Remote access: Which VPN can balance security and user experience?
© Ercom-Illustrator
Remote working is now firmly embedded within organisations. More than 63% of people in France worked remotely in 2025. However, this way of working also represents a significant source of cyber risk. Remote and multi-site access expands the attack surface at a time when 40% of organisations have experienced a significant cyber attack over the past year. How can you provide remote employees with secure access to your company's resources without compromising productivity?
Remote working takes many forms: working from home, mobile working, co-working spaces, and more. It also applies to organisations operating across multiple geographically dispersed sites.
When employees access company resources from home or public locations, they connect through networks over which the IT department has no control. Every connection point outside the organisation's perimeter represents a potential entry point for cybercriminals.
For example, if an employee uses the public Wi-Fi in a café, the data exchanged with colleagues, customers, or partners over that network may be intercepted by malicious actors. This well-known cybercriminal technique is referred to as a Man-in-the-Middle (MITM) attack.
As a result, data confidentiality cannot be guaranteed. Attackers may also alter data, corrupt information, or inject malicious content in an attempt to gain access to your organisation's information systems.
For IT leaders, the challenge is twofold: securing remote access while ensuring that teams can continue to work efficiently. If a security solution is too restrictive, employees may find ways around it, ultimately increasing the organisation's exposure to risk.
What is a VPN?
A VPN (Virtual Private Network) is the benchmark solution for securing remote working. Its principle is straightforward: it creates a secure tunnel between the user's device and the corporate network. All data travelling through this tunnel is encrypted end-to-end. Even if a cybercriminal were able to intercept the traffic, they would be unable to decrypt or read the information.
Access to the tunnel is protected through enhanced user authentication. As a result, only authorised individuals can connect to company resources.
There are two main categories of VPN:
- Remote Access VPNs, which connect a user's device to the corporate network via a secure tunnel (typically using IPSec or SSL/TLS protocols). Employees can therefore access company resources regardless of where they are working.
- Site-to-Site or Multi-Site VPNs, which permanently connect multiple geographical locations. They create a unified and secure network between different company sites and primarily rely on the IPSec protocol.
Their common advantage is centralised access management. The IT department can grant, modify, or revoke network permissions in real time across all users and locations.
Other variants also exist, such as SSL/TLS VPNs, which can be accessed directly through a web browser without installing software on the device, and MPLS VPNs, which are commonly used in large-scale network infrastructures. However, remote access VPNs (IPSec or SSL/TLS) and site-to-site/multi-site VPNs (IPSec) are generally best suited to securing remote working environments.
How does a VPN secure remote access?
VPNs incorporate several layers of security to protect remote and multi-site access. First, they provide end-to-end encryption for data in transit. However, organisations should be aware that the computational power of emerging quantum computers may eventually enable cybercriminals to break traditional encryption algorithms. To provide long-term protection, organisations should consider VPN solutions offering Quantum-Safe cryptography, designed to withstand the capabilities of quantum computing.
VPNs also enable IT departments to define user-specific access rights. When combined with multi-factor authentication (MFA), this ensures that only legitimate users can connect to the corporate network.
Some enterprise VPN solutions include additional security mechanisms such as firewalls to filter traffic and block unauthorised connections, traffic monitoring tools to provide real-time visibility of data flows, and anomaly detection systems capable of identifying and automatically blocking suspicious activity.
These security measures make VPNs a valuable compliance tool for organisations subject to regulations such as the NIS2 Directive, or those seeking certification against recognised standards such as ISO 27001. In some cases, regulations such as NIS2 may require organisations to adopt sovereign solutions. Choosing a French VPN certified by ANSSI can therefore be essential to ensure that company data remains under French jurisdiction.
The importance of user experience
Security should never come at the expense of productivity. One of the most common criticisms of VPNs is their impact on user experience, including slow connections, unexpected disconnections, and reduced performance. However, the latest generation of VPNs has largely addressed these challenges.
Modern solutions reduce latency through advanced protocols and intelligent traffic routing. As a result, employees can access company resources with the same level of responsiveness they would expect in the office, regardless of their location.
Centralised management enables organisations to deploy VPN services at scale through a single interface, supporting thousands of geographically dispersed users. IT teams retain full control over access rights and can, for example, immediately revoke permissions when an employee leaves the organisation.
Some VPN solutions rely on a gateway appliance that centralises and secures all communications between employee devices and the corporate information system. This gateway enables remote device management and supports scalability when additional users or sites need to be connected. It can also be configured with redundancy, ensuring that if one appliance fails, another automatically takes over and maintains uninterrupted access.
Ideally, organisations should choose an enterprise VPN that integrates seamlessly with their existing environment, including Single Sign-On (SSO) solutions, Active Directory directories, and Mobile Device Management (MDM) platforms, helping to preserve a smooth digital experience for employees.
The widespread adoption of remote working has created new opportunities for cybercriminals, who continue to develop increasingly sophisticated methods for stealing corporate data. VPNs provide a simple yet highly effective way to prevent MITM attacks and secure remote access, provided the right solution is selected.
Cybels VPN is an IPSec VPN solution that secures communications between remote sites up to ANSSI's "Restricted Distribution" classification level. Cryptosmart PC secures connections to and from PCs, protecting remote access environments. It also holds the ANSSI Restricted Distribution certification (currently under renewal) and incorporates Quantum-Safe cryptography to withstand the most advanced cyber threats.
Contact us to learn more about these solutions.