Skip to main content
VTechFusion Technologies
A €500,000 Fine for Missing VPN and MFA: The Basic-Controls Audit Worth Running Today
InsightsBlogEngineering
Engineering6 min readSeptember 3, 2026

A €500,000 Fine for Missing VPN and MFA: The Basic-Controls Audit Worth Running Today

VT

VTechFusion Team

VTechFusion Technologies

The CNIL's €500,000 fine against the Loire Private Hospital traces back to a genuinely basic gap: no VPN, no multi-factor authentication, for remote access to a system holding data on nearly 730,000 people. This wasn't a sophisticated zero-day exploit or an advanced persistent threat — it was the absence of two widely available, low-cost, well-understood security controls. That's actually the more useful takeaway: this kind of gap is fully within reach to find and close before it becomes a similar headline.

Why Basic Controls Still Get Missed

VPN and MFA gaps rarely happen because an organization decided these controls weren't worth implementing — they happen because of incomplete inventory. A legacy system added before current security policy existed, a vendor-managed remote access path nobody centrally tracks, an emergency access account set up quickly during an incident and never properly decommissioned. The control itself is well understood; the gap is almost always a visibility problem, not a decision problem.

A Practical Audit to Run This Week

  • List every remote access path into systems holding sensitive data — not just the ones your team set up recently, but anything a vendor, a legacy system, or an emergency procedure created that might not be centrally tracked
  • For each path, verify directly (not from memory or assumption) whether it requires both a VPN connection and multi-factor authentication, with no exceptions carved out for convenience or a specific user role
  • Check specifically for vendor-managed or third-party remote access — these are the paths most likely to fall outside your organization's own security policy enforcement, since they may be configured and controlled by the vendor
  • Review any emergency or break-glass access procedures created during a past incident — these are commonly set up quickly under pressure and forgotten, becoming a long-lived gap
  • Confirm your breach notification process is actually tested, not just documented — the Loire Private Hospital case cited a notification failure alongside the security gap, meaning the response process itself needs verification, not just the preventive controls

Why This Is Worth Doing Even If You're Confident

Most organizations that experience a breach like this one would have said, before it happened, that they had VPN and MFA requirements in place — and in a general sense, they likely did. The gap is almost always in a specific, overlooked path that the general policy didn't actually cover in practice. A direct, path-by-path verification — not a policy review — is what actually catches this class of gap before a regulator or an attacker does.

Filed under:Engineering
All Articles

Frequently Asked Questions

Why do basic security gaps like missing VPN or MFA still happen at organizations with security policies in place?

Almost always due to incomplete inventory rather than a decision not to implement the control — a legacy system, a vendor-managed access path, or an emergency access account created during an incident can fall outside general policy enforcement without anyone noticing.

What's the most important step in auditing for this kind of gap?

Directly verifying every remote access path into sensitive systems — not reviewing the written policy, but checking each actual path individually, with particular attention to vendor-managed access and any emergency procedures created during past incidents.

Does having a written VPN/MFA policy mean this gap can't happen to us?

Not necessarily — the Loire Private Hospital case illustrates that a specific, overlooked access path can fall outside an organization's general policy in practice even when the policy itself exists. Path-by-path verification, not policy review alone, is what catches this.

Enjoyed this article?

Get new articles delivered to your inbox — no spam, unsubscribe anytime.

Start Today

Ready to Build Something Great?

Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.