Cyber Essentials: what to check for remote worker VPN connections
Posted on 2 October 2026 by Beaming SupportA virtual private network (VPN) allows remote workers to connect to your business network. But the VPN connection is only one part of the security you need to consider when preparing for Cyber Essentials.
Check how people sign in, how the VPN is managed and how their devices are protected. These are useful areas to review with your IT team or support provider before completing your assessment.
Control who can connect
Give each remote worker individual login credentials and access only to the systems they need. Remove access when it is no longer required.
Enable multi-factor authentication (MFA) for VPN access wherever available. MFA adds another identity check to the sign-in process, helping protect access if a password is stolen.
Passwords should be unique and never shared. Where a password is used with MFA, Cyber Essentials specifies at least eight characters with no maximum length restriction.
Keep VPN equipment and software supported
- Check the VPN gateway’s firmware, VPN client software, and the operating systems and applications on remote workers’ devices.
Apply vulnerability fixes within 14 days of release where:
The vendor describes the vulnerability as critical or high risk. - It has a Common Vulnerability Scoring System (CVSS) v3 base score of 7 or above.
- The vendor provides no information about the vulnerability’s severity.
The deadline starts when the fix is released.
Protect firewall administration
Disable internet access to the firewall’s management interface unless there is a documented business need.
Where it is necessary, protect access with MFA or a small trusted IP allow list combined with properly managed password authentication. We recommend using both where practical.
Protect the remote worker’s device
Keep software firewalls enabled on laptops used on home or public networks.
Devices also need suitable malware protection. Antivirus is one option; application allow listing, which restricts devices to approved software, is another.
As a practical safeguard, standard users should not be able to disable the protection your business relies on.
Agree who is responsible
Ask your IT team or provider to confirm who manages VPN accounts, installs updates and checks device protection. Clear responsibilities make it easier to maintain these controls as people join, leave or change how they work.
Need help reviewing your remote access setup? Speak to Beaming about your VPN and firewall requirements.
For the wider picture, read our guide to Cyber Essentials.
- Fibre
- Managed Networks
- Media
Iliffe Media Group
Modern media companies are bandwidth-hungry environments. Iliffe Media needed an upgrade to their network and required rapid, resilient connectivity between newsrooms and office locations across the UK.