The Canadian Centre for Cyber Security (ITSAP.80.101) describes a virtual private network (VPN) as a secure connection that can allow remote access to a corporate network, and notes that the security it provides depends on proper configuration and consistent use. The Business firewall page deals with the equipment at the network edge; this one focuses on users, their devices and their access.
Short answer
You describe who works remotely, what they need to access and with which devices: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The access method, rules and schedule are set with you.
What the quote should cover
- An inventory of the resources to make accessible and the user groups
- The proposed access method: VPN, direct access to cloud services or a combination
- Multi-factor authentication for all remote access
- Rules for devices: company-managed computers, personal devices
- VPN configuration: protocol, allowed ports, tunnelling
- Logging and monitoring of connections
- The access removal procedure and the documentation provided
The steps of a remote access project
- Inventory of users, resources and devices
- Choice of access method and rules per group
- Rollout of multi-factor authentication
- Configuration of the VPN or cloud access
- Testing with a pilot group, then rollout
- Documentation, departure procedure and follow-up
VPN or direct access to cloud services
If employees need to reach a server or software installed in your offices, a VPN is the method set out in the Centre's baseline cyber security controls, which recommend requiring VPN connectivity with two-factor authentication for all remote access into corporate networks (BC.9.3). The Centre also recommends IPsec as the primary consideration for VPN access, and notes that TLS VPNs often use custom, non-standard features that can add risk.
If your tools are already in cloud services, such as online email and files, employees connect to them directly and protection relies on identity and device status. The Centre describes this approach in its publication on the Zero Trust security model (ITSAP.10.008): no user or device is trusted by default, and trust is verified every time access to a new resource is requested. The two approaches can be combined.
VPN configuration
- Restrict external access to the VPN device by port and protocol
- Use forced tunnelling where possible: all traffic goes through the VPN
- Avoid split tunnelling, which can create a bridge between the open Internet and the secure tunnel
- Apply patches and new versions to the device and the client software
- Require a privileged access workstation for administrator accounts used remotely
- Protect and monitor access to the VPN, including through logging and network segmentation
These recommendations come from the Centre's publication on virtual private networks. The Centre also notes that a VPN does not protect against a user clicking a malicious link or downloading malicious content: it complements other measures rather than replacing them.
Multi-factor authentication
For VPNs, the Centre recommends activating multi-factor authentication with phishing-resistant factors, such as an authenticator app, biometrics or hard tokens. Choosing methods and rolling them out are covered on the Multi-factor authentication page. For remote access, the quote should state which access points are covered: VPN, cloud services, remote desktop, administration tools.
Company devices or personal devices
In its security tips for organizations with remote workers (ITSAP.10.016), the Centre recommends that employees use corporately owned devices when possible. It points out the risks of personal devices: missing security updates, weak passwords and loss of control over the information they hold.
If personal devices are allowed, the project should specify what they can access and under which conditions, for example only through the browser or through protected apps. Managing company computers, with their updates and encryption, is covered on the Device management page.
Departures and access removal
A forgotten remote access is an open door. The Centre's baseline controls recommend removing accounts and functionality when employees no longer require them for their tasks (BC.12.3). The departure procedure should cover the VPN account, registered authentication factors, open sessions and returned devices. Connection logs then make it possible to check that no access occurred after the departure.
Questions to ask yourself before requesting a quote
- How many employees work remotely, and how often?
- Which resources do they need to reach: local server, software, cloud services?
- Do they work on company computers or on their own devices?
- Do outside vendors also need access?
- Is there already a VPN or remote access in place?
- Who removes access when an employee leaves?
Pitfalls to avoid
- Leaving a remote desktop exposed directly on the Internet
- A VPN without multi-factor authentication
- Enabling split tunnelling by default, without analysis
- Not patching the VPN device
- Allowing personal devices without written rules
- Forgetting vendor accounts and former employees' accounts
What to specify in your request
- The number of remote users and their groups
- The resources to make accessible
- The devices used: company computers, personal devices, phones
- The network equipment and firewall in place
- External access to plan for: vendors, subcontractors
- Logging requirements and the documentation wanted
You can then describe your project: the team will contact you to clarify your needs and provide a quote.
Frequently asked questions
Is a VPN enough to secure remote work?
No. The Canadian Centre for Cyber Security notes that a VPN does not protect against a malicious link or an infected download. It must be combined with multi-factor authentication, up-to-date devices and employee training.
What is split tunnelling?
It means sending part of the traffic through the encrypted VPN and the rest directly to the Internet. The Centre recommends avoiding it as much as possible and using forced tunnelling where possible.
Is a VPN needed if everything is in the cloud?
Not necessarily. If no resources are in your offices, employees can connect directly to cloud services. Protection then relies on multi-factor authentication, device status and the service's access rules.
Can employees use their personal computer?
That is a business decision. The Centre recommends corporately owned devices when possible. If personal devices are allowed, written rules should specify the permitted access and the conditions to meet.
How do we give remote access to an outside vendor?
With a named account, multi-factor authentication, access limited to the resources needed and logging of connections. The account is removed at the end of the engagement.