A personal VPN feels private, but on a company network it can hide risky activity and bypass security controls. Here is why it raises red flags at work and what to do instead.
Key Takeaways
- A corporate VPN is a sanctioned secure tunnel; a personal VPN on a work network sends company data through a tunnel your company cannot manage or verify.
- Attackers frequently use personal VPNs to hide their location and activity, so an unapproved VPN often triggers a security alert and gets shut down immediately.
- Personal VPNs do have a legitimate use on untrusted public Wi-Fi, such as a hotel, but that should be arranged through your IT team.
- Split tunneling lets a company VPN encrypt only the traffic that needs it, which addresses worries about routing everything through the office.
- The simplest fix is communication: tell your IT team or MSP about travel needs ahead of time so they can approve a safe option.
Full Transcript
What Is a VPN, and Why Can a Personal One Create Risk?
Shane Naugher: Welcome back to Give IT To Me Straight, where we cover technology topics, tips, and helpful items to give you a better idea of how to use technology and the safeguards you need to be aware of. I'm excited to kick things off today with Logan Wilson, our rapid response team manager and team lead, so you're getting the person with the most knowledge and direction of the rapid response team. Today we're diving into a topic we get asked about quite a bit, and there are some misunderstandings around it: personal VPNs.
Shane Naugher: If you're not familiar with a VPN, it's basically a secure tunnel back into your corporate network when you're not in the office or you work remotely. Organizations may provide their employees with a VPN, and there's a legitimate use and a proper way to do that. One of the things we want to avoid is using VPNs on our own, without sanctioned approval from corporate, because it introduces risk. So Logan, in your experience, what do you see when it comes to personal VPNs, and what risk do you see?
Why Personal VPNs Raise Red Flags
Logan Wilson: From my end, we see all sorts, from Proton to Nord to some really weird, out-of-the-way VPNs. Where this gives me concern is that if you're using a VPN as an employee, you're sending company data through a tunnel that isn't managed by the company. It's managed by somebody, just not by us.
Logan Wilson: While providers like Nord have a good track record so far, at the end of the day it's a third party the company can't verify one way or the other. Just because they say they're secure doesn't mean there isn't somebody sitting along the line who can run a man-in-the-middle attack to swipe the data you're sending. There's a big loss of control over that data's security and fidelity, and it's just not something you can guarantee as an employee.
The Travel Exception, and How Attackers Abuse It
Shane Naugher: A lot of times, if folks are traveling, there have been tech tips that say you should use a personal VPN so it always encrypts your data. If you're sitting in a hotel using public Wi-Fi, that logic does hold water, because you're connecting to an unknown network. A personal VPN protects you so that someone can't stand up a fake hotel Wi-Fi and capture your data.
Shane Naugher: But something we see frequently with threat actors, the bad guys trying to get to your data, is that when they get into a network they often use these personal VPNs so their traffic is encrypted. From a corporate IT or ownership perspective, you can't tell what they're doing or why. So a lot of times that's a big red flag that something malicious is going on.
Logan Wilson: Absolutely. You can have an employee using a personal VPN at their house, in the same state you're in, and the VPN routes that traffic to make it look like it's coming from California. That sets off all sorts of alarm bells. Now you're asking, "Why is this person suddenly in California? Is this actually this person?" There's no way to know without getting verbal confirmation.
Why IT Shuts It Down, and What to Do Instead
Shane Naugher: With our team, that's one of the things that kicks off an alert for us to respond to: a personal VPN in use that isn't in the approved applications. Our default response is to shut that down immediately. So if you're doing that legitimately, at the very least work with your IT department or your MSP. Tell them, "I'm going to be traveling, spending a lot of time in hotels or on a cruise ship. What should I use to make sure my traffic is safe and I'm not vulnerable?"
Shane Naugher: That way they can give you the approved VPN list. If you're downloading something you found online or through Facebook, who knows what that provider is doing with the data. Go through your IT department, help them understand your travel needs, and they'll set the safeguards up so it doesn't trip alarms and get everything shut down. That's typically how we find out anyway: "Hey, all of my traffic just stopped working."
Logan Wilson: Exactly. At the end of the day it comes down to the company. Some companies don't need to be so strict with their data controls. But some of our clients work with HIPAA or PCI, and there are far more stringent controls around that type of data. It really comes down to being open and honest with your employer and your IT team. If we know ahead of time, we can prevent a lot of that from becoming a headache in the first place.
Split Tunneling, and Communicating With IT First
Shane Naugher: That communication on the front end is the biggest key. Most organizations will have an approved VPN for you. There's a second question that comes up here: corporate VPNs often route your internet traffic through the corporate office, and people worry it will restrict what they can do while traveling. Again, if you communicate ahead of time, those policies can be set so it doesn't have to route all traffic through the corporate network. It can just encrypt your internet traffic, while anything you need on the corporate network goes directly to it.
Logan Wilson: Being able to split that traffic is actually a term called split tunneling. Going back to third-party VPNs, not every one of them tunnels all traffic through their services. The difference is that with a VPN we set up, we know what traffic is going through the firewall. You don't know that with Nord or TunnelBear or something else, and you may be sending things over that tunnel you don't want to. It all comes down to being open and communicative with the people in charge so the right steps can be taken to keep the data protected. We don't want to limit people, but the highest priority is keeping the company's data intact.
Shane Naugher: Absolutely. Going back to threat actors, using personal VPNs is one of their main ways to conceal what they're doing, because you can't see inside that tunnel. That's why it's always flagged as something to look into, and why our policy, and many others, is to shut it down immediately and verify what's going on. You can avoid all of that headache with a little communication on the front end. Well, Logan, I appreciate the information. I look forward to hearing more from you on tech tips our listeners can put to use.
Logan Wilson: Always happy to help, Shane. Glad to talk with you.
Ready to Stop Worrying About IT?
Join hundreds of Missouri organizations who trust DaZZee IT as their technology partner. 25+ years, 80% same-day resolution.
