Skip to content
DEKARTDIGITAL

Insight

Corporate VPN: the ten-point checklist an audit actually runs

Standing up a tunnel is an evening's work. Everything else — the access matrix, segmentation, revocation and logging — decides whether the estate survives its first review.

Dekart Digital team3 min read

We regularly take over estates that were assembled in a hurry. The tunnel in them usually works. Everything else fails. Below is the list we run against someone else's corporate VPN before agreeing to be responsible for it.

1. Does an access matrix exist

A table of group — resource — protocol — port. If there is none, access was granted on request and from memory, and nobody has measured the scope of privilege. It is the first question in any audit and the most common failure.

2. Is the network segmented or flat

In a flat network a connected employee sees everything: the ERP, the databases, the network gear's admin pages. One compromised laptop opens the whole estate. Segmentation is not a luxury; it is the primary blast-radius control.

3. How fast is access revoked

Test it simply: how many minutes does disconnecting a departed employee take, and who does it when the responsible person is on holiday. If the answer contains "someone has to log into the server", that is an incident that has not happened yet.

4. Is there a device limit per employee

One profile spread across three personal devices and a relative's home computer is an ordinary story. A device limit is not about saving money; it is about making a compromised key visible.

5. Is there a connection log

The fact is enough: who, when, from which address, to which segment. Without it you can neither investigate an incident nor answer an inspector. Storing traffic contents is neither necessary nor advisable.

6. What happens when the gateway fails

If the answer is "all remote work stops", there is no redundancy. A standby gateway with automatic failover costs less than one day of a distributed team standing still.

7. Is SSH password authentication disabled

A password on SSH is a question of when, not whether. Keys only, plus a firewall and source restrictions on the control panel.

8. Is there a key rotation policy

Keys issued three years ago and never changed outlive half the people they were issued to. A policy is needed — annually at minimum, plus an unscheduled rotation whenever an administrator leaves.

9. Who owns the access

A frequent mistake: the administrative keys exist only at the contractor. Changing contractors then becomes an operation. The company should hold the keys from day one.

10. Is there documentation your own administrator can use

Not "the config is on the server" but a description of the topology, the rules, and the procedures for granting and revoking access. Simple test: can a new administrator onboard an employee without calling the contractor.


None of these points is about the protocol. WireGuard or IPsec is the tenth question, and it is almost never the cause of the problem. The cause turns out to be that no process was built around the protocol.

  • #security
  • #vpn
  • #infrastructure

Read next

Read next

DEKART — DIGITAL

Tell us about the task

We reply within 15 minutes during business hours. The first consultation and estimate are free.

@dekart_digital