My advice to them? Don't obsess about it. There are some cases where you should be concerned about the physical security of your network, but at some point you're either going to have to trust an outside provider or run a cable through a secure area. In the case of this particular client, the risk seemed acceptable.
In the scenario you describe, an outside manhole shouldn't be a great concern. Once the traffic leaves your private network and enters the public Internet (which is of course where it goes once it leaves your building), none of the sensitive data should be sent without using encryption. Proper data encryption mitigates the risk of interception. There's no difference between someone climbing down a manhole and tapping your external connection and an eavesdropping hacker that compromises an intermediate router somewhere on the Internet.
Dig Deeper on VPN security
Related Q&A from Mike Chapple
It's not possible to eradicate the risk of DoS attacks, but there are steps infosec pros can take to reduce their impact. Mike Chapple shares ... Continue Reading
The HHS OCR ruled that healthcare ransomware attacks are HIPAA violations, so these covered entities need to react according to the HHS's guidance. ... Continue Reading
HIPAA regulations incorporate NIST guidelines and standards, so do healthcare organizations need to be compliant with both? Expert Mike Chapple ... Continue Reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.