Blog / Threats
Threats
Remote Desktop Security: RDP, VPN and RMM Are the New Front Door, and It Is Usually Unlocked
Remote desktop security in 2026 is about three doors: RDP, the VPN box and the RMM tool. How attackers find them in days, and how to lock each one this week.
Tuesday the scanner finds it, Thursday they are reading tax returns
The 25-person accounting firm bought its firewall in 2019 from an IT provider it no longer uses. The firewall has a VPN feature so the partners can reach the file server from home during tax season. It has worked for years, which is why nobody has looked at it. The login is a username and a password. There is no second factor, because the box never asked for one.
On a Tuesday in early April an automated scanner, one of thousands that sweep the internet all day, records that the firm's public address is running a VPN service with a known, unpatched flaw. The result goes into a list. The list is sold.
On Wednesday evening someone buys the list, tries the flaw, and gets a shell on the firewall. From there the file server is one hop away. Client folders. Bank statements. Scanned IDs. The tax returns for 900 households, most of them with Social Security numbers on the first page.
On Thursday the attacker installs a remote-management tool on the server, the same kind of tool the IT provider uses, so the connection looks like maintenance. Nobody notices, because nobody is looking, because it is April and everyone is looking at returns. The firm learns about it in June from a client whose refund went to someone else's account.
The firewall had a patch available since January. The VPN had needed MFA since the day it was switched on.
What the heck does this mean
Remote access is any way to reach your systems from outside the office. It is essential and it is where the majority of break-ins that are not email fraud now begin.
RDP, Remote Desktop Protocol, is the built-in Windows feature for controlling one computer from another. Exposed to the internet, it is a password-guessing target from the moment it goes live.
A VPN is the encrypted tunnel from a laptop at home into the office network. The tunnel is fine. The box that terminates it, the firewall or VPN appliance, is a computer with its own flaws, and it sits by definition on the public internet.
An edge device is any such box on the boundary. One flaw opens every network that runs the same model, which is why attackers collect them.
RMM, remote monitoring and management, is the software IT providers use to administer your machines from afar. It is legitimate, powerful, and exactly what an attacker installs once inside, because it looks like maintenance and gives them a permanent seat.
Vulnerability exploitation is the plain phrase for all of this: using a known software flaw that a patch would have closed.
The numbers that matter
Exploitation of vulnerabilities became the top way in, at 31% of breaches, and the median time to patch reached 43 days, according to the Verizon 2026 Data Breach Investigations Report. Forty-three days is a long time to leave a door open on a street where every house is tried every night.
RMM abuse rose 277% and appeared in 24% of incidents, per the Huntress 2026 Cyber Threat Report. One incident in four now involves the attacker running the same kind of tool your IT provider does.
65% of intrusions that were not business email compromise came through RDP, VPN or RMM abuse, in the Arctic Wolf 2026 Threat Report. Three doors. Two-thirds of the burglaries.
What to do this week
- Find out what you have facing the internet. Ask your IT provider for a list of every public address and every service on it, or have an outside scan done. If RDP is on the list, close it today. (CIS 12 Network Infrastructure Management)
- Put multi-factor authentication on the VPN and on every remote-access path, no exceptions for partners, no exceptions for the IT provider. (CIS 6 Access Control Management)
- Check the firmware date on the firewall and VPN appliance. If it is more than a few months old, patch it this week, and set a standing rule that edge devices are patched within days of a release, not at the next quarterly visit. (CIS 7 Continuous Vulnerability Management)
- Inventory remote tools on every machine and remove any that are not the one your current provider uses. The tool from the 2019 provider is a door with a key you no longer hold. (CIS 2 Inventory and Control of Software Assets)
- Retire equipment that no longer receives security updates. A firewall from 2019 that its maker stopped supporting is not a bargain. It is an open port with a warranty sticker. (CIS 12 Network Infrastructure Management)
- Get someone reviewing VPN and admin logins weekly during your busy season, when you are least likely to notice and most likely to be hit. (CIS 6 Access Control Management)
Where AccuSights fits
Our assessment starts from the outside, the way the scanner does: what is exposed, what version it runs, what patch it is missing, and which remote tools sit on your servers that nobody can explain. The Cyber Hygiene Test takes three minutes and asks the first questions. For a look at your actual edge, book 15 minutes with an engineer.
Questions people ask
Should RDP ever be open to the internet? No. Remote Desktop was designed for use inside a network, and an RDP port facing the internet is found by automated scanners within hours and hammered with password guesses from then on. If staff need to reach a desktop from home, put it behind a VPN with multi-factor authentication or a modern remote-access gateway that requires identity first. There is no configuration of open RDP that a small business should accept.
Does a VPN need MFA? Yes, without exception. A VPN login is a door into the whole network, and a password alone is a door with a spare key under the mat. Every stolen-credential list and every infostealer log includes VPN passwords. Add MFA today, and check the firewall or VPN appliance itself for updates, because the box protecting the door has had its own share of holes in the last two years.
How do I know which remote tools are installed on my computers? Ask your IT provider for a software inventory from every machine, then search it for the common remote-control products and anything you do not recognize. Compare the result with the one tool your IT provider actually uses. Anything else is either a leftover from a previous provider or something an attacker installed. Remove it, and set an alert so a new one cannot appear quietly.
The firewall is not the wall. It is the door in the wall, and doors are only as good as whoever checks the lock.
Questions people ask
Should RDP ever be open to the internet?
No. Remote Desktop was designed for use inside a network, and an RDP port facing the internet is found by automated scanners within hours and hammered with password guesses from then on. If staff need to reach a desktop from home, put it behind a VPN with multi-factor authentication or a modern remote-access gateway that requires identity first. There is no configuration of open RDP that a small business should accept.
Does a VPN need MFA?
Yes, without exception. A VPN login is a door into the whole network, and a password alone is a door with a spare key under the mat. Every stolen-credential list and every infostealer log includes VPN passwords. Add MFA today, and check the firewall or VPN appliance itself for updates, because the box protecting the door has had its own share of holes in the last two years.
How do I know which remote tools are installed on my computers?
Ask your IT provider for a software inventory from every machine, then search it for the common remote-control products and anything you do not recognize. Compare the result with the one tool your IT provider actually uses. Anything else is either a leftover from a previous provider or something an attacker installed. Remove it, and set an alert so a new one cannot appear quietly.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
How to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It
Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.
ThreatsBusiness Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank
Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.
ThreatsAI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not
AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.
