A report from cyber insurance firm At-Bay has linked Cisco and Citrix VPNs to an almost seven-times higher risk of ransomware.
The 2025 InsurSec Report claimed organizations using VPN solutions by the two vendors were 6.8-times more likely to fall victim to a ransomware attack, while those using on-premise VPN solutions were 3.7-times “more likely to be a victim of an attack compared to firms using a cloud-based VPN or no VPN detected at all.”
The data stems from ransomware insurance claims made between January 2024 and March of this year, with At-Bay claiming 80% of ransomware attacks against its customers involved a remote access tool as their identified entry vector, with 83% of those incidents involving a VPN device.
Other vendors named in the report include Palo Alto Networks with users of its Global Protect VPN at a 5.5-times higher risk, and Fortinet at 5.3-times higher.
According to the report, modern remote access devices are “very complex” and vulnerable, leading to a rise in ransomware breaches.
“Next Generation Firewalls (NGFWs), which can replace an entire stack of older servers … became widely adopted when remote work exploded,” wrote researchers. “But while powerful … many customers don’t fully understand how to use or secure them. The result is that NGFWs create a very large attack surface, which attackers are actively taking advantage of.”
In a firewall survey from this year, CyberRatings.org gave Google Cloud Platform’s NGFW offering 0.00% in effectiveness, with the opinion that “first-class cybersecurity firewall services aren't the highest priority for hyperscale cloud providers.”
CISO for Customers at At-Bay Adam Tyra recommended professionally managed detection and response (MDR) as a solution to remote access vulnerabilities, knocking cybersecurity automation with his opinion that “human experts can contain and remediate the threat before it becomes a major loss event.”
A surge for SASE?
At-Bay also recommended secure access service edge (SASE) tools to both reduce VPN risks and bolster cloud and legacy network security.
“Because SASE requires users to connect to a cloud service before accessing other resources, there’s no exposed ‘front door’ like a VPN appliance. This shift has helped companies avoid many of the ransomware attacks hitting others,” wrote researchers.
Forrester recently ranked Netskope, Palo Alto Networks, and Zscaler as leaders in its "Wave" ranking of SASE solution providers.
That same report left off Cisco for not having gone “far enough” to integrate Umbrella, Secure Access, ThousandEyes, Viptela, Meraki, Duo, and other elements into one unified SASE offering.
In contrast, Cisco was singled out in Dell’Oro Group research for single-vendor SASE platform segment growth during the first quarter of this year.
Dell’Oro reported global SASE revenues increased 17% year-over-year (YoY) during Q1 of 2025, hitting total sales of $2.6 billion for the quarter.
This year’s SASE surge is feeding what the research firm had previously predicted would be a $17 billion market by 2029.
Comments