GlossaryAttack surface and pentesting

VPN

Short answer

A VPN (Virtual Private Network) creates an encrypted tunnel between a device and a network over the internet, so that remote employees can reach internal systems securely. VPN gateways are exposed to the internet, which makes them a frequent target for attackers.

How companies use it

Remote access VPNs connect employees' laptops to the company network. Site to site VPNs link offices or connect an office to a cloud environment. In both cases, traffic travels encrypted over the internet.

Why VPNs are a target

A VPN gateway is reachable from anywhere on the internet and gives access to the internal network once someone is in. Vulnerabilities in VPN products from major vendors have been exploited in many serious attacks, often within days of being published, and stolen VPN credentials without MFA are a common entry point for ransomware.

How to secure it

Require MFA for every connection, patch the gateway as soon as security updates are released, limit what each user can reach once connected instead of opening the whole network, check device health before allowing access, and monitor logins for unusual locations or times. Including the gateway in attack surface monitoring helps spot exposure early.

VPN and Zero Trust

A traditional VPN trusts a user once connected. Zero Trust approaches, often called ZTNA, grant access application by application after verifying identity and device each time. Many companies are moving in that direction, while keeping the VPN for specific uses.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub