VPNs and remote work: what they solve and what they don't
The real problem with working outside the office
In an office, someone administers the network: there are firewalls, rules and somebody to call. When you work from home, a coworking space or a hotel, that layer disappears. Your laptop connects to a network whose configuration you neither control nor know.
That does not mean those networks are hostile. Most are not. But they go from being a managed environment to an unknown one, and that difference matters when you handle client information or access credentials.
What a VPN adds here
It encrypts the path between your machine and the VPN server, so the local network stops seeing which services you connect to.
It reduces what the administrator of that network can observe about your professional activity.
On networks that block specific ports or services — common in hotels and airports — it lets you work with tools that would otherwise not load.
What it does NOT replace
Precision matters here, because this is where most confusion lives.
It does not replace your corporate VPN. If your company has one for reaching internal servers, that is the one to use for that purpose. A commercial VPN gives you an exit to the internet, not access to your company's network.
It does not replace two-factor authentication. If someone has your password, a VPN does not stop them signing in.
It does not replace keeping your machine patched. An unpatched system stays vulnerable with or without a VPN.
One practical recommendation
Turn it on whenever you use a network that is not yours, and leave it on while you work. If the app has a kill switch — the one that cuts traffic if the tunnel drops — enable it: it stops your connection quietly falling back to the open network without you noticing.
And check now and then that it is still connected. That is the most common mistake: assuming it is active when it dropped half an hour ago.