The VPN That Was Never Really a VPN

The company had a “VPN.” At least, that’s what they thought. In reality, they had RDP ports exposed to the internet, legacy protocols with no modern encryption, and zero multi-factor authentication. A misconfigured VPN does not protect you — it creates a false sense of security that can be more dangerous than having nothing at all.

The problem with improvised remote access

During the 2020 pandemic, thousands of companies deployed remote access solutions in days or weeks, with no security planning. Four years later, many of those improvised implementations are still running — unreviewed, unpatched, with the same emergency configurations from 2020. The threat landscape changed dramatically. The remote access infrastructure did not.

Exposed RDP: ransomware’s favorite entry point

The Remote Desktop Protocol (RDP, port 3389) is the most widely used remote access tool in Windows environments. It is also the most exploited entry vector by ransomware operators over the last five years. When RDP is exposed directly to the internet — without a real VPN, without IP restrictions, without MFA — any malicious actor can attempt brute force against user credentials. Automated attacks scan the entire internet IP range looking for open port 3389. If your server has that port accessible from the internet, it is being scanned right now.

In 2024, 63% of ransomware incidents in Latin America had misconfigured RDP as the initial entry vector, or involved RDP credentials purchased on dark web initial access markets.

What makes a VPN real

  1. Modern encryption: OpenVPN with TLS 1.3, WireGuard, or IPSec with IKEv2. Legacy protocols like PPTP offer no real security.
  2. Multi-factor authentication: a compromised password should not be enough to access the corporate network.
  3. Least-privilege access: VPN users should only access the resources they need, not the entire internal network.
  4. Logging and monitoring: every VPN connection must be logged with user, time, source IP, and duration.

Signs your VPN is not what you think it is

  • Your employees connect “to the remote desktop” directly, without going through a VPN first.
  • The Windows password is the only thing protecting remote access.
  • You do not receive alerts when someone repeatedly fails authentication.
  • Any VPN user can access any company server.

The fix is not complicated

Migrating from improvised remote access to a properly configured corporate VPN is a days-long implementation project, not months. The cost of implementing a proper corporate VPN is a fraction of the average cost of a ransomware incident, which in 2024 averaged $847,000 in losses for mid-sized companies globally.

Do you know exactly which ports your company has open to the internet? AVN Networks conducts remote access exposure assessments and designs enterprise VPN solutions for Costa Rican SMBs. Request a risk assessment.

← All articlesTalk to an expert