Summary

  • The tunnel protects a path, not a compromised device, malicious destination or careless account.
  • Provider ownership, logging, jurisdiction, key handling and failure behaviour matter as much as the protocol.

A virtual private network authenticates an endpoint and carries traffic through an encrypted tunnel to another gateway. That can secure remote work or reduce local interception, but it changes where traffic becomes visible. Organisations should minimise routes, use strong device identity, patch clients, restrict administrative access and test what happens when the tunnel or name resolution fails. The next useful evidence is a connection trace and access review proving that only intended services traverse the tunnel and that revoked devices lose entry promptly. Privacy improves when the new trust boundary is explicit.

Sources