What the Data Shows
When offices shut down in 2020, businesses everywhere did the same thing in a hurry: they stood up VPN access for anyone who needed to work from home, then kept adding more of it as hybrid schedules became permanent. Four years later, Zscaler’s ThreatLabz 2024 VPN Risk Report, based on a survey of more than 600 IT, security, and networking professionals, put a number on what that left behind. Fifty-six percent of organizations said they’d experienced a cyberattack that exploited VPN vulnerabilities in the past year, and 91% said they were concerned that a VPN could lead to a compromising breach.
The report’s most telling finding isn’t about attacks that already happened, it’s about the access sitting there waiting to be misused. Because VPNs are built to hand out full network access once a login succeeds, 92% of respondents said they were specifically worried about third parties with VPN access, contractors, vendors, former partners, acting as backdoors into systems those third parties had no real reason to reach. That’s not a hypothetical edge case. It’s the design of the tool: a VPN doesn’t usually ask what a user actually needs to touch, it just puts them on the network and lets internal routing sort out the rest.
The consequences of that design show up in the breach data too. Among organizations that were actually compromised through a VPN vulnerability, 53% reported that attackers moved laterally once inside, spreading from the entry point to other systems on the network. That’s a direct result of the same broad-access problem: a single compromised VPN account isn’t a single-system problem, it’s a foothold that can reach almost anywhere the network allows.
None of this describes a single dramatic incident. It describes an accumulated condition, one that built up gradually as businesses added remote access faster than they audited it, and it’s exactly the kind of risk that doesn’t show up until someone goes looking for it.
Why This Matters If You’re Not a Big Company
It’s tempting to read a survey like this as an enterprise problem, since large organizations have more VPN concentrators, more contractors, more moving parts to lose track of. But the underlying dynamic scales down just as easily. A ten-person business that went remote in 2020 likely set up VPN or remote-desktop access for employees, maybe a vendor who helped with the transition, maybe an old contractor who did a project two years ago. Small businesses don’t run identity audits on a schedule the way larger IT departments do, which means that access is more likely to still be there, not less.
The math is simple and unflattering: fewer people means fewer eyes on who still has a login, and a smaller IT footprint often means nobody owns the job of periodically checking. An account that was reasonable to create in 2020 doesn’t announce itself as unreasonable in 2026. It just sits there, working exactly the way it was set up to work, until someone other than its intended user finds it.
What Actually Would Have Stopped This
The fix isn’t a single tool, it’s a mindset shift: access should be reviewed on a schedule, not left to exist until someone remembers to remove it. That means a recurring check, quarterly is reasonable for most small businesses, of who has VPN or remote access, whether they still need it, and whether that access grants more of the network than their actual job requires. A departing employee or a finished vendor contract should trigger an access removal the same day, not whenever someone happens to notice.
The deeper fix is moving away from the assumption baked into traditional VPNs, that a valid login should mean broad network access. Zero Trust approaches, which grant access to specific applications or systems rather than the whole network, directly address the exact worry that 92% of the survey’s respondents raised about third parties: even if a credential is compromised or a former contractor’s login is still active, the blast radius stays small because there was never a wide-open network to move laterally across in the first place.
Security Checklist for Your Business
Run a quarterly access review. List everyone with VPN or remote access and confirm each one still needs it, not just that the account still works.
Kill access same-day on offboarding. Employee departures and vendor contract endings should trigger immediate removal, not a cleanup task for later.
Scope access to what’s needed. Move away from all-or-nothing VPN access toward tools that grant specific application access instead of the whole network.
Treat third-party access as higher risk by default. Vendor and contractor accounts deserve extra scrutiny and shorter renewal cycles than employee accounts.
Remote access tools don’t expire on their own, and nobody schedules time to notice the ones nobody’s using. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: Zscaler, “New VPN Risk Report: 56% of Enterprises Attacked via VPN Vulnerabilities”.



