IPsec VPN: a shield against state-sponsored threats

  • Defence
  • Cyber

© 123RF

  • Type Insight
  • Published

More than half of French companies believe that the threat of state-sponsored cyberattacks is increasing. Against a backdrop of international instability, 40% consider cyber espionage to be a high risk, according to the latest annual CESIN barometer. ANSSI has also observed continued efforts by state-sponsored actors to target critical infrastructure through remote access for strategic intelligence purposes.
Current geopolitical tensions are increasing the cybersecurity risks facing your organisation, particularly when it comes to employees’ remote access. More than ever, VPNs remain the first line of defence against threats targeting remote access.

Remote access: A target for state-sponsored actors

Without a VPN, remote access can become an entry point into your organisation's IT environment, particularly when employees use public networks or unencrypted connections. These types of access are particularly attractive to state-sponsored actors seeking to infiltrate corporate networks. Once inside, attackers can remain undetected for several weeks, gathering intelligence, stealing intellectual property and technological plans, or carrying out destabilisation operations against strategic infrastructure.

This is why the NIS2 Directive identifies the security of remote access as a specific security objective and requires covered entities, among other measures, to encrypt their communications. A VPN is therefore an essential tool for meeting this requirement.

A VPN (Virtual Private Network) creates an encrypted tunnel between an employee's device and your organisation's IT system. It encrypts all exchanged data and authenticates the connection between the device and the company's server, regardless of where the employee is working.

Further evidence that state-sponsored actors are targeting remote access can be found in ANSSI's latest Cyber Threat Landscape. According to the report, state-sponsored actors massively exploited zero-day vulnerabilities in a commercial enterprise VPN solution before the vendor had even released a security patch. The attackers were then able to move laterally within compromised networks and gain access to internal resources.

Not all VPNs are created equal

Unfortunately, the vast majority of VPN solutions are not capable of protecting your organisation against state-sponsored actors, who have advanced technical expertise and considerable resources at their disposal.

Many organisations are tempted to turn to free VPN solutions, particularly in a challenging budget environment. However, these solutions may not provide an adequate level of security and can even facilitate data compromise. According to an ICSI study, 75% of free VPN services include trackers that allow providers to resell connection data. Another study found that 88% of free VPNs leak data, either intentionally or unintentionally. They therefore create a false sense of security that can expose your organisation rather than protect it.

Some paid professional VPNs still rely on outdated protocols such as PPTP, developed by Microsoft in the 1990s, whose encryption (RC4, 128-bit key) and authentication mechanism (MS-CHAPv2) have been considered obsolete for more than a decade. Some L2TP/IPsec configurations relying on pre-shared keys also present similar weaknesses. Simply paying for a VPN is therefore not enough: the underlying protocol is what determines its actual level of protection. Indeed, the use of the SSL VPN, which acts as a public access point to the internet, makes the gateway itself a more prominent target and therefore more vulnerable to attacks (such as scanning and exploitation of vulnerabilities in the web portal).

To secure remote access and withstand state-sponsored interference attempts, your VPN should rely on a protocol designed to meet these requirements. The combination of IPsec, which encrypts and authenticates data at the network level, and the IKEv2 key exchange protocol provides a robust configuration for achieving this level of security. Beyond the protocol itself, authentication plays a critical role. A VPN based on a certificate rather than a password helps mitigate the risks associated with stolen credentials.

Against the backdrop of geopolitical instability, state-sponsored cyber threats are increasing and primarily targeting remote access. In this context, choosing the right VPN plays a crucial role in protecting your organisation. A VPN that integrates an IPsec/IKEv2 combination, coupled with dual certificate authentication – for both the device and the user – offers a very high level of security. This is the approach taken by Cybels VPN, a sovereign VPN developed by ERCOM that combines this protocol with certificate-based authentication to meet the security requirements of organisations most exposed to today's geopolitical tensions. Furthermore, Cybels VPN is already preparing for the transition to post-quantum mode, to withstand future attacks from quantum computers.