Also I think it's never enough. A bad guy makes you got a virus; logs your key presses and steals the vpn config, and bam, he is inside the company!
The way he must pass to get into company network have to be much more longer and complex.