What is a VPN?
A VPN (Virtual Private Network) establishes an encrypted "tunnel" through the internet between a device and a network. All traffic in the tunnel is protected against eavesdropping, and the device behaves as if it were connected directly to the company network, with access to file servers, line-of-business systems and internal resources.
For businesses, a VPN is the classic solution for remote working and for connecting multiple locations securely to each other (site-to-site).
The two typical use cases
- Remote access: The employee's PC connects securely to the company environment from home, from customer sites or while travelling.
- Site-to-site: Two or more offices/data centres are connected permanently, so they function as one shared network.
The VPN's weak points
A VPN encrypts the transport, but it does not assess who or what is connecting. If a laptop is infected, or login credentials are stolen, the attacker gets the same broad access as the employee. Two iron rules therefore apply:
- Never a VPN without multi-factor authentication: Remote access is attackers' preferred door, not least in ransomware attacks.
- Limit what the VPN gives access to: Follow the principle of least privilege rather than "access to everything".
Modern architectures are therefore moving towards Zero Trust, where each individual access is verified, instead of one broad network access.
The Danish Centre for Cyber Security highlights unsecured remote access as one of the most exploited attack paths against Danish organisations. A VPN without MFA is in practice an open door.
How MI Support IT can help
We design, operate and monitor secure remote access for Danish businesses, from classic VPN with MFA and segmentation to modern Zero Trust access via Entra ID. Read more under IT operations and IT security.