When people refer to the “NordVPN controversy”, they are often referring to a security incident involving a server hosted by a third-party data centre in Finland. NordVPN disclosed the incident publicly in 2019 and said unauthorised access had occurred in March 2018 through an insecure remote-management account at the data centre.
What happened in the NordVPN server incident?
According to NordVPN, the incident affected one server rather than its entire network. The company said no user credentials were affected and that the compromised server did not contain user activity logs. NordVPN also acknowledged that a TLS key was obtained, although it said this could not be used to decrypt NordVPN traffic. Following the incident, NordVPN said it terminated its relationship with the data-centre provider and introduced additional security measures, audits and infrastructure changes.
What does this mean for businesses comparing VPN services?
Security incidents are relevant when assessing any security provider, but organisations should also consider architecture, administration, access controls, visibility and how a service fits their current workforce. NordVPN is primarily a consumer VPN service, while Nord Security directs organisations looking for business network access towards its separate NordLayer product.
Cloudbrink addresses a different market. It is designed for enterprises managing secure access for remote and hybrid workers, with technologies including Zero Trust Network Access. It is not positioned as a consumer privacy replacement for NordVPN. For businesses, the more useful comparison is therefore between the security and access requirements of the organisation and the enterprise platforms designed to meet them.