You could use the same line and configure traffic policing to ensure that VPN traffic is always within a fixed bandwidth.
Or you could get a separate internet pipe (to another ASA interfce), but you'd have to be careful with the routing because you can only have one default route. You would have to leave the default route as it is, and put specifc routes for VPN peers down the new line. This would only work if you knew in advance what IP addresses VPN users would connect from.
I'd try the first option, and if that proves not to be acceptable, bump up the 1M line or get another.