The Hidden Costs of Sticking With a Legacy VPN

Why Your “Cheap” VPN Is the Most Expensive Line Item You Have

Somewhere out there, a former contractor’s VPN credentials are still active. Nobody revoked them, because nobody remembered they existed. That gap, the space between what a company thinks it decommissioned and what actually still has network access, is exactly the kind of thing a VPN license renewal invoice never captures.

The bill you see for a legacy VPN is the license fee and maybe a support contract. The bill you don’t see shows up scattered across help desk hours, deferred hardware refreshes, and a compliance line item that only gets attention after an auditor flags it. Most small business owners never get that second bill itemized, so they keep budgeting as if the first one is the whole story.

The Bill You See vs. The Bill You Don’t

Diagram

When a CFO or IT lead prices out a legacy VPN, the number they land on is usually the renewal quote. That figure is real, but it isn’t close to complete. Labor, downtime, and incident response rarely show up on the invoice, and those are the costs that actually determine whether a legacy VPN is cheaper to keep than to replace.

Add up help desk hours, patch cycles, and the productivity lost every time a tunnel drops for a remote employee mid-meeting, and the license fee starts looking like the smallest number in the equation. That gap isn’t padding. It reflects three categories of cost that live outside the IT budget line: the people-hours spent keeping the system running, the productivity lost when it breaks, and the exposure it creates just by existing. Each one tends to grow the longer a legacy VPN stays in place, not shrink.

The Help Desk Absorbs a Cost Nobody Labels

Ask most IT managers what their support tickets are about, and VPN issues rarely top the list of complaints out loud. But VPN connectivity problems account for a disproportionate share of small business IT ticket volume in practice: split-tunneling misconfigurations, expired client certificates, MFA prompts that fail on flaky home Wi-Fi, remote employees locked out before a meeting they can’t afford to miss.

None of those are catastrophic on their own. They’re just constant. And constant has a cost that almost never appears anywhere labeled “VPN.” It gets folded into general IT payroll, which is exactly why it stays invisible to whoever is making the renewal decision.

Why the Ticket Volume Keeps Climbing

Legacy VPNs were built for an era when most employees worked from one office, on company hardware, behind a stable connection. Today’s remote and hybrid workforce spreads that same client across home routers, coffee shop Wi-Fi, and personal devices it was never designed to handle. Every added device and network type is another variable that can break the tunnel. That’s part of why the support burden tends to grow rather than level off.

The Security Exposure Is Concentrated, Not Distributed

This is the part that matters more than any ticket count. A VPN, by design, grants broad network access once a login succeeds. There’s no segmentation baked in by default, so one compromised credential can open the door to the whole internal network, not just one application.

Ransomware groups have learned to target that weakness directly. VPN gateways keep showing up as an initial point of entry in breach investigations, because compromising one login gets an attacker further than compromising one application ever would. Attackers aren’t guessing. They know VPN gateways are a single point of failure, and they’ve built their playbooks around that fact.

How Much a Breach Actually Costs a Small Business

The financial fallout from a breach doesn’t land evenly across companies. IBM’s Cost of a Data Breach Report, using 2024 data, put the global average cost of a breach at $4.88 million, a figure that includes large enterprises and skews the average upward. Even a fraction of that is enough to sink a small business with no cushion.

How badly a breach threatens a company’s survival is contested territory. An often-cited figure traced back to a 2012 National Cyber Security Alliance study put the failure rate at 60% within six months of a serious breach. The exact percentage has been debated ever since, and newer data hasn’t settled on one consistent number. What hasn’t changed is the direction of the finding: a meaningful share of small businesses don’t come back from a serious breach at all.

That’s the real risk calculus behind “we’ll upgrade the VPN next year.” Next year is a bet, and the odds aren’t improving on their own.

The Compliance Clock Is Already Running

For businesses in regulated industries or with European operations, there’s a deadline attached to this decision now, not just a preference. The EU’s NIS2 directive raises the bar for network security products, and regulators across member states have started enforcement actions tied to outdated infrastructure. Belgium’s Centre for Cybersecurity has signaled that unsupported, end-of-life network security products fall short of NIS2 expectations, a stance other national regulators are likely to mirror as enforcement matures.

Even outside regulated sectors, an end-of-life VPN creates an audit problem that compounds every year it stays unpatched. Auditors ask harder questions about unsupported software each cycle, and “we’re planning to replace it” stops satisfying anyone after the second or third time it’s said.

Finding VPN Specialists Is Getting Harder

There’s a labor market problem underneath all of this too. As zero trust architectures become the standard reference model taught in newer security certifications, fewer engineers are building deep VPN administration into their core skill set. That makes specialized VPN troubleshooting more expensive to source when a business actually needs it, whether that means paying a contractor’s premium rate or pulling a senior engineer off higher-value work just to keep an aging gateway patched.

That’s a hidden opportunity cost most budgets never account for. Every hour a senior engineer spends babysitting a VPN appliance is an hour not spent on the projects that actually move the business forward.

What Replacing It Actually Costs and Recovers

None of this means a switch away from legacy VPN is free. Zero Trust Network Access platforms typically cost more in year one once licensing, migration, and staff training are factored in. But the cost curve looks different than most owners expect once that first year is behind them.

Businesses that migrate generally report lower ongoing labor costs tied to VPN support, plus the elimination of hardware refresh cycles that legacy appliances require every few years. The upfront cost is real and shouldn’t be waved away, but for most organizations the payback period arrives within a couple of years, not never, and the savings keep accruing after that.

That transition window matters, because it means the first year or so costs more on paper. It also means a business still running the same legacy VPN three years from now has likely paid more in cumulative hidden cost than it would have spent migrating in the first place.

Where Zero Trust Access Fits Into the Picture

The architectural fix for the “one login, full network access” problem is what Zero Trust Network Access was built to solve. Instead of granting broad access once a user authenticates, ZTNA verifies identity and device posture continuously and opens access only to the specific application a user needs, not the whole network behind it. That segmentation is the direct answer to the entry-point risk described above: a compromised credential in a ZTNA environment doesn’t hand an attacker the keys to everything.

NordLayer is one platform built around this model, aimed at small and midsize businesses that want network segmentation and centralized access control without standing up an enterprise-scale security team to manage it. It replaces the all-or-nothing tunnel with access scoped to exactly what each person needs, not the whole network behind it, and enforces that continuously rather than checking identity once at login and trusting everything after.

That former contractor’s VPN credentials, the ones nobody remembered to revoke? Under a segmented, continuously verified access model, a stale login like that doesn’t quietly retain the keys to everything. It retains access to nothing, by design, whether anyone remembers to clean it up or not. That’s the actual bill a legacy VPN keeps sending, and the one a switch to zero trust access is built to stop.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top