Posted on

VPN for Business is more than just a VPN

vpn for business is more than just a vpn

For small businesses involved in contracts with the Federal Government or Department of Defense, compliance with security requirements for the protection of controlled unclassified information (CUI), security for your network connections may be a cause of concern.

Control 3.1.17 “Protect wireless access using authentication and encryption.” – National Institute for Science and Technology Special Publication 800-171 Revision 1 Protecting Controlled Unclassified. Information in Nonfederal Information Systems and Organizations.

Virtual Private Network

A VPN protects data by creating an encrypted tunnel between your device and another endpoint-server, somewhere else on the Internet or network. In this scenario, your Internet traffic appears to be originating from that endpoint server, rather than from your device. But how does this help protect you? Say you’re sitting at your favorite coffee shop, using their free Wifi. Unfortunately, you don’t know who manages their Wifi or if your connection to it is truly private or secure. You also don’t know the intent of your fellow patrons, all who are also using that same free Wifi connection. A VPN helps to allay these concerns. By encrypting your connection through the free Wifi to the VPN endpoint, you have confidence your privacy is maintained. Well, for that part of the link anyway.

Trust

Now, can you trust the VPN provider? In many cases, VPN services cater to those who wish to elude detection of their activities. Not necessarily for malicious purposes, but those hoping to watch movies while at work behind a firewall, or citizenry hoping to escape Internet censorship of a repressive country. And yes, some with nefarious intent. For these customers, many commercial VPN providers claim no logging or record of user’s activities, which for many sounds great.

Security and Compliance

But, if you’re responsible for protecting business communications and proving you’re doing it, anonymity such as that claimed above just won’t do. Further, who really owns and manages those services? A foreign company or government?

Senators Urge Security Audit of Foreign VPNs

Small Business Solutions

For a business committed to security and compliance goals, a VPN must offer features that support these needs. Logging to show appropriate use and trusted operation of the service is required. Further, the VPN should add protection from malicious activity and be operated by a trusted partner.

The Assured Bridge VPN

The Assured Bridge VPN meets business needs for trust, security and compliance. All VPN service end-points are located in the United States and operated by certified U.S. providers. Our company is U.S.-based and is U.S. Military Veteran owned. The VPN services include usage logging, reporting, malware protection and multifactor authentication, all at a price-point that meets the needs of small businesses.

With over 30 years of experience, Daniel Bjorklund is a dedicated information security practitioner and innovator. He serves as a principal at Assured Bridge, helping to mature and guide compliance-as-a-service and managed security service provider operations. Dan is also Chief Technologist at Sabine Solutions - a defense contractor, and owns a small cybersecurity consulting firm: Community Cyber. He is active in the startup and entrepreneurial communities in the Augusta, GA area, helping set firm cybersecurity foundations for new companies and efforts.

Dan is a current CISSP and holds a Master of Science degree in Information Assurance and Security and a Bachelor of Science degree in information technology. When not hunched in front of a computer, Dan can often be found above 3000 feet avoiding highway traffic, flying his airplane as a licensed pilot. He and his wife enjoy outdoor activities, biking, fishing and sightseeing in the Southeastern United States.