
This idea has been widely praised by security researchers, though practical guides on getting started with it on the most popular cloud platforms are still limited.


This gave birth to BeyondCorp, a theoretical model for protecting all of your applications without the use of a VPN. But once Google became wary of this approach in 2009 after the Operation Aurora hack attempt, they decided to shift towards a zero-trust security model, where every request is treated as though it is coming from a network that could be compromised. This isn’t a new idea, as companies have been creating VPNs (virtual private networks) to restrict access to their internal networks for decades.

So you should protect them to protect that data. Every company has them, and they often contain some of your company’s most important data.
