# VPN security: why the protection became the entry point

**VPN security** now sits at the centre of the ransomware problem. The infrastructure built to protect remote access has become the preferred way in. The At-Bay InsurSec 2025 report found that companies running Cisco or Citrix VPNs face 6.8 times the probability of a ransomware attack compared with organisations where no VPN was detected. The pattern is broad: 80% of ransomware attacks recorded in 2024 began with a remote access tool, and 83% of those cases involved a VPN device.

## The risk ranking

Cisco and Citrix lead at 6.8 times. SonicWall follows at 5.8 times, with attacks by the Akira group up 300% in the third quarter of 2024. Palo Alto GlobalProtect sits at 5.5 times and Fortinet at 5.3. Generic on-premise VPNs carry 3.7 times the risk of cloud alternatives or no VPN at all. Adam Tyra, CISO at At-Bay, frames it as a maintenance problem rather than a product flaw: the devices are complex, they need constant upkeep, and many organisations install them correctly but few keep them patched and configured over years.

## Italy in the crosshairs

Italian data reflect the global trend and amplify it. The National Cybersecurity Agency recorded 146 confirmed ransomware cases in 2024, up 70% on 2023. Italy ranks fourth in Europe for attacks, with 12% of the continental total, and ninth worldwide. The median ransom demand rose 7% to USD 695,000, while victims pay on average 34% of the initial figure. The geographic concentration matters for Italian business: the industrial districts of Lombardy, Veneto and Emilia-Romagna sit at the epicentre.

Manufacturing accounts for 12.5% of attacks, IT and technology services for 11.8%, and professional services for a share that reaches 26% globally. Italian manufacturing carries two structural weaknesses: legacy technology in operational environments and weak security governance, with small and medium businesses short of dedicated internal skills.

## How attackers use a VPN

Ransomware groups follow a playbook that spread from an initial access broker in the summer of 2023. The document abandoned zero-day hunting in favour of repeatable, scalable methods. Attackers scan the internet in bulk for exposed VPNs, then test accounts with weak or default credentials such as admin, test and user, and look for installations without multi-factor authentication.

Corvus reported in the third quarter of 2024 that almost 30% of ransomware attacks used VPN vulnerabilities and weak passwords for initial access. Once inside, attackers install tools to harvest more credentials and move laterally. Before encrypting, the more advanced groups exfiltrate data and run double extortion: a ransom for decryption, a threat to publish what they stole. The Fog group, active from April 2024, showed that SonicWall VPNs can be reached even with MFA enabled. Arctic Wolf documented 30 intrusions from compromised SonicWall accounts, 75% attributed to Akira.

## Why modern VPNs are so exposed

Complexity is the enemy of security, and enterprise VPNs have accumulated complexity. Early devices did one thing: build an encrypted tunnel. Today the same box is a next-generation firewall, a router, a proxy, an SSL inspection engine, an application control layer and an intrusion detection system. The shift to remote work after 2020 accelerated the adoption of these multifunction appliances and multiplied the configuration surface. Every added function creates another path in and demands specialist skills to manage safely.

Maintenance is where the model breaks. The Coalition Cyber Threat Index 2025 found that 58% of ransomware attacks start from a compromised perimeter security application, 47% use stolen credentials and 29% exploit software vulnerabilities. The cycle repeats: vendors publish critical patches, organisations delay applying them for fear of disruption or for lack of a maintenance window, and attackers work inside the gap. CVE-2024-40766 in SonicWall, rated 9.8, was published in August 2024 and was still widely exploited a year later.

## Hardening the VPNs already in place

Multi-factor authentication belongs on every VPN account, with hardware tokens or authenticator apps preferred; SMS is the weakest option because of SIM-swap attacks. Password policy needs a minimum of 16 characters, rotation every 90 days, automatic lockout after five failed attempts and a ban on default account names. Access must be segmented: separate VLANs for remote users, zero-trust verification at every request rather than only at login, and role-based access with least privilege.

Detection matters as much as configuration. At-Bay describes managed detection and response as the one service that consistently blocks full encryption. A small business can start with a SIEM collecting VPN logs, firewall events, endpoint data and directory activity, and watch for specific signals: logins from anomalous locations, concurrent sessions on the same account, access outside working hours, outbound traffic spikes that suggest exfiltration, and the use of administrative tools such as PsExec or remote PowerShell.

Patch management closes the loop. VPN vulnerabilities are typically exploited within 7 to 14 days of a fix being published. A workable process patches automatically where possible, tests in a non-production environment, applies critical fixes within 72 hours, and keeps a register of what was applied. Subscribing to vendor security feeds such as Cisco PSIRT, SonicWall Security Advisories and Fortinet PSIRT is the cheapest early-warning system available.

## Zero Trust alternatives

For organisations with limited IT resources, the maintenance load of on-premise VPNs can be unsustainable. SASE, Secure Access Service Edge, folds networking and security into a cloud-native service with centralised management, automatic patching, integrated DDoS protection and no public endpoint to defend. ZTNA, Zero Trust Network Access, grants granular access to individual applications rather than to the network, validating every request against user identity, device state and context such as location, time and behaviour.

## What NIS2 requires

The NIS2 Directive, EU 2022/2555, took effect across Europe on 16 January 2023. Italy transposed it with Legislative Decree 138 of 4 September 2024, in force from 16 October 2024. The National Cybersecurity Agency estimates around 50,000 Italian entities fall inside the new perimeter, split between essential and important subjects. Obligations include registration on the ACN platform by 28 February 2025, continuous risk assessment, a documented incident response plan with notification to CSIRT Italia within 24 hours for significant incidents, business continuity and disaster recovery, mandatory training for management and staff, supply chain risk management and vulnerability management. Non-compliance carries administrative penalties up to EUR 10 million or 2% of global annual turnover for essential subjects.

A secure tunnel does not answer a well-written message: [AI phishing as the defining threat of 2026](/en/ecorner/2025/ai-phishing-cybersecurity.html) moves the problem from the network to the person.

## Frequently asked questions

**Are on-premise VPNs inherently insecure?**
The products are not insecure by design. They are complex and need constant maintenance, and the failure rate comes from organisations that install them well and then let patching and configuration drift.

**Can MFA alone stop a VPN attack?**
MFA removes the easiest path, the reused or default password. It does not cover unpatched vulnerabilities or help-desk manipulation, and the Fog campaign reached SonicWall accounts protected by MFA.

**How quickly are VPN vulnerabilities exploited?**
Typically within 7 to 14 days of a patch being published. Critical fixes belong in production within 72 hours where the change can be tested safely.

**Is a cloud or Zero Trust model cheaper for a small business?**
The licence cost can be higher on paper. The operating cost is usually lower, because the provider handles patching, scaling and the public attack surface, and the internal team stops maintaining appliances.

**Does NIS2 apply to a company with fewer than 50 employees?**
Size is the general threshold, but supply chain clauses pull smaller suppliers inside the perimeter when they serve essential or important entities.

## Sources

At-Bay — InsurSec Report 2025, ransomware risk by VPN vendor — https://www.businesswire.com/news/home/20251028246929/en/VPNs-from-Cisco-and-Citrix-Riskiest-Products-for-Ransomware-At-Bay-Rankings-Report
Coalition — Cyber Threat Index 2025, attack origin and perimeter exposure — https://www.coalitioninc.com/announcements/cyber-threat-index-2025
Corvus Insurance — VPN targeting drives ransomware incidents in Q3 2024 — https://www.corvusinsurance.com/pressroom/vpn-targeting-drives-ransomware-incidents-in-q3-2024
Yarix and Var Group — Y-Report 2024, ransomware and sectors in Italy — https://www.vargroup.it
Clusit — annual cybersecurity report on Italy — https://clusit.it/rapporto-clusit/
Agenzia per la Cybersicurezza Nazionale — CSIRT Italia and NIS2 operational guidance — https://www.acn.gov.it
