VPN in the company

Why we need to rethink the discussion about secure remote access

VPN in companies - why we need to rethink the discussion

VPN in the company has been the standard for secure working on the move for many years. And for good reason: a VPN (Virtual Private Network) generally encrypts the connection between a device and the company network and protects the transmitted data from unauthorised access.

That is why we would like to clarify something right at the start:

VPN is not an insecure technology.

If we are currently discussing VPN, it is not because the technology has failed. It is because the way companies work, the way employees are connected – and the way modern IT security is conceived today – have changed.

Would you still use VPN in your company the same way today?

Not everyone needs direct network access

Imagine you could plan your company’s IT from scratch.

With a modern next generation firewall, network segmentation, multi-factor authentication, monitoring, professionally managed devices, cloud services and current security standards.

Would you then automatically give every employee access to the company network?

Or would you not rather ask first:

  • Which applications does the employee need?
  • Which data do they need?
  • Which systems do they actually have to reach?
  • Do they even need full network access for that?

Most management teams would probably opt for the new approach today.

And that is exactly why it is worth rethinking the discussion around VPN. Because VPN alone no longer protects SMEs without a holistic view of security.

The decisive security question does not lie in the VPN alone, but in what is checked before it and which access is permitted after it.

Why VPN alone no longer protects SMEs

With modern, correctly configured VPN solutions, the encrypted connection itself is usually not the central problem. It becomes critical when too many systems are reachable after login or when it is not sufficiently checked from which device the access is taking place.

Before login, it must be ensured that it really is the authorised user accessing the system. Multi-factor authentication can significantly reduce the risk posed by stolen credentials. However, it is not available as standard in every VPN solution and primarily protects only the login process.

The bigger challenge arises after a successful login.

Many cyberattacks today begin with phishing, compromised user accounts or already infected devices. Even a formally legitimately logged-in user or a compromised device can subsequently become a risk if permissions are too broad or internal systems remain reachable without clear limits.

What matters is therefore not only whether the connection is established securely. What matters is which systems and data are actually reachable after login – and whether a compromised account or device can move freely within the company network.

What happens before and after the VPN is also important.

Not every remote access requires network access

Alternatives to VPN, because not everyone needs network access

Many applications that used to require VPN access can be provided differently today. These include cloud services, web-based applications, targeted remote or remote maintenance access.

For access to a single application or a specific workstation, full network access is often no longer the most sensible approach. Modern access concepts provide, as far as possible, only the resources that are actually needed for the task at hand.

This reduces complexity and at the same time limits possible damage in the event of an incident. Because the fewer systems are reachable, the smaller the attack surface.

VPN is not always the most practical access route for companies

In addition to security aspects, everyday usability also plays a role.

Depending on the VPN technology used, public Wi-Fi, hotel networks or guest access can make establishing a connection difficult. Especially on the move, where VPN is used particularly often, this can lead to additional support effort and frustration among users.

This is another reason why it is worth asking whether VPN really is the best way for every use case. In some situations, targeted remote access to an application or a workstation is simpler, more stable and easier to control than full access to the network.

VPN remains an important technical tool. But it should not automatically be the standard answer to every form of remote working.

Some VPNs do not work reliably everywhere

IT security is decided at the endpoint device

With our IT service flat rates, we also keep an eye on the endpoint devices

Regardless of the chosen access route, one important principle always remains: IT security depends significantly on the device used.

It becomes particularly critical when private or not fully managed devices are used. In such cases, IT cannot reliably detect whether security updates are missing, malware is present or suspicious activities are taking place.

Professionally managed devices, regular security updates, EDR antivirus protection, monitoring and clear security policies are therefore among the most important measures in corporate IT today.

For this reason, we recommend targeted remote maintenance and remote access solutions instead of blanket network access to our customers. Where VPN access is still required, we rely on network segmentation, clear permission rules and make sure that the device used is always professionally managed and monitored. As part of our IT service flat rate, we therefore include such devices in central maintenance and monitoring.

Conclusion

VPN remains a proven and important tool for companies.

Today, however, the decisive question is no longer just how employees establish a connection to the company network.

More important is which access they actually need.

Companies should therefore check whether existing VPN concepts still fit today’s way of working. Not every user needs full network access. Targeted access solutions are often more secure, clearer and easier to operate.

Our security concepts therefore focus not only on securing the connection, but above all on the targeted limitation of access rights and the security of the devices used.

Because in an emergency, it is not the encrypted connection alone that determines how great the damage will be. What matters is whether a compromised account or device has only limited access – or can move freely within the company network.

FAQ

No. Using a VPN in the company is not automatically insecure. A modern and correctly configured VPN solution can still be a sensible part of corporate IT. However, it is important that login, permissions, endpoint devices and network access are consistently secured.

Not all VPNs offer multi-factor authentication (MFA). Where it is offered, it is an important security component, but it is not sufficient on its own. MFA primarily protects the login process. It is also crucial which user is logging in, whether the device used is well maintained and secure, and which systems may actually be accessed after login.

The security of remote access depends heavily on the device used. If a device is not managed, not up to date or already compromised, even an encrypted VPN connection can become a risk for companies. That is why business devices should be professionally maintained, updated and monitored.

VPN in companies can still make sense when full or technically necessary access to internal systems is required. It is important that this access is not granted across the board, but is secured through clear permissions, network segmentation, multi-factor authentication and secure endpoint devices.

Depending on the use case, web-based applications, cloud services, targeted remote access or remote maintenance solutions can be more sensible than full network access. Modern access concepts provide, as far as possible, only the applications and systems that an employee actually needs.

Many VPN concepts date from a time when remote working was organised differently. Today, companies work more with cloud services such as Microsoft 365, mobile devices and distributed teams. It is therefore worth checking whether existing remote access is still necessary, appropriate and secured in a controlled manner.

Using VPN? Then it is worth taking a look at your access concept.

Would you like to know whether your remote access still fits your current IT security strategy? Together we check which access is really necessary – and how users, devices and systems can be sensibly secured.

MCL Computer-Spezialisten.de GmbH