TY - GEN
T1 - Guidelines for Organizations on Protecting Against Cyber Threats through the use of Virtual Private Networks (VPN)
AU - Khantamonthon, Nattawut
AU - Patpituck, Puttinun
AU - Chimmanee, Krishna
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - The increasing use of Virtual Private Networks (VPN) among organizations and industrial facilities has effectively addressed the demand for secure and convenient access to systems and data. However, reliance on VPNs introduces significant cyber threat risks, particularly ransomware attacks, which can encrypt critical information and render it inaccessible. This research aims to develop strategies for mitigating ransomware risks within VPN environments through a mixed-methods approach. This includes analyzing four cases of ransomware attacks using the 2SMatrix and identifying preventive measures using the NIST Cybersecurity Framework, complemented by focused discussions on specific issues. The findings reveal that, despite the implementation of robust NIST-compliant protective measures, human errors remain a significant concern, leading to the incorporation of the IT governance framework (COBIT) as an additional safeguard to enhance cybersecurity protection, such as the creation of a comprehensive VPN policy and the assessment and monitoring of policy compliance with NIST security standards. The novelty of this study lies in the introduction of the 2SMatrix framework, which provides a structured and VPN-specific approach to ransomware analysis, distinguishing it from broader threat modeling tools.
AB - The increasing use of Virtual Private Networks (VPN) among organizations and industrial facilities has effectively addressed the demand for secure and convenient access to systems and data. However, reliance on VPNs introduces significant cyber threat risks, particularly ransomware attacks, which can encrypt critical information and render it inaccessible. This research aims to develop strategies for mitigating ransomware risks within VPN environments through a mixed-methods approach. This includes analyzing four cases of ransomware attacks using the 2SMatrix and identifying preventive measures using the NIST Cybersecurity Framework, complemented by focused discussions on specific issues. The findings reveal that, despite the implementation of robust NIST-compliant protective measures, human errors remain a significant concern, leading to the incorporation of the IT governance framework (COBIT) as an additional safeguard to enhance cybersecurity protection, such as the creation of a comprehensive VPN policy and the assessment and monitoring of policy compliance with NIST security standards. The novelty of this study lies in the introduction of the 2SMatrix framework, which provides a structured and VPN-specific approach to ransomware analysis, distinguishing it from broader threat modeling tools.
KW - 2SMatrix
KW - COBIT
KW - NIST
KW - Ransomware
KW - Remote working
UR - https://www.scopus.com/pages/publications/105031160527
U2 - 10.1109/InCIT66780.2025.11276011
DO - 10.1109/InCIT66780.2025.11276011
M3 - Conference contribution
AN - SCOPUS:105031160527
T3 - Proceedings - 9th International Conference on Information Technology, InCIT 2025
SP - 215
EP - 221
BT - Proceedings - 9th International Conference on Information Technology, InCIT 2025
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 9th International Conference on Information Technology, InCIT 2025
Y2 - 12 November 2025 through 14 November 2025
ER -