TL;DR: Remote access is now a primary attack path, with Verizon’s 2026 DBIR reporting that software vulnerability exploitation reached 31% of breaches and edge devices accounted for 22% of exploitation-driven incidents, showing why patch speed alone cannot secure internet-facing tunnels. The real shift is architectural: access control has to move from network reach to context-aware identity and session policy.
NHIMG editorial — based on content published by Island: The Tunnel Became the Target, Why It's Time to Retire the VPN Network
By the numbers:
- Edge devices including VPN gateways accounted for 22% of breaches that began with exploitation.
- The median time to remediate a known exploited vulnerability grew to 43 days.
- Third-party involvement now factors into 48% of breaches.
Questions worth separating out
Q: How should security teams reduce VPN risk without disrupting remote work?
A: Start by moving the highest-risk populations off the broad tunnel first, especially contractors, third parties, and privileged sessions.
Q: Why do VPNs and edge appliances keep showing up in breach paths?
A: Because they are internet-reachable, trusted by design, and often sit in front of broad internal access.
Q: What do security teams get wrong about remote access trust?
A: Teams often assume that authenticated remote access is equivalent to trusted internal access.
Practitioner guidance
- Reduce broad tunnel dependence for high-risk access Move contractors, third parties, and privileged users off always-on VPN paths first, because those groups create the highest exposure if a gateway or credential is abused.
- Scope access to specific applications rather than networks Replace network reach with application-scoped policies that verify identity, device posture, and session context before allowing access to the resource that is actually needed.
- Treat edge appliances as exposed assets Place VPN gateways and remote access controllers into the same risk review cadence as other internet-facing assets, with stronger monitoring and a clear removal path when their role can be reduced.
What's in the full article
Island's full blog post covers the operational detail this post intentionally leaves for the source:
- How the browser, desktop, and network layers are combined into a point-of-work access model.
- The contractor and third-party access scenario that motivated the 'one door' approach.
- The specific context signals used to decide whether a session is allowed.
- Why the vendor argues the tunnel model increases blast radius for remote work.
👉 Read Island's analysis of why the VPN has become the front door attackers target →
VPNs, edge appliances, and the governance gap teams are missing?
Explore further
Broad network access is the wrong trust primitive for modern identity governance. The VPN model assumes that a user who passes an authentication step should inherit broad internal reach. That assumption was built for perimeter-era work patterns and fails when the internet is the access path and the corporate network is no longer the place where work happens. Practitioners should reframe VPNs as residual infrastructure, not the control plane for trust.
A few things that frame the scale:
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to Ultimate Guide to NHIs , Key Challenges and Risks.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how remediation lag can outlast exposure windows.
A question worth separating out:
Q: Who should own the decision to retire broad VPN access?
A: Identity, infrastructure, and security leaders should own it together, because the issue spans authentication, network design, and operational access policy. The right decision is not a simple tool swap, but a governance change that limits what any successful remote session can reach.
👉 Read our full editorial: Why VPN-based remote access is failing modern identity governance