In 2020 almost every company sorted out remote working in the same way: a VPN on the firewall, one username and password per employee, and everyone started “being in the office” from home. It worked — and that is precisely the problem. A classic VPN connects the remote computer to the company network as if it were physically there: with access to servers, shared folders, printers and everything else the network has. Anyone who gets in with stolen credentials gets in with the same level of access. This article explains why the VPN, on its own, is no longer a sufficient answer and what replaces or complements it in an SME.
What a VPN does well — and what it doesn't
A VPN does one thing well: it encrypts the connection between the remote computer and the company, so that no one in a coffee shop or hotel can read the traffic. What it does not do is verify who is on the other side apart from the password, check the state of the connecting computer (is it updated? with antivirus? personal or company-owned?) nor limit what that computer can access once connected. It is a door with a good lock that opens into the whole house.
The three real risks
- Stolen credentialsmost attacks on Portuguese companies start with a phishing email that tricks someone into typing their password into a fake website. If that same password also opens the VPN, the attacker is inside the network without having to force anything.
- Personal computer compromiseda home laptop, shared with the family, without updates, connects to the VPN and brings along whatever it's picked up. The company network treats it like an internal workstation.
- Lateral movementOnce inside, the attacker looks for the file server, management software and backups. On a flat network, they reach everything in minutes. That is how most of the SME ransomware cases we know about started.
First step today: MFA on the VPN
If your VPN only accepts a username and password, the most urgent measure is to add a second factor — a code in a mobile app or an approval notification. Almost all corporate firewalls support this at no additional licence cost, or via an integration with Microsoft 365. With MFA, a stolen password is no longer enough. We explained how to implement it in the article on multi-factor authentication in the company.
Second step: check the equipment, not just the person
Remote access must also depend on the computer. The simplest rule: only company devices, managed and with active protection, access the internal network. Personal devices access email and files in Microsoft 365 via the browser, with conditional access, without entering the network. This separates two worlds that the classic VPN mixes together: working with company data and being inside the company's infrastructure.
Third step: application access instead of network access
Most remote workers need three or four things: email, files, management software and perhaps a remote desktop. None of these require being “on the network”. Email and files are already in Microsoft 365. Management software can be published via a portal or a remote desktop with strong authentication. Each access is to a specific application, logged, and does not pave the way for the rest. The VPN is reserved for those who really need to administer servers or equipment — usually the IT team — and even then with MFA and from managed devices.
Fourth step: segment what the VPN reaches
As long as the VPN exists, the segment where remote users land must not have direct access to backup servers, cameras, industrial equipment or the management network. This is done with VLANs and firewall rules — the exact same work we described in VLANs and network segmentation and in the article about Zero Trust for SMEs. If a remote laptop is compromised, the damage is contained.
What about the external suppliers?
The management software vendor, the EPOS technician, the CCTV installer: they all ask for “VPN access” and almost never return it. Each one must have their own account, with MFA, with access only to the server or equipment they support, active only during the intervention and logged. In the audits we carry out, forgotten vendor access is one of the most frequent findings.
How it works in practice in an SME
A typical scenario with 40 workstations and 10 people working remotely on a regular basis: Microsoft 365 with MFA and conditional access for email and files; management software published in a remote desktop environment with MFA; VPN maintained for just two administrators, with MFA, landing on a management VLAN; vendor access created on an intervention basis. Licence cost: little to no extra cost above what the company already pays. What changes is the architecture and who manages it. In the contracts IT Unlimited this drawing is part of the service and the firewall is managed and monitored by us, with the alerts handled by people.
Frequently Asked Questions
Should I turn off the VPN?
Not straight away. First add MFA and limit what it reaches. Then start moving access to published applications. Finally, the VPN is left for those who administer systems — a few people, well identified.
Is remote access to the desktop environment secure?
Well, if it's behind strong authentication and not directly exposed to the Internet. A Remote Desktop server with the port open to the world and only a password is one of the preferred targets for automated attacks.
Can I allow personal equipment?
For email and files in the browser, with conditional access and no local download, yes. For logging on to the internal network, no. It is the separation between working with the data and being inside the infrastructure.
Does this require buying a new solution?
In most SMEs, no. It requires better configuration of the firewall and Microsoft 365 that are already in place and, above all, someone to manage access on an ongoing basis.
Do you want to review your company's remote access?
We analyse who enters, with what credentials and what they have access to, and deliver a written plan to close any remaining doors. See our managed firewalls for businesses or call 211 459 950.





































