Skip to main content
CybersecurityNetwork Security

Wyden Urges Feds to Phase Out Insecure Public-Facing VPNs

Outdated VPN server equipment sits in a government office with ambient daylight.

“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet‑facing VPN servers to grant employees remote access,” Sen. Ron Wyden, D‑Ore., wrote in a letter urging sweeping change.

Sen. Ron Wyden's appeal to OMB, CISA and NIST

Wyden directed his letter to top officials at the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST), calling for coordinated action to “require the adoption of modern, secure remote‑access technology across the federal government.” The letter — first reported by CyberScoop — frames the issue as a cross‑agency implementation and procurement problem that those three organizations must lead together.

Legacy, internet‑facing VPNs as a digital "front door"

In the letter, Wyden described older virtual private network (VPN) servers that are directly accessible via the public internet as a digital “front door” that allows mobile devices and remote employees to log in. He argued that modern remote‑access solutions “eliminate this vulnerability entirely,” because they “provide remote access without broadcasting their presence,” making such servers effectively invisible and, in his view, beyond attackers’ reach.

Attacks and vulnerabilities Wyden cited

Wyden referenced several concrete incidents and exploit classes he says demonstrate the risk of internet‑facing legacy access appliances. His letter cites the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways, and “vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.” These examples underpin his critique that continued use of exposed remote‑access appliances results in repeated compromises.

Concrete federal actions Wyden demands

Wyden laid out a set of specific policy steps he wants the federal government to take:

  • CISA should issue a binding operational directive giving agencies two years to “fully expunge legacy, public‑facing remote access systems.”
  • NIST should issue implementation standards for transitioning to zero‑trust architectures.
  • OMB should issue a memo directing agencies to prioritize zero‑trust architecture spending.
  • OMB should team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero‑trust standards.

Wyden also urged moving away from what a Congressional Research Service report to him called a “castle‑and‑moat” approach — the traditional model that assumes anyone inside the network is authorized — and toward zero‑trust’s “never‑trust, always‑verify” posture.

What this means for federal cybersecurity teams, vendors, and defense contractors

  • Federal cybersecurity teams: Wyden argues current practices force them into a reactive posture. He wrote that “to keep federal networks online, CISA has been forced to repeatedly issue extraordinary Emergency Directives and hyper‑accelerated patch mandates,” and called those emergency, reactive measures “unsustainable.”
  • Vendors and procurement leaders: The letter would, if implemented, require vendor attestations of compliance with NIST zero‑trust standards before agencies or defense contractors could buy network edge or remote access solutions — a direct procurement constraint tied to standards and attestations.
  • Defense contractors: Wyden explicitly ties defense contractors to the procurement change, saying OMB should work with CISA and the Defense Department to prevent purchases of covered remote‑access products without vendor attestations of NIST zero‑trust compliance.

Wyden’s letter frames the risk as systemic rather than episodic: repeated emergency directives and accelerated patches are, in his words, a “whack‑a‑mole” response that fails to address “the fundamental issue that these flaws are inherent in the use of legacy remote‑access appliances.” The next concrete move he requests is a binding CISA directive with a two‑year deadline, backed by NIST standards and OMB procurement and budgeting actions.

The critical, named next step now rests with the agencies Wyden addressed: whether CISA, NIST and OMB will adopt the specific directive, standards and procurement changes he seeks — and whether those measures will produce the rapid transition Wyden argues is necessary to remove internet‑facing VPNs from the federal attack surface.

Read the original CyberScoop story