A VPN (virtual private network) creates an encrypted tunnel between a device and a VPN server, protecting traffic on untrusted networks.
How a VPN works
The VPN client encrypts all traffic and sends it to a VPN server, which forwards it to its destination. Websites see the IP address of the VPN server instead of yours, and the local network – for example public Wi-Fi – sees only encrypted data. Common protocols are WireGuard, OpenVPN and IPsec/IKEv2. There are two main uses:
- Corporate VPNs – remote employees connect to the internal company network, or offices are connected site-to-site.
- Consumer VPNs – services that hide your traffic from local networks and internet providers and let you choose a country for your IP address.
Why VPNs matter for security
A VPN protects against eavesdropping on the local network, but it moves trust to the VPN provider, who can see your traffic. It does not make you anonymous and does not protect against phishing or malware. Free VPN apps have been caught selling data or containing malware.
For companies, VPN gateways are among the most attacked devices on the internet. In recent years critical vulnerabilities in Ivanti Connect Secure, Fortinet FortiGate SSL-VPN, Cisco, Palo Alto Networks and other products were exploited en masse by ransomware gangs and state-sponsored groups, often before patches were available. Stolen VPN passwords without MFA are another common entry point.
Best practices
- Patch VPN appliances immediately and follow vendor and CISA advisories.
- Require MFA for every VPN login and restrict access to what users need; consider zero trust access (ZTNA).
- Choose paid, audited VPN providers with a clear no-logs policy for personal use.