menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

The VPN Risk Too Many Companies Ignore

13 0
04.06.2026

We’ve all heard the horror stories of companies hiring full-time remote workers—only to find out later they’re actually based in North Korea and had access to a company’s sensitive data. This kind of fraud, enabled through using VPNs and residential proxies, is rampant. According to a study last month from Spur Intelligence, 94% of organizations have experienced this type of anonymizing in cybersecurity incidents, and about half lost significant money or information in the attack.

But while the threat is known, it’s not one that many companies are fighting proactively. About 44% analyze IP data only after an attack, and only 38% have strong controls on access to enterprise systems from personal devices. More than six in 10 said they aren’t very concerned about these devices leading to exposure of company data. I spoke with Spur Intelligence cofounder Riley Kilmer about this vulnerability and why and how companies should protect themselves. An excerpt from our conversation is later in this newsletter.

We’re taking a short break next week, so the next edition of Forbes CIO will land in your inboxes on Thursday, June 18.

This is the published version of Forbes’ CIO newsletter, which offers the latest news for chief innovation officers and other technology-focused leaders. Click here to get it delivered to your inbox every Thursday.

This week, after a long back-and-forth, President Donald Trump quietly signed an executive order on AI regulation. The order puts official policy between the laissez-faire approach of letting AI companies do whatever they want and the requirement that the administration vet all new frontier models before they are released to the public. The order directs the federal government to develop a classified benchmarking process to assess the capabilities of AI models, then design a voluntary framework by which AI companies could submit their new frontier models to the government for vetting for up to 30 days before releasing them.

As of now, the order doesn’t mandate any change to the development and release process for AI companies, though Politico reports it represents a huge change in the Trump Administration’s willingness to regulate AI technology. Establishing a process is just the beginning. And while the policy looks rather innocuous now, the benchmarking process—calling on the Treasury Department, National Security Agency, the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Commerce Department and the National Institute of Standards and Technology—could become rather rigorous. AI experts, lobbyists and consultants told Politico that the defense-heavy posture of this group, coupled with the historical fact that voluntary regulation rarely stays voluntary over time, could be setting the stage for more stringent regulations in the future.

Forbes contributor Paulo Carvão writes that the order is a start, but it faces challenges from the beginning. It could be difficult to establish a process with any legitimacy given the broadness of the........

© Forbes