Remote work is normal now. The way many small businesses enabled it is not: a port opened on the firewall so Remote Desktop can be reached from anywhere. It works, which is the problem — it works for everyone, including the automated scanners that try thousands of passwords a day against exactly that door.
What goes wrong
Exposed remote desktop is one of the top two ways ransomware groups get in (the other is phishing). They do not need a vulnerability; a guessed or leaked password is enough. From there the burglary described in our ransomware article begins.
What secure remote access looks like
- A VPN or zero-trust gateway in front of everything — the door is invisible until you have proved who you are.
- Multi-factor authentication on the connection itself, so a password alone opens nothing.
- Company-managed devices, or at least a check that the connecting machine is patched and protected.
- Access to what the person needs, not to the whole network because that was easier to set up.
Does it slow people down?
Set up properly, no. Staff open an app, approve a prompt on their phone, and are in. The friction people remember is from badly configured VPNs of years past. We design remote access so the accountant at home, the dispatcher on the road and the engineer at 2 a.m. all have the same experience: quick, and quietly watched.

