← All terms

Virtual Private Network (VPN)

A virtual private network (VPN) encrypts traffic between a device and a trusted network, protecting remote work from snooping and rogue Wi-Fi hotspots.

A virtual private network (VPN) creates an encrypted tunnel between a device and a trusted endpoint — typically a corporate gateway — so that traffic crossing untrusted networks cannot be read or tampered with in transit. For two decades it has been the workhorse of remote access, and for a distributed workforce it remains the most familiar answer to hostile networks.

How it works

The VPN client authenticates to a gateway and negotiates encryption keys; from then on, traffic travels inside the tunnel regardless of what network carries it. On a coffee-shop hotspot or an evil twin access point an attacker controls, an eavesdropper sees only ciphertext. Corporate VPNs also place the remote device "inside" the network, reaching internal applications that are not exposed to the internet. That convenience is also the weakness: a VPN authenticates a connection, not every action after it. A phished credential or a stolen laptop can bring an attacker through the tunnel with the same broad reach — which is why VPN portals are among the most targeted assets in credential phishing and MFA fatigue campaigns, and why unpatched VPN appliances themselves regularly headline exploitation reports.

How to defend with it

Require MFA — preferably phishing-resistant — on every VPN login, and alert on impossible-travel or first-time-country connections. Patch gateway appliances aggressively; they are internet-facing by design and exploited within days of disclosure. Narrow what the tunnel reaches: per-application access or zero trust network access, which verifies identity and device posture per request, limits how far a hijacked session can travel. Check device posture at connect time so a malware-ridden personal laptop cannot enter simply because its owner knows a password. And set expectations with employees: a VPN protects data in transit, not against phishing pages, malicious downloads, or a session hijacked after login. Where VPNs fit among the other controls for a distributed workforce is covered in our guide to remote and hybrid work security.

Related terms

Evil Twin AttackAn evil twin attack uses a rogue Wi-Fi access point that mimics a legitimate network to intercept traffic and steal credentials from users who connect.Zero TrustZero trust is a security model that grants no implicit trust based on network location or identity claims — every access request is verified. Where the human layer fits.Session HijackingSession hijacking is the theft or takeover of an authenticated session — via stolen cookies or tokens — letting an attacker bypass login and MFA entirely.MFA Fatigue AttackAn MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo