{"id":1316,"date":"2022-06-17T15:44:29","date_gmt":"2022-06-17T08:44:29","guid":{"rendered":"https:\/\/dt-corp.com.vn\/?p=1316"},"modified":"2022-06-17T15:44:29","modified_gmt":"2022-06-17T08:44:29","slug":"5-virtual-private-network-vpn-best-practices-for-2022","status":"publish","type":"post","link":"https:\/\/dt-corp.com.vn\/?p=1316","title":{"rendered":"5 Virtual Private Network (VPN) Best Practices for 2022"},"content":{"rendered":"<div class=\"blog-summary\">\n<p>Learn about VPNs, why organizations are using them so much more, and what IT leaders can do to help ensure their security.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<h2>WHAT IS A VPN AND WHY DO ORGANIZATIONS USE THEM?<\/h2>\n<p>Since the beginning of the COVID-19 pandemic, the workplace has undergone a dramatic shift moving from the office to the home, and organizations are now more spread out than they\u2019ve ever been. This shift to remote work has complicated organizations\u2019 cybersecurity initiatives in more ways than one, but one of the main concerns of many organizations continues to be secure and private access to their sensitive corporate data. For this reason, the use of virtual private networks (VPNs) by organizations has skyrocketed by 68% since the beginning of the pandemic,\u00a0<a href=\"https:\/\/openvpn.net\/blog\/covid-19-fast-tracks-virtualization-openvpn-study-reveals-remote-work-is-the-future\/\" target=\"_blank\" rel=\"noopener\">according to OpenVPN<\/a>.<\/p>\n<p>VPNs provide organizations with a way to create a secure, encrypted connection between their employees and their corporate networks so that critical data can be accessed by authorized users that are outside of the corporate perimeter. As corporate VPNs are generally cost-effective, relatively easy to deploy, and scalable, they&#8217;ve quickly became a popular way for organizations to adapt to hybrid and remote work. With that in mind, though, like just about any other cybersecurity tool, VPNs aren\u2019t one-size-fits-all solutions, nor are they \u201cdeploy and look away\u201d solutions. The following five best practices will help to ensure that your organization\u2019s VPN and corporate network remain safe from the growing threat landscape.<\/p>\n<h3>1. CHOOSE THE TYPE OF VPN THAT BEST FITS YOUR ORGANIZATION.<\/h3>\n<p>The first step in deploying a VPN within your organization is understanding which type of VPN makes the most sense for your needs. An organization\u2019s current workforce size, growth trajectory, IT budget, and more can all influence which type of VPN it chooses to implement.<\/p>\n<p>Business VPNs are generally offered in two different varieties: remote access VPNs and site-to-site VPNs. While the objective of both types of VPNs is to connect an organization\u2019s workers to its corporate network, they each accomplish this slightly differently. A remote access VPN is similar to consumer VPNs in that it requires an end-user to install a client. The VPN gateway then authenticates the user in order to create a secured connection between that user and the corporate network.<\/p>\n<p>Remote access VPNs are commonly used by employees that work from home, are frequently traveling, or work in public areas using public networks. A site-to-site VPN (or router-to-router VPN), on the other hand, connects the local area networks (LANs) of separate geographic sites\u2014usually separate offices\u2014directly to the corporate LAN to create the secured connection. Site-to-site VPNs serve as a cost-effective way for organizations to connect entire networks to a consolidated intranet.<\/p>\n<p>If your organization has a large remote workforce that works from their home offices, remote access VPNs could prove to be easier to deploy and scale as your workforce grows but issues with latency and a lack of compatibility with cloud applications could arise. If your workforce is largely working out of the office, though, and your goal is to solely connect domestic branches and international offices with the corporate network, then a site-to site VPN could be the better option. IT teams may even find that employing a combination of both types of VPNs is the best option for their respective organizations assuming they have the means to maintain both.<\/p>\n<h3>2. CREATE AND ENFORCE STRONG SECURITY POLICIES AROUND VPN USAGE.<\/h3>\n<p>Your organization may already have comprehensive\u00a0<a href=\"https:\/\/www.helpsystems.com\/blog\/corporate-data-security-policy-what-why-and-how\" target=\"_blank\" rel=\"noopener\">corporate data security policies<\/a>\u00a0in place that dictate how its sensitive data should be handled on a daily basis by employees. Since many of these policies are technology-centric, making sure to include specific VPN-related policies is an absolute must.<\/p>\n<p>Your organization\u2019s VPN security policies can and should cover a lot of ground, including which employees do and do not have access to the VPN, how employees first gain access to the VPN and authenticate themselves in the future, what privileges will be allowed to each VPN end user, and more. Furthermore, VPN security policies do not have to be solely people- or employee-centric in nature. These policies should also detail the VPN\u2019s configuration settings, like what type of encryption it uses, what applications will and will not be compatible with the VPN, and what protocol is used. These policies can ideally prevent human error when employees operate the VPN as well as any lapses in hardware or software functionality that may negatively impact an organization\u2019s operations.<\/p>\n<h3>3. ENSURE YOUR ORGANIZATION\u2019S VPN IS PROPERLY CONFIGURED.<\/h3>\n<p>While cost, convenience, and scalability are all important factors in initially choosing a business VPN, ultimately, the point of an organization using such a tool is to heighten security. Unfortunately, though, VPNs can be used against the organizations they were originally supposed to help protect even with VPN security policies in place.\u00a0<a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/?CMP=OOH_SMB_OTH_22222_MC_20200501_NA_NM20200079_00001\" target=\"_blank\" rel=\"noopener\">Verizon\u2019s 2022 Data Breach Investigations Report<\/a>\u00a0indicates that the human element was present in more than 8 in 10 data breaches and that carelessness\u2014including misconfigurations\u2014was the third top action vector in those breaches. Misconfigured VPNs are no exception to those findings. For example, an attack carried out against the communications company Viasat this past February was the result of an attacker exploiting a misconfigured VPN, according to\u00a0<a href=\"http:\/\/www.viasat.com\/about\/newsroom\/blog\/ka-sat-network-cyber-attack-overview\/\">the company&#8217;s analysis<\/a>.<\/p>\n<p>Perhaps the biggest security risk associated with VPNs is that they can leave an entire network vulnerable to an attack. If a bad actor were to gain unauthorized access to the secured VPN connection, likely using an end-user&#8217;s compromised credentials, that attacker can then gain access to other (perhaps more sensitive) systems on that same network if it is inadequately segmented.<\/p>\n<p>To prevent such an attack before one ever occurs, IT leaders need to consider several important features when first choosing a VPN and following standard recommendations during its initial configuration. Most recently, the\u00a0<a href=\"https:\/\/media.defense.gov\/2022\/Mar\/01\/2002947139\/-1\/-1\/0\/CTR_NSA_NETWORK_INFRASTRUCTURE_SECURITY_GUIDANCE_20220301.PDF\" target=\"_blank\" rel=\"noopener\">NSA recommended<\/a>\u00a0finding a VPN with strong encryption algorithms and \u201cdisabling all unneeded features and implementing strict traffic filtering rules for traffic flowing to VPN gateways,\u201d including limiting accepted traffic to known VPN peer IP addresses. This past year, the NSA additionally released\u00a0<a href=\"https:\/\/media.defense.gov\/2021\/Sep\/28\/2002863184\/-1\/-1\/0\/CSI_SELECTING-HARDENING-REMOTE-ACCESS-VPNS-20210928.PDF\" target=\"_blank\" rel=\"noopener\">joint guidance<\/a>\u00a0with the Cybersecurity and Infrastructure Security Agency (CISA) that included a multitude of suggestions for both finding and hardening a VPN to reduce its attack surface. Some of these recommendations include finding a VPN that supports strong authentication, digital certificates, logging and auditing, and an intrusion prevention system. After finding a VPN that supports these important features, it\u2019s important to have a knowledgeable network engineer put these measures in place before deploying the VPN.<\/p>\n<h3>4. TAKE PRECAUTIONS AGAINST ZERO-DAY VULNERABILITIES, RANSOMWARE, AND OTHER MALWARE.<\/h3>\n<p>Just as a bad actor could move through a VPN-protected network after gaining unauthorized access, the same can be said for malware. While VPNs can serve as useful security tools to prevent man-in-the-middle attacks and general eavesdropping, they cannot prevent, detect, or eliminate malware moving through a network.<\/p>\n<p>This is where your organization\u2019s corporate data security policies should come back into play, and more specifically, its policies on devices. It\u2019s imperative that business VPNs are only used on company hardware that has anti-virus and anti-malware pre-installed on the device. Because a VPN can facilitate the spread of malware through a corporate network, similar to how a VPN needs to be properly configured before deployment, IT leaders need to ensure that any hardware that will make use of the VPN is properly protected against ransomware and other forms of malware before ever connecting to the VPN hardware or installing a VPN client. Furthermore, it\u2019s important that employees are continuously educated to prevent the spread of malware via phishing attacks and\/or compromised credentials.<\/p>\n<p>Lastly, it\u2019s vital that your business VPN is continuously updated promptly after its deployment. Zero-day vulnerabilities are being exploited more than they\u2019ve ever been before, with\u00a0<a href=\"https:\/\/www.mandiant.com\/resources\/zero-days-exploited-2021\" target=\"_blank\" rel=\"noopener\">Mandiant Threat Intelligence<\/a>\u00a0having identified 80 zero-day vulnerabilities exploited in the wild in their most recent report\u2014more than doubling the record previously set in 2019\u2014and a similar report by\u00a0<a href=\"https:\/\/www.technologyreview.com\/2021\/09\/23\/1036140\/2021-record-zero-day-hacks-reasons\/\" target=\"_blank\" rel=\"noopener\">MIT Technology Review<\/a>\u00a0having found 66 exploits by roughly the end of Q3 2021. Ensuring that software updates and patches are regularly applied to your VPN as soon as they become available is an important way to mitigate the threat of zero-day exploits<\/p>\n<h3>5. TEST YOUR VPN\u2019S CAPABILITIES AND MONITOR ITS USAGE.<\/h3>\n<p>Before finally deploying your organization\u2019s VPN, testing its capabilities and fully understanding how it will handle user traffic is wholly necessary. Particularly if your organization plans on using an on-premises network access server (NAS) to connect end-users to its VPN, then it should be understood that it has a limited amount of bandwidth. And while security should remain the top priority in a VPN\u2019s configuration, the use of more security features can mean more latency. If poor network performance causes a dip in work efficiency, that can have negative implications for your organization.<\/p>\n<p>To combat the possibility of poor network performance, organizations should test how their VPNs handle user traffic before deployment\u2014regardless of where their NAS is located\u2014and continue to monitor fluctuations in traffic after deployment. By understanding when an organization\u2019s user traffic is at its highest, who is sending and receiving the most data, and where that data is coming from, IT leaders can adjust traffic filtering, block certain sites that generate too much data, and adjust other VPN configuration settings accordingly to accommodate high user traffic.<\/p>\n<p class=\"blog-tags\">Tags:\u00a0<a href=\"https:\/\/digitalguardian.com\/blog\/search\/privacy\">Privacy<\/a>,\u00a0<a href=\"https:\/\/digitalguardian.com\/blog\/search\/virtual-private-networks\">Virtual Private Networks<\/a>,\u00a0<a href=\"https:\/\/digitalguardian.com\/blog\/search\/cybersecurity\">Cybersecurity<\/a>,\u00a0<a href=\"https:\/\/digitalguardian.com\/blog\/search\/data-privacy\">Data Privacy<\/a><\/p>\n<p>Source:<a href=\"https:\/\/digitalguardian.com\/blog\/5-virtual-private-network-vpn-best-practices-2022\">Robbie Araiza<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"tx-excerpt\">Learn about VPNs, why organizations are using them so much more, and what IT leaders can do to help ensure their security. &nbsp; WHAT IS A VPN AND WHY DO ORGANIZATIONS USE THEM?","protected":false},"author":3,"featured_media":1317,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[13],"tags":[],"class_list":["post-1316","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/dt-corp.com.vn\/wp-content\/uploads\/2022\/06\/c-users-mumo-downloads-privecstasy-cxlqhmqy3my-un.jpeg","_links":{"self":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1316"}],"version-history":[{"count":1,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1316\/revisions"}],"predecessor-version":[{"id":1318,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1316\/revisions\/1318"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/media\/1317"}],"wp:attachment":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}