What a VPN Does and Doesn’t Protect
A virtual private network, commonly known as a VPN, is often marketed as an all-in-one privacy and security solution.
Advertisements may suggest that switching on a VPN makes you anonymous, blocks hackers, protects your passwords and keeps every part of your online activity completely private.
The reality is more nuanced.
A reputable VPN can provide useful protection, especially when using public Wi-Fi, working remotely or connecting to business systems. However, it does not replace antivirus software, secure passwords, multi-factor authentication or sensible browsing habits.
Understanding what a VPN does—and what it does not do—can help you use one effectively without developing a false sense of security.
What Is a VPN?
A VPN creates an encrypted connection between your device and a VPN provider’s server.
Instead of connecting directly to a website or online service, your internet traffic first travels through this encrypted tunnel. The VPN server then connects to the destination on your behalf.
This changes two important parts of your connection:
- Your internet provider sees that you are connected to a VPN, but has less visibility into the traffic passing through it.
- Websites generally see the VPN server’s internet protocol address rather than your home or office IP address.
This can improve privacy, but it does not make you invisible online.
What Does a VPN Protect?
It Encrypts Traffic Between Your Device and the VPN Server
The main benefit of a VPN is encryption.
Without a VPN, someone monitoring an insecure network may be able to observe parts of your connection. With a VPN enabled, the traffic between your device and the VPN server is encrypted.
This is particularly useful when using:
- Hotel Wi-Fi
- Airport networks
- Coffee-shop Wi-Fi
- Conference-centre networks
- Shared accommodation networks
- Other public or untrusted connections
Modern websites already use HTTPS encryption, but a VPN adds another protective layer around your connection.
It Reduces What Your Internet Provider Can See
Your internet service provider normally handles your connection to websites and online services.
When you use a VPN, your provider can generally see that you are connected to a VPN server, along with connection timing and data usage. However, it has less visibility into the individual services being accessed through that tunnel.
This can improve privacy from your internet provider, although the VPN company itself becomes an important point of trust.
It Hides Your Public IP Address From Websites
Websites normally see the public IP address assigned to your internet connection.
A VPN replaces this with the IP address of its server.
This can make it harder for websites, advertisers and other online services to associate activity directly with your home or office internet connection.
However, websites may still identify you through:
- Cookies
- Account logins
- Browser fingerprinting
- Advertising identifiers
- Tracking pixels
- Device information
Changing your IP address is not the same as becoming anonymous.
It Can Protect Remote Access to Business Systems
Businesses often use VPNs to allow staff to connect securely to internal systems from outside the office.
A business VPN may provide access to:
- Internal file servers
- Line-of-business applications
- Remote desktops
- Management platforms
- Private intranet pages
- Network equipment
In this situation, the VPN is not mainly being used to hide a user’s location. It creates a secure route into the organisation’s network.
Access should still be protected by strong authentication and appropriate device-security controls.
It Can Reduce Risk on Untrusted Networks
Public Wi-Fi is not automatically dangerous, but you should not assume it is trustworthy.
A malicious hotspot, compromised router or poorly configured network could attempt to inspect or redirect traffic.
A VPN can reduce this risk by encrypting traffic before it leaves your device.
It does not make a compromised device safe, but it can make the network itself less capable of interfering with your connection.
It May Help With Location-Based Access
Some VPN services allow users to connect through servers in different countries.
This can make online services believe that the connection originates from the VPN server’s location.
People sometimes use this for:
- Accessing business systems restricted by location
- Testing websites from different regions
- Maintaining access while travelling
- Viewing services available in their home country
However, streaming platforms and other providers may block VPN traffic, and using a VPN does not override a service’s terms or local laws.
What Doesn’t a VPN Protect?
It Does Not Stop Malware
A VPN does not automatically block:
- Viruses
- Ransomware
- Spyware
- Keyloggers
- Malicious applications
- Infected documents
- Dangerous browser extensions
Some VPN products include additional web-filtering or security features, but the VPN tunnel itself is not antivirus protection.
If you download and run a malicious file, the VPN may simply deliver that file through an encrypted connection.
You still need:
- Reputable endpoint protection
- Current software updates
- Secure browser settings
- Regular backups
- User awareness
It Does Not Protect You From Phishing
A VPN cannot tell whether a login page is genuine.
If you enter your Microsoft 365, banking or social-media password into a convincing phishing page, the attacker can still receive it.
The connection to the phishing site may even be encrypted.
A padlock icon or VPN connection only means that traffic is encrypted. It does not prove that the person or organisation receiving the information is trustworthy.
Protection against phishing requires:
- Careful link checking
- Multi-factor authentication
- Email filtering
- Password managers
- User training
- Suspicious-login monitoring
It Does Not Make You Anonymous
A VPN improves privacy, but complete online anonymity is difficult to achieve.
You can still be recognised when you:
- Sign into an account
- Accept tracking cookies
- Use the same browser profile
- Submit personal details
- Pay using an identifiable method
- Use an advertising-linked device
- Allow browser fingerprinting
- Share your location with an application
For example, signing into a Google, Microsoft or social-media account immediately tells that service who you are, regardless of your IP address.
It Does Not Protect Accounts With Weak Passwords
A VPN cannot prevent an attacker from signing into an account using a stolen or reused password.
If you use the same password across several websites, one data breach may expose multiple accounts.
VPN use should be combined with:
- Unique passwords
- A reputable password manager
- Multi-factor authentication
- Login alerts
- Breach monitoring
Account security and connection security solve different problems.
It Does Not Secure a Compromised Device
If your laptop or phone already contains malware, a VPN will not remove it.
A keylogger may still record what you type. Spyware may still capture screenshots. A malicious browser extension may still access webpages.
The VPN protects data while it travels across the network. It cannot guarantee that the device creating or receiving that data is secure.
It Does Not Prevent Tracking by Logged-In Services
A VPN changes your visible IP address, but it does not stop platforms from recording your activity when you are signed in.
A search engine, retailer or social network may still track:
- Pages viewed
- Searches performed
- Purchases
- Videos watched
- Devices used
- Account interactions
- Advertising interests
The VPN provider cannot prevent a service from recording activity that you perform within your own account.
It Does Not Protect Data After It Reaches the Destination
VPN encryption applies between your device and the VPN server.
After traffic leaves the VPN server, it continues towards the destination. Most reputable websites use HTTPS, which provides its own encryption, but a VPN cannot control how the destination stores, processes or shares your information.
If a website suffers a data breach, your account information may still be exposed.
A VPN cannot protect data once you have voluntarily submitted it to another organisation.
It Does Not Guarantee Safe Downloads
A VPN may help keep outsiders from observing what you download, but it does not verify that the file is safe.
Malicious software can be distributed through:
- Fake updates
- Pirated applications
- Email attachments
- Compromised websites
- Fake security tools
- Browser pop-ups
Treat downloads with the same caution whether a VPN is enabled or not.
It Does Not Replace HTTPS
A VPN and HTTPS protect different parts of a connection.
HTTPS encrypts traffic between your browser and the website. A VPN encrypts traffic between your device and the VPN server.
Using both provides stronger protection than relying on either one alone.
Avoid assuming that a VPN makes an unencrypted website secure. Information entered into an HTTP-only site may still be exposed after it leaves the VPN server.
Does a VPN Protect Online Banking?
A VPN can help protect the network connection, particularly on public Wi-Fi.
However, it does not protect you from:
- Fake banking websites
- Stolen passwords
- Compromised devices
- Fraudulent phone calls
- Malicious remote-access software
- Social-engineering scams
For online banking, you should also use the bank’s official application or verified website, enable strong authentication and avoid responding to unexpected requests for passwords or security codes.
Can a Free VPN Be Trusted?
Free VPNs can carry significant trade-offs.
Running a secure global VPN service costs money. A free provider must therefore fund the service in another way.
This may involve:
- Advertising
- Limited speeds
- Restricted data allowances
- Selling premium upgrades
- Collecting usage data
- Sharing information with partners
Not every free VPN is unsafe, but users should carefully review who operates the service, how it is funded and what data it records.
Avoid installing an unknown VPN simply because an advert claims your device is exposed.
What Should You Look for in a VPN Provider?
A suitable VPN service should offer clear information about:
- Encryption standards
- Logging policies
- Ownership
- Jurisdiction
- Independent security audits
- Device compatibility
- Update practices
- Business support
- Multi-factor authentication
- Breach-response procedures
For organisations, consumer-focused VPN subscriptions may not provide the control, visibility or access management required for business use.
A professionally managed remote-access solution may be more appropriate.
VPN Logging Policies Explained
Many providers advertise a “no-logs” policy, but the phrase can mean different things.
A service may avoid storing browsing history while still recording:
- Connection times
- Device information
- Account details
- Data volumes
- Payment information
- Server choices
- Diagnostic records
The important question is not simply whether the provider uses the words “no logs,” but exactly what information it collects, why it collects it and how long it is retained.
Independent audits can provide additional confidence, but they should still be reviewed carefully.
Does Your Business Need a VPN?
A VPN may be useful for businesses that need secure remote access to internal systems.
However, modern cloud-based working has changed the role of traditional VPNs.
If most business services are hosted in Microsoft 365, Azure or other cloud platforms, organisations may benefit from a wider security approach involving:
- Conditional Access
- Multi-factor authentication
- Device compliance
- Microsoft Intune
- Entra ID
- Endpoint detection and response
- Zero Trust principles
- Secure web gateways
- Identity monitoring
A VPN can remain an important component, but it should not be the only security control.
Common VPN Myths
“A VPN Makes Me Completely Anonymous”
It hides your normal public IP address, but accounts, cookies, fingerprinting and personal information can still identify you.
“A VPN Stops Hackers”
It can reduce certain network risks, but it does not prevent phishing, malware, weak passwords or compromised accounts.
“A VPN Means I Don’t Need Antivirus”
VPN encryption and antivirus software perform different jobs. Many users and businesses need both.
“A VPN Makes Every Website Safe”
It does not verify whether a website is legitimate or trustworthy.
“All VPN Providers Offer the Same Protection”
Providers differ significantly in security, ownership, logging, infrastructure and transparency.
When Should You Use a VPN?
A VPN is particularly useful when:
- Working on public Wi-Fi
- Travelling
- Connecting to private business systems
- Using an untrusted network
- Reducing visibility from an internet provider
- Protecting remote-access traffic
- Testing online services from another region
It should be treated as one layer within a broader security strategy.
The Best Protection Uses Multiple Layers
A VPN is most effective when combined with:
- Updated operating systems
- Reputable antivirus or endpoint protection
- Multi-factor authentication
- Unique passwords
- Secure backups
- Email filtering
- Staff cyber-security awareness
- Device encryption
- Access controls
- Regular security reviews
No single product can protect against every online threat.
So, Is a VPN Worth Using?
For many people and businesses, yes.
A reliable VPN can improve connection privacy, protect traffic on untrusted networks and provide secure access to private business resources.
However, it cannot make you anonymous, stop every cyberattack or compensate for weak account security.
The safest approach is to understand the problem the VPN is designed to solve and avoid expecting it to provide protection outside that role.
How Hamilton Group Can Help
Choosing the right VPN or remote-access solution can be confusing, particularly when services make broad claims about privacy and security.
Hamilton Group can help businesses assess whether a VPN is appropriate, configure secure remote access and build the additional protections needed around it.
We can assist with:
- Business VPN deployment
- Secure remote working
- Microsoft 365 security
- Multi-factor authentication
- Entra ID and Conditional Access
- Endpoint protection
- Device management
- Cyber-security assessments
- Secure network configuration
- Ongoing managed IT support
To discuss your business security or remote-access requirements, call Hamilton Group on 0330 043 0069 or visit hgmssp.com.