Summary
- Senator Ron Wyden has written to OMB, CISA and NIST demanding a coordinated campaign to remove legacy, internet-facing VPNs from federal agencies and contractors.
- Wyden cited the ArcaneDoor Cisco firewall attacks, Fortinet FortiBleed credential exposures, and Ivanti and Check Point VPN vulnerabilities as evidence of systemic risk.
- He is calling for a CISA binding operational directive giving agencies two years to retire legacy remote-access systems entirely.
- NIST would be required to publish zero-trust implementation standards; OMB would direct agencies to prioritise zero-trust spending and update procurement rules accordingly.
- The push reframes the problem as architectural, not patch-management — reactive emergency directives, Wyden argues, cannot fix flaws that are inherent to legacy appliances.
The Complaint
Senator Ron Wyden (D-OR) sent a letter Monday to the heads of the Office of Management and Budget, the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology, arguing that the federal government’s dependence on older, internet-facing VPN appliances has become a structural liability. “For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers,” he wrote.
The Attack Record Wyden Points To
The letter references a pattern of high-profile compromises affecting federal infrastructure: the ArcaneDoor campaign targeting Cisco firewall appliances, the FortiBleed credential exposure across Fortinet gateways, and exploited vulnerabilities in Ivanti and Check Point VPN products. Each of these incidents involved network-edge appliances that present a publicly reachable surface — what Wyden describes as a digital front door open to anyone on the internet.
An Architectural Problem, Not a Patching Problem
Wyden draws on a Congressional Research Service report to characterise traditional VPNs as embodying a “castle-and-moat” security model — one that assumes anyone who has crossed the perimeter is entitled to access internal resources. That assumption, he argues, is fundamentally at odds with a distributed and mobile workforce. Modern zero-trust architectures operate on a never-trust, always-verify basis and, crucially, do not broadcast their presence to the public internet, making them harder for adversaries to locate and probe in the first place.
Why Reactive Mandates Are No Longer Sufficient
A recurring theme in the letter is the unsustainability of CISA’s current posture. The agency has repeatedly issued Emergency Directives and compressed patching timelines in response to active exploitation of remote-access products. Wyden characterises this as an endless game of whack-a-mole. Each directive addresses a symptom rather than the underlying condition: that legacy appliances carry inherent, architectural weaknesses that no patch can permanently resolve.
What Wyden Is Asking For
The letter lays out four specific asks. First, CISA should issue a binding operational directive requiring agencies to fully retire legacy, public-facing remote-access systems within two years. Second, NIST should publish implementation standards for transitioning to zero-trust architectures. Third, OMB should issue a memorandum directing agencies to prioritise zero-trust spending in their budgets. Fourth, OMB should work with CISA and the Department of Defense to update federal procurement rules so that agencies and defence contractors cannot purchase network-edge, VPN or remote-access products unless the vendor provides a formal attestation of compliance with NIST zero-trust standards.
No Response on the Record
At the time of the CyberScoop report, there is no indication that OMB, CISA or NIST had publicly responded to the letter. Whether the agencies will act on the proposals, and on what timeline, remains unknown.
Why it matters
For CISOs in both the public and private sectors, this letter is a useful policy signal. If the proposed binding operational directive is issued, federal agencies and their contractors will face a hard deadline to retire legacy VPN infrastructure — with procurement rules that could eventually restrict which products enter the supply chain at all. Private-sector security leaders should treat this as an early indicator of where regulatory expectations are heading. More immediately, the catalogue of exploited platforms Wyden references — Cisco, Fortinet, Ivanti, Check Point — maps directly onto products many organisations still run. The architectural argument is worth internalising regardless of regulatory pressure: if your remote-access layer is publicly addressable, it is permanently in scope for threat actors. Zero-trust approaches that remove that visibility reduce the exploitable attack surface in a way that patching alone cannot.
What to do now
- Audit your current remote-access stack to identify any legacy VPN appliances that are directly reachable from the public internet, including those from vendors named in the letter — Cisco, Fortinet, Ivanti and Check Point.
- Assess whether your organisation’s remote-access architecture still relies on a castle-and-moat trust model, and document the gap against zero-trust principles.
- Begin or accelerate zero-trust architecture planning, referencing existing NIST guidance (SP 800-207) while monitoring for any updated implementation standards NIST may publish in response to this push.
- If your organisation is a federal agency or government contractor, track CISA’s binding operational directive pipeline for any directive covering legacy remote-access systems and build a two-year transition scenario into your roadmap now.
- Review vendor procurement criteria to consider whether zero-trust compliance attestations should become a standard requirement in future remote-access product evaluations.
