NordLayer
Remote access without building a network to reach
NordLayer provides secure remote access as a subscription rather than as hardware. Users connect to a managed gateway, the organization is given a fixed address it can allow at the applications it protects, and access is granted per user and per resource rather than by admitting somebody to the whole network. This brief covers what that model does well, what it does not attempt, and how to judge whether it fits.
Executive summary
Traditional remote access places an appliance at the office and has staff connect back to it. That works while the office is the centre of the estate. It works poorly once the applications have moved to cloud platforms, because traffic travels to the office only to turn around and go back out.
The subscription model inverts this. The gateway is operated by the vendor, staff connect to the nearest one, and the organization receives a stable address it can use as a condition of access at each application. No hardware is bought, and the office stops being a bottleneck for people who no longer work there.
Takeaway: the question is where your applications live, not where your people are.
Why the fixed address matters more than the encryption
Encryption between a laptop and a gateway is commodity. Every product in this category does it competently, and on a modern web application the traffic was already encrypted anyway.
The genuinely useful property is a dedicated address. Given one, an organization can tell a cloud application to accept connections from that address and refuse everything else. A stolen password then stops being sufficient, because the attacker is not coming from the permitted address.
That turns a remote access product into an access control, which is a different and considerably more valuable thing.
Takeaway: buy this for the allow list it makes possible, not for the tunnel.
The approach in practice
Deployment is a client application and a directory connection. Staff sign in with the identity they already use, and group membership determines which resources their connection may reach.
Network segmentation is available so that a connected user reaches only the resources assigned to their team, rather than being placed on a flat network with everything else. This is the difference between remote access and remote admittance.
For organizations still running something on their own premises, a gateway can be installed there too, so the same client reaches both cloud applications and the remaining local systems without staff having to know which is which.
Takeaway: adoption depends on the client being unremarkable to use, which is a real evaluation criterion.
What changes, and what does not
| Concern | Before | After |
|---|---|---|
| Stolen password alone | Often sufficient | Blocked by address restriction |
| Traffic path to cloud apps | Via the office | Direct through a nearby gateway |
| Hardware to maintain | An appliance | None |
| Scope of a connection | The whole network | Assigned resources only |
| Endpoint compromise | Still a problem | Still a problem |
Key findings
- The dedicated address is the control worth paying for; the encrypted tunnel is not a differentiator.
- Segmentation matters as much as access, because admitting somebody to a flat network is most of the historic risk.
- This protects the route, not the device. A compromised laptop connects perfectly well.
- It is not a substitute for multi factor authentication; the two address different failures and belong together.
Takeaway: treat it as one control among several, not as the perimeter restored.
Recommendation
For distributed teams using cloud applications, and for organizations wanting to retire a remote access appliance, this is a sound and inexpensive fit. It is particularly effective where cloud applications support address restrictions, since that is where the control becomes real rather than notional.
For an organization whose systems remain largely on its own premises, with staff mostly in the building, the case is thinner and a conventional appliance may serve better. Equally, a large enterprise pursuing a full zero trust architecture will find this a component rather than the answer.
Takeaway: verify your critical applications support address restriction before buying on that basis.
Schedule the access readout
A short session listing which applications staff reach remotely, which of them could be restricted to a single address, and what a stolen password would currently achieve.
Schedule the readoutGet in touch with Your Company
Questions about this solution? Reach us directly.