Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity News

Why Corporations Need to Give Employees Personal VPNs

By Greg Falco
Doorway to Cybersecurity
February 18, 2019

Late last year, the House Energy and Commerce Committee’s Subcommittee on Oversights and Investigations released its Cybersecurity Strategy report, which starts by observing that current IT strategies aren’t working. It then lays out steps to tighten them up. A small piece of this cybersecurity puzzle is ensuring that employees don’t unwittingly provide entree to the corporate ship when they travel for business while surfing the web on their personal time.

Frequent business travelers today need to travel armed and prepared to protect corporate data from cyberattacks. Typically, corporations provide their roaming workforce with a corporate VPN (Virtual Private Network), which locks down the employee’s connection to company network servers when they are using public wifi, like such as in an airport or hotel room. But companies should also supply their traveling employees with a personal VPN. Both are critical for a “Defense in depth” strategy.

Here’s why:

You don’t want employees conducting private business on your corporate VPN because you can’t predict what sites they choose to access, the content they choose to stream or what they choose to re-tweet. Some companies heavily restrict access on their corporate network to a subset of sites, but this is not always feasible due to the nature of some jobs. If employees are engaging in unsavory or illegal activity via the corporate network, the corporation could be at risk.

Conversely, employees want autonomy in their downtime, so they’re less likely to conduct their personal business on the corporate VPN (which should be prohibited). But when employees go off private networks and use public wifi in airports, hotel rooms and cafés, they become a “third party” attack vector to your company. Essentially, they are easy prey not only to having their private information stolen and used by cyber criminals, but as targets for the corporation itself.

Even though its risk has been well-publicized, free wifi is a habit that’s hard to break. I was surprised to learn from a recent PC Magazine article, which cites statistics from a Pew Research Center study, that even though most people claim they’d use a VPN because of the risk about wifi, their desire to access content -- from bank accounts to their Amazon profiles -- overshadows any worries about safety: only 29% in the study have ever used one for personal reasons.

So let’s assume that your employees are using public, unencrypted networks. Cyber criminals could find dirty information on that person and blackmail them into gaining access to your corporate data. If employees use their corporate computer for personal use over public wifi, hackers could gain access to past corporate search history or temporary files that were downloaded for business. The less dramatic and more likely scenario is that your employee is using the same password for his corporate and personal accounts (a common practice), and the hacker listening in on network traffic steals the personal account password. Cyber criminals will then successfully use that information to try accessing the corporate network.

As a reformed blackhat hacker and security researcher at Stanford and MIT, I study and use the cyber kill chain, which is a methodology for how hackers break into systems. Hackers spend most of their time on reconnaissance -- scoping out what information he needs to access corporate services. Employee passwords are an easy catch.

If you think the risk of these scenarios is low, you’d be incorrect. It’s the reality of our world today, and the repercussions are terrible. Corporate travelers to China, for example, are primary targets. United States citizens traveling to China who connect to a network there will be spied on. The government is trying to get information about that person’s employer for corporate espionage (something China has been charged for time and again). Business travelers to China are advised to bring burner devices. But what if your employee is in China for pleasure? Without a personal VPN, your company is still at risk.

This is not a full solution; VPNs are a small part of the total cyber security puzzle. And, while I cannot say for sure how often corporations have been trounced through unprotected networks -- what company would publicize such a breach? -- it has certainly happened. Corporations would be well-served with a “Defense in depth” strategy that provides layers of protection. Minimizing your third-party risk that is your employees while they are off-the-clock by paying for a personal VPN for them is an additional layer of security for your organization. You can market it as a benefit for them, but really, it is for your company’s protection.

 

 

KEYWORDS: cyber security cybersecurity IT security VPN

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Greg falco
Dr. Falco is a security researcher at MIT’s Computer Science and Artificial Intelligence Laboratory, Stanford and Harvard University; he received his PhD in Cybersecurity from MIT. He is the founder and CEO of NeuroMesh, an IoT security company that secures critical infrastructure. Dr. Falco also serves as the security expert at InvinciBull, a leading VPN provider that lets users easily access the data and content they’re looking for without the risk of hacking and tracking.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Digital, tablet and hands

The 2025 Annual Guarding Report: Unrest Inspires Upgrades in Training, Technology

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity predictions of 2026

5 Cybersecurity Predictions for 2026

Code

Security Leaders Discuss the Marquis Data Breach

Digital human mind

Should Organizations Block AI Browsers? Security Leaders Discuss

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

January 14, 2026

Is Your Organization Prepared to Navigate Interconnected Threats in 2026?

The 2026 threat environment will be louder, faster, and more interconnected. The most pressing risks, from global political volatility to emerging tech disruptions, will challenge organizations to act amid ambiguity and protect credibility in an era of accelerating uncertainty.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • smartphone-app-development-freepik.jpg

    Why mobile app developers need to prioritize user data privacy and security — and what they can do to ensure it

    See More
  • Why every CIO should retire their VPNs

    See More
  • Changing the Hoodie Image for Cybersecurity

    No More Hoodies: Why We Need to Attract More Women to Cyber

    See More

Related Products

See More Products
  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing