The common mistake: one VPN for everything

When every VPN user gets access to the whole network, the risk is much higher than it needs to be. Accountant, owner, accounting agency and remote branch do not have the same needs.

The right approach is grouping users and rules by resources.

  • User VPN
  • Accounting VPN
  • Site-to-site VPN for locations
  • Temporary vendor access
  • Administrator access separated from user access

MFA and identity

A password alone is not enough for remote access. MFA significantly reduces risk when a password is stolen, captured by phishing or saved on someone else's device.

It is also important that an account is removed the same day a person no longer works with the company.

What is logged and checked

VPN should record who connected, from where, when and for how long. During an application issue or suspicious activity, these logs often shorten diagnostics.

Without logs there is no clear answer whether the problem is the link, user, server or application itself.

Introducing VPN without downtime

A new VPN is introduced through a pilot user, access test, documentation and an agreed cutover time. Old access remains only until the new one is confirmed.

This avoids remote work stopping because of one wrong firewall change.