Zscaler VPN Report Finds Nearly Half of Organizations Are Concerned About Enterprise Security Due to Unsafe VPNs

In This Article:

Zscaler, Inc.
Zscaler, Inc.

Insecure VPNs, Email, and End User Devices Identified as Primary Attack Vectors, Stressing the Need for a Zero Trust Architecture

  • 88% of companies report being concerned that VPNs jeopardize their ability to maintain a secure environment

  • 90% of organizations are apprehensive that attackers will target them through third-party-owned VPNs

  • User satisfaction is also low, with 72% of users expressing frustration due to slow and unreliable VPN connections

SAN JOSE, Calif., Aug. 01, 2023 (GLOBE NEWSWIRE) --  Zscaler, Inc. (NASDAQ: ZS), the leader in cloud security, today revealed the findings of its annual VPN Risk Report, produced by Cybersecurity Insiders, which shows that a resounding number of organizations are expressing deep concerns about their network security due to the risks from VPNs. The report includes a survey of 382 IT and cybersecurity professionals in multiple industries and explores their security and user experience challenges. The report stresses the need for organizations to reevaluate their security posture and migrate to a Zero Trust Architecture due to the increasing threat of cybercriminals exploiting VPN vulnerabilities.

“The report shows 92% of survey respondents recognize the importance of adopting a Zero Trust architecture; however, it is concerning to see many organizations are still using a VPN for remote employee and third-party access, inadvertently providing a juicy attack surface for threat actors,” said Deepen Desai, Global CISO and Head of Security Research, Zscaler. “Legacy firewall and VPN vendors are spinning virtual VPNs in the cloud and claiming that it is Zero Trust, and they go the extra length to hide the word "VPN". Customers need to ask the right questions to make sure that they are not getting a false sense of security with these virtualized legacy offerings in the cloud. To safeguard against evolving ransomware attacks, it is critical for organizations to eliminate the use of VPNs, prioritize user-to-app segmentation, and implement an in-line contextual data loss prevention engine with full TLS inspection.”

VPN Vulnerabilities Underscore the Need for a Zero Trust Architecture
88% of organizations express deep concern over potential breaches due to VPN vulnerabilities. More specifically, organizations are most concerned with possible phishing attacks (49%) and ransomware attacks (40%) as a result of regular VPN usage.

Nearly half of the organizations reported they have been targeted by cyber attackers who were able to exploit a VPN vulnerability like outdated protocols or data leaks, with one in five experiencing an attack in the past year. Ransomware, in particular, has emerged as a significant adversary for organizations, with 33% falling victim to ransomware attacks on VPNs within the past year.