The obvious downside to entirely relying on this philosophy for security, however, is that once a bad actor breaches the perimeter, there are limited protections for the network, and a cyber criminal has all-but unfettered access to the whole shebang.
How secure is a business VPN?
VPNs are far from entirely safe. They’re not designed to replace security safeguards like anti-virus software, and they should belong to part of a wider security posture.
In one study of IT professionals working at organisations that used a VPN for network access and/or security measures, almost 40% of respondents believed that their network had already been breached.
These same IT professionals also listed “security” as their main pain point in working with VPNs.
Of note, the study was conducted just before the pandemic hit. The pandemic put an extra strain on IT teams who needed a fast and effective back-up plan to accommodate the sudden shift to a predominantly remote workforce.
Even today, remote and hybrid working has become the favoured mode for most workplaces.
However, this rapid growth in employees working from home combined with the increased use of cloud-based applications has meant that IT departments have had the difficult task of balancing performance and security.
As a result, cyber criminals are targeting these vulnerabilities by breaching usernames and passwords to access VPN services and exploiting vulnerabilities in the VPN service itself. Organisations often don’t realise that they’re in danger, and are skipping critical patches that help maintain security, only compounding the risk further.
In another study conducted in 2021, 94% of the organisations surveyed reported that they know that their VPNs are vulnerable to cyberattacks and exploits and 72% were concerned that their VPN may jeopardise the ability to keep their environment secure.
Yet many businesses still choose to take this path.
What’s the alternative to a business VPN?
Given the current landscape where remote or hybrid working has become the preferred environment, getting serious about securing remote users is critical to keeping any organisation’s network and data protected.