Update - Okay I looked through the report again. The issue the security police had was with the VPN. They say Microsoft PPTP has issues associated with its use as a VPN solution and should be replaced with a more robust method of remote access. They reference
www.sans.org/resources/malwarefaq/pptp-vpn.php and www. schneier.com/paper-pptpv2.html. Cisco, OpenVPN can be configureed to suport both certificate and pssword authentication.
We have a Cisco ASA router but we were using Microsoft PPTP so need to enable Cisco's VPN.
They also rec a proxy server to reduce risk and data loss by logging and analysis.