Contact
Network infrastructure representing VPN and remote access

Library

VPN from an attacker's perspective

Share via

VPN connections have long provided remote employees with access to internal networks. Their structural risk comes less from networking itself than from the implicit trust granted after connection. Broad access and limited visibility create blind spots in hybrid environments.

Explanation

A VPN encrypts traffic between a client and a gateway and may provide access to internal network services. The protocol does not create a complete trust decision; security also depends on identity, device posture, gateway hardening, cryptography, segmentation and session management. Because a VPN gateway must be internet-facing, it is an attractive target for credential attacks and vulnerabilities in edge appliances. After authentication, users often receive network reach that is broader than one application. Assessment therefore needs to cover both the external gateway and the privileges and detection capabilities available inside the tunnel.

Risk

Compromised credentials, missing MFA, outdated firmware or excessive network access can turn a VPN into an initial access path. An attacker with a valid session may discover internal names, services and management interfaces while appearing to be a normal remote user. Split tunnelling, weak cryptography, unused features and unrestricted session duration may further increase exposure. If VPN and identity logs are not correlated with endpoint and network telemetry, anomalous locations, devices and lateral movement can remain unnoticed. A successful sign-in should therefore not result in broad implicit trust.

Points to check

  • IP-level access instead of application-level access.
  • No contextual verification of user, device and location.
  • VPN traffic treated as trusted by default.
  • Long-lived sessions after context changes.
  • Weak segmentation behind the VPN.

Approach

DeepBlue assesses gateway version, external exposure, cryptographic configuration, authentication, MFA, certificates, roles and network access. Controlled tests validate account policy, session management, lockout, segmentation and detection without creating unnecessary availability risk. VPN, identity, endpoint and firewall logs are correlated by source, device, time, session and follow-on traffic. Improvements focus on phishing-resistant MFA, minimal protocol and port exposure, rapid edge-system patching, role-based access and separate administration paths. Where application-level access is feasible, a zero-trust model can progressively replace broad network trust; the decision should follow risk and operational constraints.

Conclusion

Traditional VPN architecture no longer fits a Zero Trust security model. Identity-bound, context-aware access is necessary to reduce broad trust and improve visibility across modern IT and OT environments.

Contact

Want to understand the impact in your own environment? Contact DeepBlue Security & Intelligence at info@deepbluesecurity.nl or +31 (0) 70 290 6 290.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.