Remote working and the death of the VPN

Person working at a desk
(Image credit: Shutterstock / LStockStudio)

The year 2020 was branded unprecedented as we navigated unknown situations and moved to the "new normal". Of course, IT teams couldn’t have predicted a pandemic, global lockdowns and the total upending of our day-to-day lives along with them.

There was one prediction that certainly did come through in 2020 – and that was our beliefs about the trajectory of the VPN. Even before the move to remote working, the technology has been showing its age for some time.

VPNs were built for the network-centric world, where apps resided solely in the data centre and a security perimeter around the “castle” was all you needed. Even in 2019, many organisations were moving toward a perimeter-less model, where traditional network security based on the castle-and-moat approach, is no longer relevant. We predicted that, in the next few years, VPNs would be redundant.

About the author

Nathan Howe is Director of Transformation Strategy at Zscaler

VPN redundancy accelerates

We may have been right about the VPN being on its last legs, but off with the timeframe. To understand how the status of VPNs has deteriorated, we need to look at the evolution of remote working over the past year.

In 2019, many businesses’ infrastructure investment was not in enabling remote working. The two primary goals were driving applications to the cloud to achieve cost benefits and competitive advantage and simplifying their IT in general. This, most commonly, was through investment in SD-WAN projects. This made sense at the time, but when lockdowns started hitting in March, business continuity plans were shown to be lacking, and their SD-WAN sites sat unused and gathering dust.

In March last year, businesses found themselves unable to handily support mass remote working, as there was a key shortage in network connections. More than one business I’m aware of was having employee’s VPN into the data centre to get internet access. This kind of solution was capable of handling 20%, maybe 30%, of the workforce, so scaling this to a full workforce was impossible. Reliable connections became a rare resource, and productivity suffered as a result.

As connectivity inevitably became the precious resource needed to ensure business continuity, pressure was put upon IT teams to enable more reliable connections. In an ‘ends justify the means scenario’, IT teams started bypassing security controls. They spun up cheap remote desktop and VPN solutions, empowering employees to use their personal devices to access the corporate network.

In the short term this meant a summer period of relative calm. Businesses’ connectivity stabilised, productivity rose, and board members breathed a tentative sigh of relief. However, the quick fixes and workarounds that had enabled this moment of respite had left cracks in security that have, in recent months, made themselves apparent.

VPN security issues come full circle

Back in mid-October 2020, the U.S. National Security Agency (NSA) released a list of the top 25 security vulnerabilities that Chinese hackers are exploiting to steal intellectual property, as well as economic, political, and military information. VPNs and remote desktop protocols (RDP) make up nearly half those vulnerabilities. Since the middle of last year, we’ve seen significant cyber incidents aimed at large enterprises’ remote access, particularly in the form of ransomware.

Now, VPN vulnerabilities are nothing new. The NSA and its UK counterpart the National Cyber Security Centre (NCSC), have been flagging vulnerabilities in VPNs for years. The difference now is that many businesses are relying on VPNs to ensure the continuity of their businesses. The attack surface is larger and the prizes for cybercriminals larger still. 

We recently conducted research into how European businesses are enabling secure remote access. Thirty per cent of companies are using remote access VPN solutions to provide access to business applications in data centres or the cloud. One-third are using RDPs. More modern approaches, such as zero trust and identity management trail behind at 17% and 19% respectively.

This, to put it mildly, is risky. Whilst we do not know for sure how our year or so working remotely will affect working practices in the future, it seems sensible businesses should be putting in place the infrastructure to enable secure mass remote working in future, whether from a business strategy perspective or should we face another epidemic or pandemic scenario.  

As mentioned, infrastructure investments in 2019 were often unsuited for the challenge’s businesses have over the last year of remote work. Business leaders couldn’t have anticipated the last 12 months, and now need to not get bogged down in sunk costs. It’s time to kill off the VPN, before its inadequacies cause serious harm to businesses.

  • Here's our list of the best proxy services right now

Nathan Howe, Director of Transformation Strategy at Zscaler, has 20+ years in security experience across a multitude of organisations including governments, enterprises and telco service providers.

Read more
VPN
7 VPN predictions to look out for in 2025
Outlook Calendar on a Tablet
What we learned from VPNs in 2024
A VPN runs on a mobile phone placed on a laptop keyboard
The 3 biggest VPN innovations of 2024 – what does the future hold?
A VPN running on a mobile device
3 VPN rising stars – what will it take to reach the top in 2025?
Green background featuring laptop with connect button
I tried the "world's most secure VPN" and while it's not the VPN you'll want, you'll need it sooner than you think
Security
Protect your network with an AI-secure browser and SASE framework
Latest in VPN
Demonstrators protesting against the arrest of the Mayor of Istanbul Ekrem Imamoglu block Atatürk Boulevard on March 22, 2025 in Ankara, Türkiye.
Turkey's social media ban has been lifted, but VPN usage is still high
Shape of Russia filled with Russian flag-colored internet codes on a black hacking background
A new wave of blocks in Russia targets VPN apps and Cloudflare subnets
A hand holds a smartphone displaying the NordVPN logo
NordVPN Prime hits lowest-ever price in VPN Spring sale
Digital hand set location on map with two pins. AI technology in GPs, innovation delivery, map location, future transport logistic, route path concept. GPs point. New office location, change address
What does your IP address reveal about you?
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS