Cybersecurity
Zero Trust Security 2026: Why VPNs Are Getting Ripped Out
In May 2026, Palo Alto Networks confirmed something security teams had been dreading for years: attackers were actively exploiting an authentication bypass flaw in its GlobalProtect VPN software. Within days, the Qilin ransomware crew had a foothold. Two weeks later, Shadowserver counted more than 167,000 exposed GlobalProtect instances still sitting online, unpatched, waiting.
This is the story behind the headline number everyone in zero trust security keeps quoting: a market racing from $48.43 billion in 2026 to a projected $102.01 billion by 2031, according to Mordor Intelligence. But the growth curve isn’t the interesting part. What’s interesting is what’s forcing it, and it’s playing out on live infrastructure right now.
Table of Contents
- The $102 Billion Number, and Why It’s Actually a Range
- Why This Is Happening Right Now
- The Perimeter Is Failing on Schedule
- What Zero Trust Actually Means
- The Money Is Already Moving
- The Case Against Zero Trust Hype
- Frequently Asked Questions
The $102 Billion Number, and Why It’s Actually a Range
Ask three analyst firms how big the zero trust security market is, and you’ll get three different answers, none of them wrong, all of them measuring slightly different things.
| Source | 2026 Estimate | 2031 Projection | CAGR |
|---|---|---|---|
| Mordor Intelligence | $48.43B | $102.01B | 16.07% |
| KBV Research | n/a | $101.39B | 16.1% |
| Allied Market Research | n/a | $126.02B | 18.5% |
The spread, roughly 25% between the low and high end, comes down to scope. Some firms count only software and licensing. Others fold in professional services, managed detection, and identity infrastructure that touches zero trust without being sold as a “zero trust product.” Treat $102 billion as the working consensus figure and the range as a footnote, not a red flag.
What all three agree on: this isn’t a niche category anymore. Global information security spending overall is projected to hit $244.2 billion in 2026, up 13.3% year over year, per Gartner’s most recent forecast analysis. Zero trust is eating a growing slice of a budget that’s already growing.
Why This Is Happening Right Now
Three things converged in the space of about 90 days that turned “zero trust” from a slide-deck buzzword into an urgent line item.
First, breach costs hit a record high. IBM’s 2026 Cost of a Data Breach Report, built on 602 breached organizations across 17 countries and interviews with more than 3,550 security and C-suite leaders, put the global average breach cost at $4.99 million, up 12% year over year. In the United States, that average climbs past $11.5 million, more than double the global figure. AI-driven attacks were up 56% year over year and added roughly $1 million to the cost of a breach when present.
Second, the industry’s own attack data flipped. For the first time in 19 years of reporting, Verizon’s 2026 Data Breach Investigations Report found vulnerability exploitation, not stolen credentials, was the number one initial access vector, responsible for 31% of breaches, up from 20% the year before. Buried inside that number is the statistic that matters most for this story: edge devices and VPNs jumped from 3% to 22% of exploitation-driven breaches. A sevenfold increase in a single year.
Third, it’s not theoretical. While that report was still fresh, ransomware operators were actively exploiting authentication-bypass flaws across four separate perimeter appliance vendors in the same window: Palo Alto GlobalProtect, Fortinet FortiGate, Citrix NetScaler, and Check Point’s VPN gateway. Median time to patch a known-exploited vulnerability had also risen to 43 days, up from 32 the year before, and only 26% of critical vulnerabilities on CISA’s Known Exploited Vulnerabilities list got patched inside the study window.
Put those three together and the pitch writes itself: the exact device category that’s supposed to guard the perimeter is now the preferred way in, and it’s costing record money when it works.
The Perimeter Is Failing on Schedule
The GlobalProtect case is worth walking through because it shows the whole failure loop in miniature. Palo Alto patched CVE-2026-0257, an authentication bypass rated 7.8 on the CVSS scale, on May 13, 2026. Rapid7 confirmed active exploitation had already begun by May 17. CISA added it to the Known Exploited Vulnerabilities catalog on May 29, with a three-day remediation deadline for federal agencies. Arctic Wolf Labs later tied exploitation of the flaw to the Qilin ransomware-as-a-service operation.
Four days from patch to active exploitation. That’s the entire window organizations had to close the gap before it became a live incident, and most didn’t.
It wasn’t an isolated event. Around 75,000 internet-facing FortiGate firewalls were swept up in a parallel campaign nicknamed “FortiBleed.” A Check Point VPN flaw tied to deprecated IKEv1 configurations and a CitrixBleed-style NetScaler bug were both under active exploitation in roughly the same period. Four vendors, one attack pattern, one quarter.
This tracks a pattern that goes back further than 2026. The original CitrixBleed incidents in 2023 and 2024, and the Ivanti exploitation chain before that, established the same lesson: perimeter appliances sit in slow patch cycles, they’re internet-facing by design, and they’re an unusually efficient target because compromising one grants broad network access rather than a single user’s session.
“Traditional IAM systems, built for humans, struggle to manage this explosion of non-human identities, blurring the line between trusted and untrusted entities.”Mick Leach, Field CISO, Abnormal AI, via SecurityWeek
Leach’s point matters here because it’s not just user VPN sessions that are exposed. Site-to-site connections, partner integrations, and service accounts running behind these same appliances rarely get the same scrutiny as employee logins, and that’s exactly where a lot of the 2026 campaigns landed.
What Zero Trust Actually Means
Strip away the marketing and zero trust is a fairly plain idea: don’t trust a user, device, or application just because it’s inside the network. Verify continuously, based on identity, device health, and context, instead of granting broad access once at the perimeter and assuming everything after that is safe.
The reference architecture is NIST SP 800-207, published in 2020 and still the standard vendors and federal agencies cite in 2026. CISA’s Zero Trust Maturity Model, currently at version 2.0, breaks implementation into five pillars:
- Identity, continuous verification of who’s requesting access
- Devices, checking the health and posture of the requesting device
- Networks, segmenting traffic instead of one flat trusted zone
- Applications and Workloads, securing access at the app layer, not just the network edge
- Data, classifying and protecting data regardless of where it sits
Three cross-cutting capabilities tie the pillars together: visibility and analytics, automation and orchestration, and governance. In June 2026, CISA published an updated guide in its “Journey to Zero Trust” series to help federal civilian agencies migrate off legacy TIC 2.0 perimeter architectures toward the newer TIC 3.0 and SASE-supported models, the most recent official movement on the government side.
The Money Is Already Moving
Analyst projections are one thing. Actual revenue is another, and here the numbers back up the forecast instead of just feeding it.
Zscaler, a pure-play zero trust vendor, reported Q2 FY2026 revenue of $815.8 million, up 26% year over year, with annual recurring revenue at $3.36 billion, up 25%. Palo Alto Networks, taking the platform-consolidation route rather than the pure-play one, saw its Next-Generation Security ARR reach $6.33 billion in the same quarter, up 33% year over year, then climb to $8.13 billion, up 60% year over year, by Q3.
Almost two-thirds of organizations globally have fully or partially implemented a zero trust strategy, according to a Gartner survey of 303 security leaders. Of those, four in five say they have metrics in place to measure whether it’s actually working.
Our read: the fact that Palo Alto, a company that also sells the appliances getting exploited, is growing its zero trust revenue faster than its pure-play competitor says something. Enterprises aren’t necessarily ripping out every vendor relationship. They’re demanding that existing vendors prove they’ve moved past the perimeter model.
The Case Against Zero Trust Hype
No serious security leader thinks zero trust is a silver bullet, and the person who arguably built the framework’s modern reputation is also its sharpest internal critic.
“Security is not a product, but a combination of strategy, process, and execution. Zero Trust is not just an architecture, it’s a mindset. There is no Zero Trust product, period.”Dr. Chase Cunningham (“Dr. Zero Trust”), creator of the Zero Trust eXtended framework, former Principal Analyst at Forrester, via drzerotrust.com
Cunningham’s argument, echoed across multiple interviews, isn’t that zero trust doesn’t work. It’s that the market around it has splintered into thousands of overlapping vendor tools all marketed as one-stop “zero trust” fixes, and organizations chase the label instead of the architecture. Passing an audit or buying a badge, in his framing, is the floor, not the ceiling.
Gartner’s own analysts have made a related, more specific warning: attackers are shifting toward vectors zero trust controls don’t fully cover, including public-facing APIs, social engineering, and policy workarounds employees create themselves to get around strict access rules. Is that a reason to skip zero trust? No. But it’s a reason not to treat it as complete coverage.
Cost is the other honest limitation. In that same Gartner adopter survey, three in five organizations that implemented zero trust said they expect costs to rise, not fall, and two in five expect staffing needs to increase. That directly undercuts any pitch that frames zero trust as a savings play. It’s a risk-reduction investment, not a budget cut.
What This Means If You’re Running Security
If you’re a CISO or infrastructure lead, the budget conversation has quietly shifted from “should we do zero trust” to “which pillar are we weakest in,” and CISA’s five-pillar model doubles as a ready-made audit checklist. Expect more internal scrutiny of VPN and firewall patch cadence specifically, given the 43-day median patch time against a four-day exploitation window in the GlobalProtect case.
If your organization still runs internet-facing VPN concentrators or SSL-VPN gateways as the primary remote-access control, that’s not a hypothetical risk anymore. It’s a documented, current pattern across four major vendors. Replacing appliance-based remote access with identity-aware access is the specific fix for the specific gap attackers used in 2026.
Non-human identity is the piece most implementations still miss. Service accounts, bots, and AI agents now operate inside enterprise networks at a scale traditional human-focused IAM and MFA was never built for, and that’s precisely where AI agent adoption is accelerating fastest.
Frequently Asked Questions
What is zero trust security?
Zero trust is a security model built on “never trust, always verify.” No user, device, or application is trusted by default, even inside the traditional network perimeter. Access is continuously verified using identity, device posture, and context. NIST SP 800-207 remains the reference standard.
Why are companies moving away from VPNs?
Verizon’s 2026 DBIR found edge devices and VPNs accounted for 22% of exploitation-driven breaches, up from 3% the year before, a sevenfold jump. Active 2026 ransomware campaigns exploited authentication-bypass flaws in Palo Alto, Fortinet, Citrix, and Check Point VPN appliances.
How big is the zero trust security market?
Estimates vary by analyst firm. Mordor Intelligence projects the market reaching $102.01 billion by 2031, up from $48.43 billion in 2026. Other firms estimate as high as $126.02 billion by 2031, depending on scope and segmentation methodology.
Is zero trust worth the cost?
Gartner surveys found three in five adopters expect costs to rise after implementing zero trust, and two in five expect higher staffing needs. IBM’s 2026 data shows the average breach now costs $4.99 million globally, $11.5 million in the US, which most CISOs weigh against that up-front investment.
What are the five pillars of zero trust?
CISA’s Zero Trust Maturity Model defines five pillars: Identity, Devices, Networks, Applications and Workloads, and Data, supported by three cross-cutting capabilities: visibility and analytics, automation and orchestration, and governance.
Who invented zero trust?
The term and concept are credited to John Kindervag, who introduced zero trust as an analyst at Forrester in 2010. NIST formalized the architecture in SP 800-207 in 2020.
Where This Goes Next
Here’s what’s different about 2026 compared to earlier zero trust hype cycles: the evidence now runs in both directions at once. The market data says adoption is mainstream, not niche. The breach data says the thing zero trust replaces is failing in real time, at scale, across every major perimeter appliance vendor. Those two data sets rarely line up this cleanly.
Over the next 6 to 18 months, watch three things. First, whether CISA’s federal deadlines slip again, agencies have a track record of missing them, and Gartner has previously predicted a majority of federal agencies would fail to fully implement zero trust on schedule due to funding and staffing gaps. Second, whether non-human identity management, the gap Mick Leach flagged, becomes its own funded category rather than a bolt-on to existing IAM tools. Third, whether the vendors currently getting exploited, Palo Alto, Fortinet, Citrix, Check Point, can out-patch the four-day exploitation windows that defined this year’s incidents.
None of this means zero trust is finished the day it’s deployed. It means the alternative, standing perimeter hardware as your primary defense, has a documented, current, multi-vendor failure record. That’s a harder thing to argue with than a market forecast.
Want the next breach report and vendor exploitation update before your competitors see it? Subscribe to The Neural Loop at neuralwired.com/newsletter.
