VPNs and firewalls assume the user sits behind a trusted corporate boundary. When workers connect from home, that boundary disappears and access decisions must shift to identity, device trust, and application context. If controls still depend on network location, a compromised home device or stolen credentials can expose internal resources far beyond the intended scope.
Why Home Working Exposes the Limits of Boundary-Based Security
Traditional VPN and firewall controls are strongest when they can make a simple location-based assumption: traffic inside the corporate boundary is more trustworthy than traffic outside it. Home working breaks that model because the employee’s network now includes routers, personal devices, consumer-grade Wi-Fi, and a much less predictable local trust environment. The control still works as a transport path, but it becomes a weaker decision point for access.
That weakness matters because the risk is not just unauthorised entry from the internet. It is also overconfidence in a tunnel that says nothing about whether the endpoint is healthy, whether the credential has been stolen, or whether the application being reached should be available at all. NHI Management Group research on the Ultimate Guide to NHIs — Standards shows how identity and access risk escalates when controls depend on static assumptions rather than current context. In practice, many security teams discover that “remote access” was treated as a trust guarantee only after an endpoint or credential has already been abused.
How the Control Model Changes in Practice
VPNs and firewalls were designed to protect networks, but modern work increasingly depends on protecting sessions, identities, devices, and applications. Once a user works from home, the security question shifts from “Which network are they on?” to “Who is requesting access, from what device, with what assurance, and to which resource?” That is why identity-aware and device-aware controls are now more important than location alone.
A VPN can still be useful for encrypting traffic and reducing exposure of internal services to the open internet. A firewall can still enforce segmentation and block obviously unwanted flows. But neither control can determine whether a session is legitimate if the credential has been phished, the device is unmanaged, or the user has far broader access than the task requires. This is where current guidance suggests moving toward least privilege, conditional access, and short-lived authorization rather than permanent network trust.
Practically, that means a few things:
- Authenticate the user and the device, not just the network path.
- Limit access to specific applications and data, rather than broad internal subnets.
- Prefer time-bound or context-bound access decisions over always-on trust.
- Monitor for unusual location, device posture, and session behaviour after login.
For identity-dependent work, the underlying problem is often the same one highlighted in the OWASP Non-Human Identity Top 10: access becomes dangerous when long-lived trust is granted without enough context to constrain misuse. These controls tend to break down when organisations treat VPN reachability as equivalent to authorization because that assumption collapses the moment the endpoint or credentials are no longer trustworthy.
Where the Old Assumptions Break, and What Replaces Them
Tighter remote-access control often increases user friction and administrative overhead, so organisations have to balance usability against assurance. The trade-off is real: if you make access too restrictive without a clean alternative, teams will create workarounds that reintroduce shadow access paths.
The most common edge case is a hybrid environment where some applications are still protected by network segmentation while others are already exposed through SaaS or zero-trust style access. In that environment, the VPN may remain necessary for legacy systems, but it should no longer be treated as the primary security boundary. Another important edge case is third-party or contractor access, where home-working risk is amplified because the organisation often has less control over the device and less visibility into the local environment.
There is also no universal standard for replacing perimeter controls all at once. Best practice is evolving toward layered checks: identity, endpoint health, application policy, and continuous evaluation. The key test is whether access can be revoked or narrowed quickly when the context changes. If it cannot, the organisation is still relying on network location as a proxy for trust, and that proxy is weakest precisely when employees are least likely to be on a corporate network.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | 3 — Zero Trust Architecture Principles | Home working weakens location-based trust assumptions that ZTA replaces. |
| Recommendation — Base remote access on verified identity, device state, and least privilege rather than network location. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorization Management | Remote access should be limited to authorized resources, not broad network reach. |
| Recommendation — Scope remote users to specific applications and revoke unnecessary internal reach. | ||
| CIS Controls v8 | 6 — Access Control Management | Remote workers need tighter account and privilege governance than perimeter trust provides. |
| Recommendation — Review and restrict remote access rights so credentials cannot open excessive internal access. | ||
| NIST AI RMF | MAP — Map AI Risk and Context | Context-aware access decisions depend on understanding environment, use, and risk context. |
| Recommendation — Assess access context continuously and adjust trust when device or session conditions change. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Stolen credentials make location-based controls ineffective against legitimate-looking access. |
| Recommendation — Monitor for abuse of valid accounts and investigate unusual remote login patterns promptly. | ||
Practitioner Guidance
What to verify: Confirm whether remote-access decisions still depend on network location anywhere in the path, including legacy VPN policy, firewall exceptions, and split-access routes. If a user can reach more than the job requires after login, the control set is broader than the business need.
Decision rule: If the protected resource would be damaging to expose after credential theft, treat VPN access as transport only and require stronger identity, device, and session checks before granting reachability.
What practitioners underestimate: The real failure is often not the tunnel itself but the false sense of safety it creates. A secure channel does not fix stolen credentials, unmanaged endpoints, or excessive internal reach, so those issues must be measured and reduced directly.
Practitioner takeaway: Home working weakens VPN and firewall assumptions whenever “where the user is” matters more than “who the user is and what state the device is in.”
Related resources from NHI Mgmt Group
- How should security teams reduce remote-work identity risk for employees using home offices?
- Why do traditional VPN and OAuth controls fall short for AI agents?
- How should security teams handle trust when employees work from home and the office?
- Why do identity controls become weaker when AI calls are hidden inside Kubernetes environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org