
US Senator Ron Wyden is urging the Trump administration to phase out legacy virtual private network (VPN) technology across the federal government, arguing that outdated remote access systems have repeatedly enabled Chinese and Russian state-sponsored hackers to breach government and contractor networks.
In a letter sent to the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Institute of Standards and Technology (NIST), the Oregon Democrat called for mandatory federal cybersecurity standards that would replace internet-facing VPNs with modern zero-trust remote access technologies within two years.
Wyden argues that traditional VPN appliances create an exposed “front door” that attackers can easily locate, scan, and exploit. He points to a series of major attacks against Cisco, Fortinet, Ivanti, and Check Point products, as well as Travelers' Q4 2025 Cyber Threat Report, which found that 85% of ransomware-related cyber insurance claims stemmed from exploited VPNs. According to the letter, Chinese and Russian government-backed hackers have repeatedly leveraged these flaws to steal sensitive government data and gain administrative access to federal networks.
Instead of continuing to patch vulnerable VPN appliances, Wyden says agencies should adopt zero-trust architectures that do not expose public-facing remote access gateways. The accompanying Congressional Research Service (CRS) memo explains that zero-trust systems establish outbound-only connections, continuously verify users and devices, and limit access to specific applications rather than granting broad network access.
The senator is asking CISA to issue a Binding Operational Directive requiring civilian agencies to eliminate legacy public-facing VPNs within two years. He also wants the National Security Agency to impose the same deadline across military, intelligence, and other national security networks using its existing authorities.
Wyden further urged NIST to develop implementation standards requiring outbound-only remote access architectures, software written in memory-safe programming languages, agency-controlled encryption keys to reduce supply-chain risk, and alignment with post-quantum cryptography efforts. He also asked OMB to prioritize zero-trust investments during the federal budgeting process and require agencies to adopt the new standards.
The proposal also targets future procurement. Wyden wants OMB, CISA, and the Department of Defense to update the Federal Acquisition Regulations (FAR) and the Defense Federal Acquisition Regulation Supplement (DFARS) to prohibit agencies and defense contractors from purchasing VPN or other remote access products unless vendors formally attest that their products comply with NIST's zero-trust requirements.
The CRS memo accompanying the letter notes that traditional VPNs have been the subject of numerous CISA emergency directives over the past several years, citing vulnerabilities in products from Pulse Secure, VMware, Ivanti, F5, and Cisco. While it acknowledges that zero-trust architectures also introduce security challenges, it concludes that they eliminate several of the inherent risks associated with internet-facing VPN gateways by making protected resources effectively invisible to external attackers.







Leave a Reply