A Small Business VPN Is a Procurement Decision, Not a Subscription

The phrase covers at least three different problems, and only one of them is solved by the kind of subscription an individual buys. Before comparing anything, work out which problem you have — because if it is the common one, giving your staff consumer VPN accounts will not address it at all, and you will find that out slowly.

The second thing to understand is that this is procurement. Not because it is expensive, but because it involves contracts, other people’s access, your obligations to third parties, and what happens on the day someone leaves.

Three problems wearing one name

Staff working from networks you do not control. Hotels, cafés, client sites, home connections shared with a household. Here the concern is the local network, and a consumer-shaped product genuinely does address it — this is the case where the ordinary subscription is the right answer, for the reasons in why hotel and airport Wi-Fi breaks your VPN.

Staff needing to reach things that are not on the public internet. A file server, an internal application, a database, equipment at a site. This is remote access to a private network, it is a different product category, and no consumer subscription provides it. A subscription routes your traffic out through somebody else’s network; it does not create a path into yours.

Needing traffic to arrive from a known, fixed address. Because a supplier’s system, a client’s environment, or a regulator’s portal only accepts connections from addresses you have registered with them. That is a third requirement again, and it is about having a stable identifiable address rather than a private or varied one — close to the opposite of what a privacy-marketed service is designed to give you.

Write down which of the three you actually have. Businesses commonly have the first and the second, and they are usually best served by two separate arrangements rather than one compromise.

What makes it procurement rather than shopping

An individual buying a subscription risks their own money. A business buying one takes on obligations, and these are the ones that get discovered late.

Ownership of the account. If the subscription is in an employee’s name, on an employee’s card, with an employee’s recovery address, the business does not control it. Reimbursing someone’s personal subscription is the most common version of this mistake and it is invisible until the person leaves.

Revocation. You need to be able to remove one person’s access without disrupting anyone else’s and without changing a shared credential. A shared login fails this, and shared logins are what informal arrangements become.

Central administration. Whether settings can be enforced rather than suggested, whether you can see what is deployed, and whether a new starter can be set up without someone walking them through it. Consumer products are built for one person deciding for themselves, which is the wrong shape here.

Records for audit and accounting. Named invoices, a paper trail, and a defensible answer when someone asks who had access to what. Personal card receipts are not that.

Third-party obligations. If traffic covered by a duty of confidentiality — client data, health information, anything a contract speaks to — passes through a supplier, that supplier is part of your compliance position. You need a written processing arrangement, not a consumer terms-of-service page you clicked through.

Support you can rely on when it matters. Not the existence of support, but the commitment: response undertakings, an escalation path, and someone contractually accountable. A chat widget aimed at consumers is a different service.

The tension nobody points out

Business requirements and consumer privacy marketing pull in opposite directions, and the sooner you notice this the better your decision will be.

A business often needs to know who connected, from where, and when — for audit, for incident investigation, for regulatory answers. A consumer VPN’s central marketing promise is that it retains as little as possible about exactly that. The features are not just different; they are contradictory. A product optimised to know nothing about its users cannot give you an access record.

Which one you need depends on your first question. If the concern is protecting staff from untrusted networks, retaining nothing is a virtue. If the concern is controlled access to company resources, an authoritative access record is a requirement, and you should be buying something built to produce one.

There is a matching tension in the other direction, and it deserves an explicit policy: if company software carries staff traffic, it may also carry their personal browsing, particularly on their own devices. Decide what you will and will not collect, write it down, and tell people. Discovering this by accident is a serious problem, and it is the reason travelling with a work laptop treats the personal and company cases separately.

What to write down before you approach anyone

  • Who needs what. Which people, which resources, from which devices. Distinguish employees from contractors, and company devices from personal ones.
  • The joiner, mover, leaver process. How access is granted, changed, and removed, and who is responsible for each. If the answer is “whoever remembers”, fix that before choosing a product.
  • Your device reality. Managed or unmanaged, which platforms, whether you can require anything to be installed. This constrains the field more than any feature comparison.
  • Your obligations. Any contractual or regulatory commitments that a supplier in the traffic path affects, plus who signs off on that.
  • What happens when it fails. Whether work stops, whether there is a fallback, and who is called. Availability is a business question, not a technical one.
  • Exit. How you leave, what you take with you, and how long the process takes. Answer it before you sign, because you will not get a better answer afterwards.

Questions to put in writing to a vendor

Ask for these in email or in the contract, not from a comparison page. Whether an administrator can enforce configuration and revoke individual access. What is logged, retained for how long, and who inside the vendor can see it. Whether a data processing agreement is available and who its subprocessors are. What support response the vendor will commit to. What notification you get after a security incident. What the termination terms are. How the vendor handles requests for customer data from authorities.

The answers matter, and so does the responsiveness. A vendor that will not answer procurement questions in writing before you buy will not answer them after.

If you are a sole trader or a very small team

Then the honest answer may well be that a consumer subscription is fine, with two conditions: the account belongs to the business rather than to a person, and you know which of the three problems you are solving. Do not buy the enterprise shape of a problem you do not have. The general selection logic in how to choose a VPN applies to you more than any of the above.

Bottom line

Decide first whether you need protection on untrusted networks, access to private resources, or a fixed known address, because those are three products and not one. Then treat the purchase as procurement: business-owned accounts, revocable individual access, central administration, a written processing agreement, committed support, and a rehearsed exit. And resolve the contradiction between wanting an access record and buying a product that promises to keep none.