Virtus Group • Security & protection pilot

ZTNA Pilot

A focused Zero Trust Network Access pilot for one internal application or small user group, helping you validate per-app access before wider VPN replacement or SASE rollout.

Virtus Group logo

Give users access to the app, not the whole network

Traditional VPNs can expose more of the internal network than users actually need. ZTNA can reduce that exposure, but the first rollout needs careful scoping.

This pilot validates one application or one small group so policy-based access, user experience, connector readiness and rollback can be proven before broader change.

What the pilot helps answer

Which app should come first?

We confirm a suitable target application or user group with a clear owner and validation contacts.

Will access work cleanly?

Identity, policy, connector and user-experience assumptions are validated in a controlled scope.

Can VPN access be reduced later?

The pilot creates evidence for a staged path toward broader access modernisation.

Common signs this is worth doing

VPN access is too broad
users connect to a network when they only need one application or service.
One app is a good test case
there is a defined owner, known users and a clear business workflow to validate.
Remote access needs modernising
but the business wants proof before replacing VPN or changing many users.
App quirks may matter
legacy auth, hardcoded paths or unusual ports need to be identified early.

What we focus on

The scope is agreed before work begins. The pilot is limited to one target application or one agreed small user group.

Target app and users

Application owner, pilot users, success criteria and key business journeys.

Identity and policy

Identity provider connection, MFA assumptions and baseline access policy.

Connector readiness

Connector, egress, DNS, certificates and other platform prerequisites.

Validation and rollback

User testing, evidence capture, constraints and practical rollback notes.

What you get

Published pilot path

One internal app or limited access path published through the agreed ZTNA approach.

Policy validation evidence

Evidence on user experience, policy fit, connector behaviour and rollback readiness.

Close-out roadmap

Findings, constraints and phased recommendations for the next app, group or managed path.

How the pilot works

1

Scope

We confirm the app or group, users, owners, identity provider and success criteria.

2

Prepare

We review prerequisites, connector or egress needs, access policy and rollback expectations.

3

Validate

We publish or test the agreed path and capture access, experience and issue evidence.

4

Decide

You choose whether to tune, expand to more apps, reduce VPN access or plan broader access work.

What this is not

Not full VPN replacement

The pilot is limited to one app or one agreed small user group unless separately scoped.

Not full SASE rollout

SWG, CASB, DLP, broad endpoint rollout and multi-path deployment are separate work.

Not broad BYOD policy work

Device compliance, BYOD governance and organisation-wide access policy are separate unless added.

Quick questions

What makes a good first app?

A good first app has a clear owner, a known user group, manageable dependencies and a business workflow that can be tested without affecting everyone.

What access is required?

Administrative or delegated access to the chosen identity provider and ZTNA platform or trial is usually required, along with app owner and validation contacts.

Will this replace our VPN?

Not during the default pilot. The pilot provides a proof point that can inform whether selected VPN use cases should later move to per-app access.

Are pilot prices published?

No. We confirm the estimate after scope, access requirements and deliverables are understood.

Want app access without opening the whole network?

Start with a short conversation. We will help confirm whether a ZTNA Pilot is the right first step, or whether SASE, identity hardening, secure web access or a broader security review makes more sense.

No hard sell. Just clarity and next steps.

Start with a free 30-minute IT conversation

hello@services.virtusgroup.biz
0800 847 887 (VIRTUS)
virtusgroup.co.nz