When good security controls become optional, they eventually stop being controls.
In almost every organisation, there is constant tension between usability and security. Users want fast, seamless access to systems. Security teams want strong authentication, auditability and protection against compromise. Most of the time those objectives can coexist. Occasionally they cannot.
The debate over APN (Access Point Name) connectivity versus VPN access is one of those cases.
At first glance, APN can appear attractive. Connections may feel simpler, users avoid repeated VPN logins, and those working in remote locations can experience fewer interruptions when network quality is poor. From an operational perspective, the argument is understandable.
The problem is that convenience is not the same thing as risk reduction.
The Security Control You Don't Notice Until It's Gone
Modern VPN services typically incorporate Multi-Factor Authentication (MFA), arguably the single most effective defence against credential compromise.
If an attacker obtains a user's password, MFA provides an additional barrier that often stops the attack from progressing.
APN-based access models frequently remove or bypass that additional authentication layer. The user may still require valid credentials, but the second factor is no longer protecting the connection.
From a risk perspective, the conversation changes dramatically.
Instead of asking:
"Is APN more convenient than VPN?"
the question becomes:
"Is this business requirement important enough to justify operating without one of our primary identity protection controls?"
Those are very different discussions.
The Slippery Slope of Preference-Based Exceptions
Most organisations establish standard access methods for a reason. Standards create a predictable security baseline.
Once exceptions begin to be granted based on convenience, preference or frustration with a security control, the standard starts to erode.
Consider the justification often presented:
- VPN sessions drop in remote areas
- Users receive frequent MFA prompts
- Sign-in interruptions impact productivity
- APN provides a smoother experience
None of these statements are necessarily incorrect.
However, they also apply to potentially hundreds or thousands of employees who work remotely, travel regularly or operate in low-bandwidth locations.
If one user receives an exemption because the VPN experience is inconvenient, what prevents the next request? Or the one after that?
Before long, the organisation finds itself supporting two access models:
- A secure standard model with MFA.
- A less secure model available to anyone who can successfully argue inconvenience.
At that point, APN is no longer an exception service.
It has become an alternative service.
Security Teams Should Advise, Not Own the Risk
One of the most important points raised in the discussion is often overlooked.
Security teams are experts in identifying and communicating risk. They are not usually the owners of business requirements.
A cybersecurity team can assess questions such as:
- Does APN reduce authentication assurance?
- Does it increase exposure if credentials are compromised?
- Does it bypass existing security controls?
- What is the resulting residual risk?
What the security team cannot determine is whether the operational requirement genuinely justifies that risk.
Only the business owner can answer questions such as:
- Can the employee still perform their role using the standard solution?
- Are alternative options available?
- What would be the operational impact of remaining on VPN?
- Is the risk justified by the business outcome being achieved?
This distinction is critical.
If cybersecurity becomes the approval authority for every exception, it effectively becomes the owner of the resulting residual risk. That creates a governance problem.
Risk should sit with those who receive the business benefit from accepting it.
Remote Work Is Not Automatically a Valid Exception
One of the stronger arguments often presented for APN revolves around remote operations.
In regional and remote environments, intermittent connectivity can lead to repeated VPN reconnections and MFA prompts. Users can experience genuine frustration and, in some cases, reduced effectiveness.
That may represent a legitimate business justification.
However, a legitimate business justification does not mean the risk disappears.
It simply means the organisation may decide that the benefit outweighs the security impact.
There is a subtle but important difference.
An exception should be granted because the business cannot reasonably achieve the required outcome using the standard control set—not because the alternative is easier.
What Happens When Credentials Are Stolen?
Security professionals often evaluate decisions by asking a simple question:
"What changes on the day a user's credentials are compromised?"
In a VPN and MFA model:
- The attacker requires the password.
- The attacker requires the second factor.
- The attack is more likely to be detected or blocked.
In an APN model without MFA:
- The password may be sufficient.
- The attack path is simpler.
- The overall resistance to credential theft is reduced.
This doesn't mean APN is inherently insecure.
It means the security assumptions are different.
And when protecting government, health, financial or sensitive citizen data, those differences matter.
The Right Model: Controlled Exceptions
The answer is not to ban APN.
The answer is to govern it appropriately.
Strong security frameworks typically treat access control exceptions as:
- Rare
- Justified
- Documented
- Risk assessed
- Approved at an appropriately senior level
Importantly, the approval authority should be commensurate with the risk being accepted.
If the organisation is choosing to depart from a standard MFA-protected access model, the decision should not rest with an individual user seeking convenience. Nor should it necessarily sit with a frontline operational manager.
The higher the security impact, the higher the level of accountability should be.
Security Controls Are Most Valuable When They're Inconvenient
There is an uncomfortable truth in cybersecurity:
The controls users dislike are often the controls protecting them most effectively.
- Passwords are inconvenient.
- MFA is inconvenient.
- Conditional access is inconvenient.
- VPN authentication is inconvenient.
Yet those same controls repeatedly prevent real-world compromises.
The purpose of security architecture is not to eliminate inconvenience. It is to ensure that exceptions are made deliberately, transparently and with a clear understanding of the risk.
APN has a place in secure environments. There will always be genuine operational scenarios where an exception is justified.
But if APN becomes the answer whenever users find MFA frustrating, the organisation has not improved usability, it has quietly weakened one of its most important security boundaries.
And that is exactly why APN should remain an exception-based service, not a standard technology option.

No comments:
Post a Comment