Why Consumer VPNs Aren't Business-Grade
Virtual private networks (VPNs) used to be the sectional province of the Information technology professional, providing secure links not just to road warrior employees and telecommuters simply besides to securely tie buildings and multiple corporate campuses to a central information center. But in recent years, consumers have discovered VPNs and their security and privacy benefits, which have resonated greatly plenty that many consider a consumer-form VPN just as essential to a basic device setup as they do a web browser. PCMag recently published a VPN review roundup that provides a comprehensive await at VPNs that can provide the privacy and anonymity you may want when browsing the net or finding content options that aren't available from your location.
That's considering a VPN provides a secure pathway through the cyberspace to some other server. This is accomplished by running an application on your desktop figurer or mobile device that handles the encryption and sets up the tunnel to the remote server. From at that place you can admission material on the internet, but someone in between you and that remote server can't see what you're doing. Additionally, because your actual contact signal to the cyberspace is originating from that server and not your personal device, it'due south more than difficult to track the actual user than information technology would be if y'all connected to the web straight since the IP address associated with the session belongs to the server, not you.
That all sounds much more than secure than your usual consumer internet session and it is. Merely just because a VPN can provide a connection to another server doesn't hateful it's an advisable solution for handling sensitive corporate information. From a corporate perspective, in that location's a lot more involved than just a connection to a server.
Types of VPNs
Commencement, it's important to know that there's more than one type of VPN. For nearly companies, VPN apply began as a remote access connection to a dedicated VPN gateway. The secure connectedness used the internet for ship, but the encrypted tunnel it created led but between your computer or other device and the VPN gateway. When that tunnel was created, you became role of the visitor network: you lot could access the visitor servers and you had a company IP address. The network extended securely to your machine.
With a remote admission gateway, your connection to the internet, if whatever, was through your company's internet gateway. These connections were provided by using defended hardware, and were oft provisioned by an internet service provider (Isp) or major telecom. They were expensive and sometimes hard to manage, but they were secure.
VPN services are attractive because they're relatively cheap, easy to prepare (at to the lowest degree for the user), there'due south little management once they're running, and they're widely available. So why not reach your company's data through a VPN service?
"The VPN network might be secure, but what happens when information technology leaves there?" asks Jack Gilded, Principal Annotator at tech manufacture analyst business firm J. Gilded Associates. "What happens when you run the connection to your corporate network?"
And therein lies the trouble. Using a consumer VPN to access your corporate network solves merely half of the problem. Yous may have a secure connection to the VPN server but what kind of connection do you take betwixt the VPN server and your corporate network? In may cases, information technology may merely exist an unencrypted internet connection or maybe information technology will take Secure Sockets Layer (SSL). But for sensitive data, you need more than that.
Why You Need a Business VPN
What you demand is a concern VPN. Just that doesn't mean that yous need an onetime-fashioned remote access gateway, although that may be an option in some cases. Fortunately, there are also other options.
A remote access gateway can make a lot of sense if what you need to do is connect a remote office network to the corporate network through the internet. In that location are a number of VPN appliances that tin can exercise this for you, from companies you know, including Cisco, Linksys, TP-Link, and WatchGuard. They're available for organizations of pretty much any size.
A more flexible solution is a VPN service that operates much like the consumer services, only which is designed for the needs of business users, including the need to protect sensitive information on its entire trip to the corporate network. These providers include some of the consumer VPN providers, notably NordVPN, which non only earned an Editors' Pick but also a rare five-star editor rating in our consumer VPN review roundup.
NordVPN for business starts where the company'southward consumer product ends, providing a secure connexion to the corporate network and tin can even provide a dedicated server. You also take central assistants, cardinal billing, and a dedicated account and helpdesk support team.
Of course, in that location are providers other than NordVPN, including some of the companies in our review roundup. What's important is that you ostend that they're really suitable for your concern. This means meeting Payment Card Industry (PCI) rules if credit card information volition travel over the VPN. You lot must also come across requirements for protecting personally identifiable information (PII), Health Insurance Portability & Accountability Act (HIPAA) rules for medical and electronic medical tape and other health data, and in some cases, US Securities and Exchange Committee (SEC) regulations.
How to Run into VPN-Related Requirements
So, how exactly do you meet these requirements? Aureate suggests request the following questions:
-
Who is certifying the encryption? You must know that the encryption meets the standards your business is required to meet.
-
How was it tested and who did the testing? Testing is expensive, so some providers may non desire to spend the money. You don't desire those providers.
-
Where is the server? Crossing national boundaries tin often exist problematic, non but for performance reasons but also when addressing some compliance needs.
-
How do they connect to your corporate network? Information technology needs to see those same standards of protection that the rest of your business must meet.
-
What kind of logging is performed? Logs can exist subpoenaed, which is why consumers don't like them. Just businesses may be required to keep logs for the very compliance regulations you're trying to meet. You lot demand to know this.
Y'all also demand to know what kind of back up you'll get, especially if the VPN goes downwardly right as you're getting ready to run your employee payroll for the month. You'll want to know how easy information technology is to set up and configure the VPN endpoints.
Protecting your company with a VPN really isn't optional, unless you don't permit whatsoever operations to have place remotely. Since that's not very practical, information technology pays to find a VPN that volition piece of work for your visitor and start using it. While a consumer VPN might be better than having goose egg at all, the fact is, it's probably not good enough to keep you lot and your concern out of trouble.
Source: https://sea.pcmag.com/nordvpn/29590/why-consumer-vpns-arent-business-grade
Posted by: johnsonbigod2001.blogspot.com
0 Response to "Why Consumer VPNs Aren't Business-Grade"
Post a Comment