The tunnel, the moat, and the bridge - three ways to guard what shouldn't be reached from outside.
A VPN (virtual private network) sounds boring, but the idea is elegant: you dig an encrypted tunnel through the open internet, and on the other side you come out inside the network, as if you'd never been outside. For remote work it's convenient - you sit at home, and the system treats you like an employee at a desk. The problem is that the tunnel doesn't ask who's actually going through it. It only asks whether you have the key.
And that's exactly why a VPN is attackers' favorite door. They don't have to break a wall - it's enough to steal login credentials leaked from some other site and try them here, hoping the password is the same. Once they're through the tunnel, the system inside sees only legitimate traffic - the thief stays invisible to it. That's why good networks no longer trust the tunnel alone - they demand a second proof: a device they recognize, behavior that fits.
Air-gap is the other extreme - a moat with no bridge at all. The machine has no cable to the internet, no Wi-Fi chip, it's physically cut off. It's used where the cost of a breach is catastrophic: industrial control systems, backups, the most important encryption keys. The inconvenience is brutal - every update walks in on foot, on a USB stick, through a person who carries the risk literally in his pocket. But that inconvenience is exactly the protection. No network - no way to hack it remotely.
A jump host is the compromise between the two - a narrow bridge across the moat, instead of ten open doors. Anyone who wants to reach the internal systems passes through it first, and from there every one of his moves is logged. The good part is that instead of guarding a hundred entrances, you guard one, tightly. The bad part is the mirror image - if that one bridge falls, the attacker inherits all the traffic that passed over it. That's why good teams don't stop there - they watch the bridge itself as closely as the moat behind it.
This one holds up
My first instinct at home was to open a VPN to everything - it's convenient, you work from anywhere. Then I thought about who else has that same key if my laptop leaks or my password shows up in some old breach. Now the most sensitive things have no network path out at all - literally an air-gap on a small machine, reachable only in person. It's not convenient. That's exactly why it works.
I keep a VPN only for the things I need to reach remotely, and through a narrow jump host, not an open door to everything. The difference is philosophical: you accept that convenience and security pull in different directions, and you decide consciously what each one is worth, instead of letting inertia decide for you.