Technology Intelligence
Cyber Security

The UK Isn’t Banning VPNs — But Is Yours Fit for Business?

IT Club Editorial6 minutes read22 July 2026
The UK Isn’t Banning VPNs — But Is Yours Fit for Business?

VPNs remain legitimate privacy and security tools in the UK. But having a VPN does not automatically make remote access secure. Here is what businesses should check.

Last reviewed: July 2026. This article describes a current UK government position, which may be reviewed as online-safety policy develops. Businesses should refer to current government and Ofcom guidance.

The UK government has decided not to introduce restrictions or age gates for VPN services at this stage, following research into how children use them and how age checks are bypassed online.

That matters to businesses because VPNs have entirely legitimate uses: secure remote working, access to internal systems, protection when travelling, privacy on untrusted networks and secure connections between offices.

But there is an important distinction. A VPN is a connection method, not a complete cyber-security strategy. The question for businesses is no longer whether VPNs will be restricted. It is whether their own VPN is secure, supported and properly managed.

What has the UK government decided?

Calls had been made for restrictions on VPN services because they could potentially be used to bypass online age checks. The government commissioned research into how children experience age assurance, how they get around age checks, why they use VPNs and how common different circumvention methods are.

The government subsequently decided not to restrict or age-gate access to VPNs at this stage. Legitimate privacy, security and freedom-of-expression uses formed part of the policy consideration. The position may be reviewed as online-safety policy develops.

What did the research find?

  • The study covered more than 2,000 children aged 11 to 17.
  • Around 26% reported having used a VPN.
  • Privacy was the most common stated reason among VPN users.
  • Around 22% of VPN users said they had used one to access age-restricted websites, apps or games.
  • Giving a false age or date of birth was a more common circumvention method than using a VPN.

These are survey findings. They do not prove that VPN circumvention never happens, and the findings themselves do not automatically constitute government policy — they contributed to the evidence considered by policymakers.

Where does responsibility now sit?

Online platforms and services remain responsible for complying with applicable online-safety and age-assurance obligations. Platforms may be expected to use effective age-assurance measures, assess circumvention risks, identify weaknesses in their controls, take proportionate steps to reduce bypassing and follow current Ofcom guidance. The government and regulators may continue engaging with platforms and VPN providers.

This part of the decision is mainly relevant to businesses that operate online platforms, apps or services within the scope of the Online Safety Act. It does not mean every ordinary business website must introduce age verification.

What is a VPN?

VPN stands for Virtual Private Network. A VPN creates an encrypted connection between a device and another trusted point — such as a company firewall, a business network, a cloud environment or a VPN provider’s server.

For a business, it may allow an authorised employee to access files, servers, applications, remote desktops, internal systems and network resources without exposing those systems directly to the public internet.

A VPN is a protected route into a network — but the business must still control who is allowed through the door.

Consumer VPNs and business VPNs are not the same

TypeTypically used to
Consumer privacy VPNMask a user’s public IP address, encrypt traffic to the VPN provider, improve privacy on public networks, appear to connect from another region
Business remote-access VPNAuthenticate employees, connect authorised devices, provide access to company systems, enforce business access rules, record security events, support remote working
Site-to-site VPNConnect two offices, link a business network to a data centre or cloud environment, carry network traffic between trusted locations

These technologies may use similar underlying concepts, but they solve different problems. A consumer VPN subscription is not a replacement for secure business remote access.

What a VPN does protect

Depending on its configuration, a VPN can:

  • Encrypt traffic across an untrusted network
  • Reduce exposure of internal services
  • Provide controlled access to business resources
  • Connect offices securely
  • Protect communications on public Wi-Fi
  • Support remote administration
  • Provide a consistent route through company security controls

What a VPN does not automatically protect

A VPN does not automatically:

  • Stop phishing
  • Remove malware
  • Protect a stolen password
  • Make an infected device safe
  • Secure an unsupported server
  • Enforce multi-factor authentication
  • Stop an authorised user accessing too much information
  • Patch vulnerable software
  • Prevent data being copied
  • Guarantee anonymity
  • Make every website trustworthy
  • Replace endpoint protection, backups or staff awareness training

An attacker with a valid username and password may be able to use the same VPN doorway as a legitimate employee.

Why business VPNs are attractive targets

A remote-access system is deliberately available from outside the business network. Attackers may target it using stolen credentials, password spraying, repeated login attempts, unpatched vulnerabilities, obsolete protocols, forgotten user accounts, exposed administrator interfaces, weak or reused passwords, compromised personal devices or incorrectly configured access rules.

The business lesson: any internet-facing remote-access service needs stronger protection than a username and password alone.

Is your business VPN properly protected?

  • Every user has an individual account
  • Multi-factor authentication is enforced
  • Shared VPN accounts are not used
  • Former staff accounts are promptly removed
  • The VPN software and appliance are supported
  • Firmware and security updates are current
  • A modern, supported VPN protocol is used
  • Administrator access is restricted
  • Default passwords have been changed
  • Failed login attempts are limited or controlled
  • Security events are logged
  • Logs and alerts are reviewed
  • Access is restricted to necessary systems
  • Remote devices are appropriately secured
  • VPN access is reviewed regularly
  • A recovery plan exists if the VPN fails

Any unticked item deserves investigation.

Why multi-factor authentication matters

A password can be guessed, reused, phished, stolen or exposed in a data breach. Multi-factor authentication adds another check before access is granted — for example an authenticator application, a hardware security key, a securely implemented one-time code or certificate-based device authentication.

For business remote access, a password alone should not normally be considered sufficient protection. UK schemes such as Cyber Essentials place strong emphasis on multi-factor authentication for accounts that are accessible over the internet — but the presence of MFA does not automatically make every VPN configuration compliant.

What about login throttling and account lockout?

Internet-facing login systems should have protection against repeated password attempts. Depending on the system, this may include rate limiting, temporary lockout, progressive delays, source blocking, automated attack detection and alerts for repeated failures.

The exact control varies by platform. Administrators should verify what their VPN product supports rather than assuming protection is enabled — and avoid permanent lockouts that could easily be abused to deny access to legitimate users.

Does your VPN meet Cyber Essentials requirements?

A VPN may form part of the boundary through which users access company systems. Its configuration may therefore affect areas such as secure configuration, user access control, security update management, authentication, protection against brute-force attempts, exposure of administrative interfaces and account management.

A product supporting “VPN” does not by itself demonstrate Cyber Essentials compliance.

Businesses should assess the exact product, firmware version, authentication method, password controls, MFA capability, rate-limiting or lockout controls, administrative exposure, support status and configuration. For definitive guidance, refer to the current Cyber Essentials requirements and your certification body.

Do all remote workers still need a traditional VPN?

Modern cloud-based businesses may not always need full network-level remote access. Alternatives may include Microsoft 365 with modern authentication, securely published cloud applications, zero-trust network access, remote desktop gateways, application-specific access, device-compliance controls, identity-aware access proxies and virtual desktop services.

That does not make VPNs obsolete. A VPN may remain appropriate where users need access to legacy applications, internal file servers, on-premises systems, specialist equipment, private cloud networks or office-based resources.

The right question is not “VPN or no VPN?” It is “What access does this person need, and what is the safest way to provide it?”

Should staff use a VPN on public Wi-Fi?

A VPN can protect traffic between the user’s device and the VPN endpoint when using an untrusted network. However, staff should still prefer a trusted mobile hotspot where practical, avoid unknown open networks, confirm the correct network name, keep devices patched, use endpoint protection, enable the local firewall, use MFA, avoid leaving devices unattended and report unusual security warnings. A VPN does not make unsafe activity risk-free.

What should businesses do now?

  1. 1Identify every VPN in use — remote-access VPNs, site-to-site VPNs, cloud VPN connections, consumer VPN subscriptions, remote-support tools and VPN access supplied by third parties.
  2. 2Confirm why each VPN exists. Who uses it? What can they access? Is that access still required? Is there a safer alternative?
  3. 3Review authentication — individual accounts, MFA, password controls, device certificates, old accounts and third-party access.
  4. 4Review the technology — vendor support, firmware, protocol, known security advisories, licensing and replacement plans.
  5. 5Review monitoring — login logs, repeated failures, unusual countries or locations, dormant accounts, unexpected access times, alerts and who reviews them.
  6. 6Schedule the next review. VPN access should be part of the organisation’s ongoing Operational Heartbeat.

Signs your VPN needs urgent review

  • Users share one VPN account.
  • MFA is not available or not enabled.
  • The appliance no longer receives updates.
  • Nobody knows who has access.
  • Former employees still appear in the user list.
  • The administrator page is exposed publicly.
  • Failed login attempts are not logged.
  • The system uses an obsolete protocol.
  • The VPN was installed years ago and never reviewed.
  • A third party manages it, but ownership is unclear.
  • Users connect from unmanaged personal devices.
  • The business cannot explain what the VPN allows users to reach.

Why business owners should care

A VPN may provide direct access to some of the organisation’s most important systems. If it is poorly protected, an attacker may bypass many of the controls protecting the normal office environment.

A secure VPN can support flexible working, business continuity, travel, external support, cloud connectivity and access to legacy systems. An insecure VPN can create unauthorised access, ransomware risk, data loss, operational disruption, compliance issues and reputational damage.

The issue is not whether VPN technology is good or bad. The issue is how it is selected, configured and maintained.

The IT Club View

The UK government’s decision recognises that VPNs have legitimate privacy and cyber-security uses. That is sensible — but businesses should not mistake legal availability for secure implementation.

A VPN is one of the front doors into a business network. That front door should have a strong lock, a second identity check, a record of who entered, restrictions on where they can go, regular maintenance and someone checking for suspicious activity.

The government may not be restricting VPNs, but every business should restrict and monitor who can use its own.

Four questions to ask your IT provider

  1. 1Does our VPN require multi-factor authentication?
  2. 2Is the VPN product and firmware still supported?
  3. 3What happens after repeated failed login attempts?
  4. 4Who reviews VPN accounts, logs and security alerts?

If nobody can answer these questions clearly, the VPN needs a review.

Not sure whether your VPN is secure?

Ask the IT Club Advisor about your remote-access setup, MFA, VPN appliance or Cyber Essentials requirements.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.

Technical note for IT administrators

When reviewing a business VPN, assess: supported VPN protocols and cryptographic configuration; firmware and software lifecycle; identity-provider integration and MFA support; certificate management; password and lockout controls; rate limiting; user-to-resource access rules; split tunnelling; DNS handling; device posture and endpoint compliance; logging and retention; geo-impossible or unusual-login alerts; site-to-site routing; administrative interface exposure; configuration backups; and high availability and recovery.

Split tunnelling is not automatically right or wrong. Its suitability depends on the risk assessment, traffic-routing requirements and security controls in place.

Refer to current vendor security guidance, NCSC advice and the applicable Cyber Essentials requirements when making configuration decisions.

Plain-English Takeaway

The UK government has decided not to restrict VPN access at this stage, recognising that VPNs have legitimate privacy and security uses. For businesses, the important question is whether remote access uses MFA, supported technology, individual accounts and regular monitoring.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor