Minds Study: Zero Trust Network Access Friction
A deep-dive simulated study by Minds on why network security architects resist VPN-to-ZTNA migrations, bypassing recruitment barriers with high-fidelity personas.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- ØAverage
- 7
Architects rate the friction of migrating legacy systems to ZTNA as highly severe, with a strong concentration around scores 7 to 9.
- 15+ stats with cross-tabs by age, country, income
- 5 downloadable charts
- Raw response data (CSV)
- Ask your own questions in this Study
Methodology
A simulated study of four hundred network security architects conducted via the Minds platform reveals that legacy application incompatibility and user-experience disruption are the primary drivers of resistance to zero-trust network access migrations. Validated against established industry benchmarks from Kantar, the simulation shows that seventy-two percent of technical gatekeepers delay zero-trust deployment due to integration friction.
Architects citing legacy app incompatibility
Architects fearing user-experience disruption
Architects reporting budget-to-complexity mismatch
Based on a simulated Audience of 400 respondent. Benchmark agreement varies by audience, question, grounding, and reference study.
Audience composition
- 15-10 years25%
- 211-15 years45%
- 316+ years30%
- 1Hybrid Cloud & On-Premise Legacy60%
- 2Multi-Cloud Native25%
- 3On-Premise Private Cloud15%
To understand the deep-seated resistance that enterprise cybersecurity providers face when attempting to transition customers from legacy Virtual Private Networks (VPNs) to Zero Trust Network Access (ZTNA), research teams must engage with highly specialized technical gatekeepers. However, recruiting network security architects, principal security engineers, and infrastructure directors is notoriously difficult. These professionals are highly compensated, exceptionally busy, and naturally skeptical of traditional marketing panels. Furthermore, traditional research panels often fail to capture the nuanced technical objections that drive architectural decisions.
To bypass these recruitment barriers, this study utilized the Minds Target Audience Simulation platform to model a high-fidelity panel of 400 network security architects across the Anglo-Global region. The simulation was executed using the Minds three-stage model to ensure maximum accuracy and alignment with real-world behaviors:
- Datenverankerung (Level 01): The simulation was grounded in real-world enterprise infrastructure datasets, security architect job descriptions, and industry reports from leading research bodies such as Gartner and Forrester. No persona was built from pure assumptions.
- Simulationsmodell (Level 02): The platform modeled deep technical expertise, demographic anchors, and robust behavioral frameworks specific to network security architects managing hybrid cloud and legacy on-premise environments.
- Validierung (Level 03): The simulated responses were validated against established consumer behavior frameworks and reference benchmarks from national statistics agencies and industry research. This methodology achieves an average agreement of 85% to 95% with physical panels on complex technical preferences, language alignment, and objection mapping.
By leveraging this advanced simulation infrastructure, the research was completed in under 1 hour, providing deep qualitative and quantitative insights at a fraction of the cost of a classical panel, and without any per-respondent recruitment fees. The entire simulation was hosted on secure EU-servers, ensuring 100% GDPR (DSGVO) compliance with zero processing of personal participant data.
The Core Friction: Legacy Application Incompatibility
The primary technical barrier to ZTNA adoption is the sheer volume of legacy, on-premise applications that lack support for modern identity and access management protocols. While modern SaaS applications and cloud-native workloads integrate seamlessly with identity providers via SAML 2.0 or OpenID Connect (OIDC), legacy enterprise systems often rely on hardcoded IP addresses, custom protocols, or legacy active directory authentication.
Traditional VPNs operate at Layer 3 (the Network Layer), establishing a secure tunnel that grants users broad access to the entire network segment. This model is inherently insecure, as it allows lateral movement if credentials are compromised, but it has one major operational advantage: it just works for legacy applications. ZTNA, by contrast, operates at Layer 7 (the Application Layer), enforcing granular, application-specific access.
We have over two hundred legacy on-premise applications that don't support modern SAML or OIDC. Forcing a ZTNA client onto these without breaking our daily operations is a logistical nightmare.
When migrating to ZTNA, security architects are forced to map every single application, port, and protocol across the entire enterprise network. For organizations with hundreds of legacy applications, this mapping process represents a massive operational bottleneck. Architects fear that enforcing strict Layer 7 access policies will break critical business workflows, leading to costly downtime and emergency rollbacks. Consequently, many choose to maintain legacy VPNs in a hybrid state, which ultimately defeats the security benefits of a zero-trust architecture.
The User Experience Dilemma: MFA Fatigue and Session Friction
Beyond the technical integration challenges, network security architects are highly sensitive to the impact of security controls on employee productivity. A successful security architecture must balance robust protection with usability. If security measures are too intrusive, they create friction that actively hinders daily operations.
ZTNA architectures rely on continuous authentication and device posture checks. Unlike a VPN, which typically authenticates a user once at the start of the day, ZTNA continuously evaluates the user's identity, location, and device health. While this continuous verification is essential for preventing credential abuse, it often manifests as frequent multi-factor authentication (MFA) prompts and session timeouts.
Our users are already suffering from MFA fatigue. If ZTNA introduces continuous re-authentication prompts every time their IP shifts slightly, they will find workarounds, completely undermining our security posture.
Architects are acutely aware of MFA fatigue and the psychological toll of intrusive security controls. When users are repeatedly interrupted by authentication requests, their productivity drops, and their frustration grows. More importantly, high friction drives users to seek workarounds, such as routing traffic through unmanaged personal devices or using unauthorized shadow IT tools. Architects resist ZTNA solutions that do not offer seamless, passwordless authentication or intelligent, risk-based session management, as they know that user bypasses represent a far greater security risk than legacy VPN vulnerabilities.
Routing Complexity and Infrastructure Inertia
The third major friction point lies in the underlying network topology and routing complexity. Enterprise networks are not static; they are complex webs of IPsec tunnels, MPLS circuits, and static routing tables built over decades. Transitioning from a centralized, perimeter-based network to a software-defined ZTNA edge requires a fundamental redesign of the network architecture.
Many ZTNA solutions require routing all traffic through a vendor's cloud-based security edge. While this simplifies policy enforcement, it can introduce significant latency, particularly for real-time traffic such as VoIP, video conferencing, and high-performance database queries. For global enterprises with distributed offices, backhauling traffic to a distant cloud gateway can severely degrade application performance.
The vendors sell ZTNA as a magic bullet, but they don't see the underlying routing complexity. We can't just rip out our IPsec tunnels overnight when our entire disaster recovery protocol depends on them.
Furthermore, network security architects must manage the operational overhead of maintaining dual routing paths during the multi-year migration process. They must ensure that disaster recovery protocols, failover mechanisms, and network monitoring tools continue to function seamlessly across both the legacy VPN and the new ZTNA environments. The sheer complexity of managing this transition, combined with the fear of performance degradation, leads many architects to adopt a conservative, slow-paced approach to migration.
Accelerating the Sales Cycle: Strategic Implications for Cybersecurity Vendors
For cybersecurity vendors targeting the enterprise market, these findings provide a clear roadmap for overcoming late-stage sales friction. To accelerate the transition from legacy VPNs to ZTNA, vendors must move beyond high-level security messaging and directly address the practical, operational concerns of technical gatekeepers.
First, vendors must provide robust tools and services to simplify the discovery and mapping of legacy applications. Offering automated application discovery, protocol translation, and legacy authentication wrappers can significantly reduce the migration bottleneck. By demonstrating a clear, low-risk path for onboarding legacy systems, vendors can alleviate the primary fear of network disruption.
Second, vendors must prioritize user experience by integrating advanced passwordless authentication, single sign-on, and continuous, non-intrusive posture assessment. Reducing the frequency of active MFA prompts while maintaining strict security controls is a critical selling point for architects who are protective of user productivity.
Finally, cybersecurity product and marketing teams can leverage the Minds platform to continuously test and refine their positioning, documentation, and sales enablement materials. By simulating high-fidelity panels of network security architects, vendors can identify and address specific technical objections before launching campaigns or entering late-stage sales cycles. This high-speed simulation capability delivers deep, actionable insights in under 1 hour, allowing teams to optimize their go-to-market strategies without the high cost and long timelines of traditional research.
To see how target audience simulation can help your team map technical objections and accelerate your enterprise sales cycle, book a methodology call with our research experts today. We will demonstrate how the Minds platform can simulate your exact target segments, providing the precise insights you need to overcome implementation friction and drive adoption.
Frequently asked questions
How does Minds simulate highly paid security architects so accurately?
Minds leverages a three-stage validation model that calibrates high-fidelity technical personas against real-world security datasets and established consumer behavior frameworks. This achieves an 85% to 95% average agreement with traditional physical panels, occasionally reaching up to 100% on specific technical objection mapping, without the extreme cost and time of recruiting busy enterprise gatekeepers.
How fast can we get insights on complex B2B buyer objections?
Unlike traditional research sprints that take weeks to recruit and interview enterprise security architects, Minds delivers deep, multi-segment simulations in under 1 hour. All data is hosted entirely on secure EU-servers, ensuring 100% GDPR (DSGVO) compliance with zero processing of personal participant data.
What is the cost advantage of using Minds over traditional panels?
Minds provides deep qualitative and quantitative insights at a fraction of the cost of a classical panel. By eliminating per-respondent recruitment fees and incentive costs for high-earning technical professionals, enterprises can run continuous simulations without budget strain.
How do these simulation results map to the bottom-of-funnel buyer journey?
By identifying specific implementation friction objections, such as legacy application incompatibility and routing complexity, cybersecurity vendors can tailor their BOFU sales enablement, documentation, and product positioning to directly address the exact technical hurdles that cause security architects to stall deals.
About Minds
Minds is an AI research lab building synthetic focus groups and studies. It helps go-to-market and product teams understand their target audiences in minutes, not months.


