PowerData

  • Consulting
  • Training
  • PRIAM Platform
  • Articles
  • About
  • Consulting
  • Training
  • PRIAM Platform
  • Articles
  • About
Let's Talk →
Compliance

From Traditional VPN to Zero Trust: How NordLayer Became the Right Fit for a Social Services Contractor

By Murray · September 7, 2026 · 6 min read
From Traditional VPN to Zero Trust: How NordLayer Became the Right Fit for a Social Services Contractor

While preparing a small business for cyber-insurance, I provided the client with a list of action items. One of those items was acquiring a suitable VPN. The business has about 30 contractors who work remotely using their own devices wiht no VPN usage, and it provides social work services to county governments. Many didn’t know why they should use one.

This wasn’t just about checking a box for insurance. The operation involved Protected Health Information (PHI) and the client needed to demonstrate a serious commitment to security. Cyber-insurance was the immediate goal, but the real objective was protecting the people whose data flowed through the systems.

The Starting Point: A Cyber-Insurance Readiness Checklist

The first step was straightforward: build a comprehensive checklist to get this business insurance-ready. Among the essential items was acquiring a suitable VPN solution for remote contractors. But this wasn’t going to be a simple “buy any VPN” situation.

The requirements were specific:

  • Google Workspace Business Starter was already in use, so whatever we chose needed to integrate seamlessly with their existing identity management.
  • BYOD was non-negotiable—contractors use their own laptops and phones, and that wasn’t going to change.
  • HIPAA compliance was critical given the PHI involved in social services work.
  • Ease of use was paramount—these weren’t IT professionals, and many didn’t understand why they needed a VPN in the first place.

The Evaluation Process: Casting a Wide Net

I began by looking at the landscape of options. The initial shortlist included some heavy hitters:

Cloudflare Zero Trust stood out for its comprehensive approach and generous free tier for small teams. Twingate and Tailscale offered modern Zero Trust Network Access (ZTNA) with identity-based access controls. NetBird was another ZTNA contender worth considering.

Then there were the traditional VPNs. ProtonVPN was my first natural choice—I’ve been using it for years and have been consistently happy with its performance for my use. But here’s where things got interesting.

Traditional VPNs, including ProtonVPN, simply weren’t the right fit for this scenario. They excel at encrypting traffic and masking IPs, but they lack the granular controls needed when you have 30 contractors on unmanaged personal devices. Traditional VPNs typically give broad network access once a user connects, which contradicts the “least privilege” principle that insurers and security best practices demand.

The ZTNA Dilemma: Too Much of a Good Thing?

The Zero Trust Network Access options were compelling. ZTNA follows a “never trust, always verify” approach—every user and device must be authenticated and authorized before accessing any resource, regardless of location or network. This is exactly what you want when sensitive PHI is involved and devices are personally owned.

But there was a problem: the ZTNA solutions I evaluated were too much for this client—from both usage and management perspectives. These are powerful platforms designed for enterprise IT teams. The client is a small business owner trying to get insurance coverage. The complexity of deploying and managing a full ZTNA solution would have been overwhelming.

The client didn’t know to ask for ZTNA, and given the sensitive nature of social services work and the BYOD environment, I knew that zero trust principles weren’t optional—they were necessary.

Enter NordLayer: The Unexpected Contender

NordLayer wasn’t on my initial list. But when I came across it, something clicked.

NordLayer is Nord Security’s business solution—the enterprise cousin of the popular NordVPN. It’s designed specifically for small and medium businesses, offering enterprise-grade security without enterprise-grade complexity.
What Made NordLayer Stand Out

  1. Seamless Google Workspace Integration

The client was already using Google Workspace Business Starter. NordLayer integrates directly with Google Workspace, enabling Google as the identity provider for the organization. Users can log in instantly via Google SSO with a single click. This meant no additional passwords to remember, no separate login flows—just a streamlined experience that contractors could adopt without friction.

  1. HIPAA Compliance Built In

This was non-negotiable. NordLayer has been independently assessed and confirmed to meet the security objectives outlined in the HIPAA Security Rules. It offers AES 256-bit and ChaCha20 encryption—industry-leading standards for protecting sensitive data. For eligible customers, NordLayer even provides a HIPAA Business Associate Agreement (BAA), which simplifies vendor compliance during security reviews.

  1. BYOD-Friendly Features

With 30 contractors using personal devices, BYOD support was critical. NordLayer’s Device Posture Security treats all devices as untrusted until they can prove trustworthy. Administrators can set security rules, monitor device compliance, and automatically block non-compliant devices from accessing the network. This is exactly the kind of zero trust capability needed for a BYOD environment—without the complexity of a full ZTNA platform.

  1. The Sweet Spot: Core Plan

The pricing structure made the decision easier. The Lite plan was too basic. It lacked the dedicated IP, IP allowlisting, and device posture monitoring that BYOD environments require.

The Premium plan offered everything but included features like Site-to-Site connectors and Cloud LAN that this 30-person operation simply didn’t need.

The Core plan was the sweet spot. It included:

  • IP allowlisting for controlling access to resourcces
  • DNS filtering and application blocking
  • Device posture monitoring
  • A dedicated account manager
  • All the essential zero trust features without the enterprise overhead

For a team of 30 contractors, the Core plan offers a reasonable investment for cyber-insurance readiness and PHI protection.
Why Traditional VPNs Lost

To be clear: traditional VPNs have their place. For securing a single user’s traffic on public Wi-Fi, they’re excellent. But for a business with 30 contractors accessing sensitive data from personal devices, they fall short.

Traditional VPNs typically:

  • Provide broad network access once connected
  • Lack device posture checking
  • Offer limited visibility into who’s connected from what
  • Don’t support granular access controls

NordLayer, on the other hand, sits at the intersection of traditional VPN simplicity and ZTNA security. It delivers encrypted connections (like a VPN) while incorporating zero trust principles like device verification and least-privilege access.
The Road Ahead: Testing in Progress

We’re now in the testing phase. The Core plan is being deployed, and a small group of contractors is running through the setup process. The initial feedback is promising: the Google SSO integration means users can log in with their existing credentials, and the NordLynx protocol (based on WireGuard) keeps connection speeds fast.

The real test will come when the full deployment rolls out. Will contractors remember to connect before accessing sensitive data? Technically, they don’t have to and this is a business decision whether to activate the Always On VPN option or not. Will the device posture monitoring flag issues we need to address? Will the IP allowlisting work seamlessly with Google Workspace?

These questions are being answered in real-time. The testing continues, but the direction is clear: NordLayer’s Core plan offers the right balance of security, usability, and cost for this small business. It’s not the flashiest solution, and it wasn’t the first one I considered. But for a social services contractor trying to protect PHI, satisfy insurance requirements, and keep remote contractors productive, it just might be the perfect fit.

Murray Founder, PowerData Solutions Inc.

Murray specializes in cybersecurity, business process engineering & improvement, and business operations continuity. Before starting PowerData, Murray spent 20+ years helping organizations (both private sectors and government entities) to improve and streamline their operations.
Between 2002 and 2019 he built and restructured the IT infrastructure operation of multiple state government agencies, and enhanced the cybersecurity operations. He also led various projects that resulted in strengthening Mayo Clinic’s data security protocols and better protecting patient data.

Murray holds a bachelor’s degree in Computer Information Systems and a Master’s degree in business administration.

Related Insights

Ready to act?

Stop juggling spreadsheets.

Schedule a 30-min walkthrough and find out how PRIAM can simplify your operation.

Book a Walkthrough → Learn About PRIAM
PowerData

Practical cyber protection training, business planning consulting, and PRIAM — simple software for policies, risk, incidents, and assets. Built for small business owners.

Offerings
  • Training
  • Consulting
  • PRIAM Platform
Company
  • About
  • Articles
  • Let's Talk
  • LinkedIn ↗
PRIAM
  • Overview
  • priamtiv.com ↗
  • Book a walkthrough ↗
© 2026 PowerData Solutions Inc. All rights reserved.
Privacy Terms