VPN once coverage is complete.
Is ZTNA harder for users? Usually it's easier. There's no tunnel to connect, and access is seamless per application. The friction lives in the architecture work, not the user experience.
What if our applications are on-premise? ZTNA works for on-premise applications too, via connectors. It isn't a cloud-only technology — the model applies wherever the application lives.
How does this map to NCA requirements? Zero-trust principles align closely with the direction NCA controls are moving: identity-centric access, least privilege, and segmentation. Adopting ZTNA generally puts you ahead of requirements rather than chasing them.
Future-proofing your perimeter
The traditional network perimeter is gone. Your perimeter now is wherever your employee happens to be sitting. To do well in the Kingdom's digital economy, you need a partner who gets this cloud-native reality — and can build you a borderless, zero-trust enterprise that's quick, flexible, and secure at its foundation.
Contact us for a Zero Trust Readiness Workshop. We'll map your applications and show you how a SASE architecture can replace your legacy VPN in as little as 30 days.
Book your Zero Trust Workshop. Call 920-020-750, email [email protected], or visit itbuilders.com.sa.
Sources & references
Turn this insight into a practical next step.
Discuss your environment with our team and get a clear recommendation grounded in your operational reality.


