Yeah right, the folks that write our intranet tools are the ones not qualified enough to work on a shipping product (I know this is harsh but the few exceptions just prove the rule).
No way in hell we'd expose their stuff directly to the internet, especially since these internal tools deal with things like benefits, paystubs, asset allocations, access control, etc.
The government's point here is that qualified people should be writing those intranet tools. It is no longer ok to write insecure janky software because "don't worry we can secure later by putting it behind a VPN/Firewall". That is fixing bad engineering with duck tape. The correct approach is to engineer it correctly.
Write your software as if it was going to be directly exposed to the internet. While VPNs do provide protection, they do not provide sufficient protection.
If software isn't safe to use without a VPN, it isn't safe to use with a VPN either.
You could use something like Cloudflare Access to secure it, while it's on the Internet. There's no reason you need to build the security just because you build the tool.
No way in hell we'd expose their stuff directly to the internet, especially since these internal tools deal with things like benefits, paystubs, asset allocations, access control, etc.