Earlier quoted context omitted.
This may be a stupid question, but isn't it standard practice to require that employees use VPN? Why would they expose servers to the internet?
At least not unusual for many companies but there are proponents of a different philosophy [1]. The idea is that drawing a clear line between outside and inside became futile and you are much better off with an approach that recognizes that fact. Their somewhat provocative slogan is: "The perimeter is dead" . For those working at FAANG: Do you have a corporate VPN? Do you use it? Do you need it for your daily work? […
When I was at Microsoft, you still needed a VPN to connect to your dev machine and write code, but more and more internal services were moving to a zero-trust model that didn't require a VPN. Not sure if they've gotten there 100%, but it felt like the clear direction.