Incidentally, I work at a bank, and to get access remotely you have to have a randomly-generated username, a random password, and a client-side certificate. The VPN software denies all outgoing connections except to port 80 (and the VPN port, I guess) when it is not active. When it is active, it makes all the network interfaces that aren't the VPN disappear (so you can't see your link-level network anymore). Then, it asks for your password every 24 hours.
Usually I find the commute to work less stressful.
But it does show you that some organizations do take data security seriously... perhaps too seriously. (The port blocking is just security theater. I can run whatever I want over port 80. But the random username / random password / client-side SSL certificate is excellent security.)