Why VPNs Are High-Value Targets
Virtual Private Networks are internet-facing systems that, when compromised, provide direct access to internal networks. Major VPN vendors — Fortinet, Pulse Secure/Ivanti, Citrix, SonicWall, Palo Alto — have all had critical vulnerabilities exploited at scale by ransomware groups and nation-state actors in recent years. The combination of internet exposure, privileged network access, and historically slow patch cycles makes VPN appliances a prime target. CISA maintains a list of known exploited vulnerabilities that includes numerous VPN appliance CVEs.
VPN Security Hardening Checklist
- Patch aggressively — VPN patches must be treated as critical and applied on an emergency timeline, not a standard 30-day cycle. Attackers begin exploiting new VPN vulnerabilities within hours of disclosure.
- Require MFA — VPN access without MFA is a single-factor authentication system. Every VPN user must authenticate with MFA. FIDO2 or certificate-based authentication provides the strongest protection.
- Disable split tunneling where possible — Split tunneling allows VPN clients to route some traffic outside the tunnel, creating visibility gaps and potential bypass paths.
- Restrict who can use the VPN — Not every employee needs VPN access. Limit access to users with a documented need and disable accounts immediately when employees leave.
- Monitor VPN logs — Unusual VPN login patterns (off-hours access, unusual locations, repeated failed authentications) are early indicators of credential-based attacks.
- Implement network access control post-VPN — VPN access should not grant blanket network access. Users should only be able to reach the systems they are authorized to use.
When to Consider Alternatives to VPN
Zero Trust Network Access (ZTNA) solutions represent the next generation of remote access technology. Rather than providing network-level access, ZTNA provides application-level access — users can only reach specific applications they are authorized to use, not the full network. This fundamentally limits the blast radius of a compromised credential compared to traditional VPN. Organizations with significant remote access requirements and mature security programs are increasingly adopting ZTNA as a replacement or complement to VPN.
Is your VPN exposure tested?
Grid32's external network penetration tests specifically assess VPN security — configuration, vulnerability status, and authentication controls.
Get a Quote →