Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

VPN age-gating debate: are enterprise remote access controls ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Identity-based attacks accounted for 68.6% of incidents in 2025, according to Expel, and the UK’s VPN age-gating consultation highlights how remote access policy, third-party connectivity, and OT segmentation can become governance blind spots when organisations depend on VPNs for enterprise access. The practical issue is not consumer restriction, but whether managed devices, phishing-resistant MFA, and visibility into VPN/proxy use are strong enough to hold up under attack.

NHIMG editorial — based on content published by Expel: a discussion of VPN age-gating policy, remote access ambiguity, and identity-based attack patterns

By the numbers:

Questions worth separating out

Q: What breaks when VPN access is treated as trusted after login?

A: Broad VPN trust breaks containment.

Q: Why do proxies and consumer VPNs make credential attacks harder to stop?

A: Because they let attackers make malicious sign-ins look geographically normal.

Q: How do you know if remote work security controls are actually working?

A: Look for fewer standalone passwords, consistent SSO adoption, enforced MFA or passwordless authentication, and access scopes that stay narrow after login.

Practitioner guidance

  • Inventory every VPN client in use Build visibility into approved and unapproved VPN software on managed and unmanaged devices, then flag sign-ins from consumer privacy tools as a review condition.
  • Require managed devices for privileged remote access Apply conditional access so high-value accounts can authenticate only from enrolled, compliant endpoints with phishing-resistant MFA.
  • Treat blocked proxy and VPN logins as incidents Investigate denied logins from suspicious geographies, TOR exit nodes, or unauthorized VPN applications as possible credential compromise rather than normal background noise.

What's in the full article

Expel's full analysis covers the operational detail this post intentionally leaves for the source:

  • A breakdown of suspicious remote access behaviours seen in 2025 SOC cases, including unauthorized VPN applications and proxy-routed login attempts.
  • The specific identity incident patterns behind the 68.6% figure, useful for teams comparing their own alert mix with Expel’s findings.
  • The operational control recommendations for managed-device enforcement and blocked-login triage in real incident response workflows.
  • The red-team observations behind remote access misconfigurations and access management failure points.

👉 Read Expel's analysis of VPN policy uncertainty and remote access identity risk →

VPN age-gating debate: are enterprise remote access controls ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Remote access governance is now an identity problem, not just a network problem. VPNs can hide transport origin, but they do not solve identity assurance, device trust, or privilege scope. That makes remote access one of the places where IAM, PAM, and security operations must converge, especially when third parties and legacy systems depend on the same pathway. Practitioners should treat remote access as governed identity infrastructure, not as a perimeter exception.

A question worth separating out:

Q: Who is accountable when third-party or service access is still routed through a VPN?

A: The accountable team is the one that owns lifecycle governance for the access path, not just the network. If vendors or service accounts can keep using broad access after their task ends, the organisation has an offboarding failure, not simply an access-tool problem. Auditors will expect revocation discipline and traceable ownership.

👉 Read our full editorial: VPN age-gating debate exposes enterprise remote access governance gaps



   
ReplyQuote
Share: