I would call that system secure. It does not just rely on an obscure password but is actually restricted by a list of whitelisted networks.
The failure in that case is only that the admin didn't consider that normal work might be done from home at some point or that the middle or upper manager thinks that he should be able to freely administrate his critical infrastructure from anywhere...