Can a Stranger Reach Your Office Computer? How to Lock Down Remote Access

Forgotten remote desktop rules, unpatched VPN boxes and vendor support tools are how a lot of ransomware gets in. Here's a 5-minute check to see what you're exposing, and how to close it.

Can a stranger reach your office computer right now? Not by walking in. Over the internet, from anywhere, by typing your office's address into a remote desktop app.

For a lot of small businesses the honest answer is "maybe, and nobody knows." Someone set up remote access years ago so the owner could work from home, it worked, and it was never looked at again. That forgotten doorway is one of the most common ways ransomware gets in, and checking for it takes about five minutes.

The 5-minute check

You don't need to be technical for this. You're looking for three things.

  1. Look for port forwards on your router. Open Command Prompt (press the Windows key, type cmd, press Enter), type ipconfig and press Enter. The number next to Default Gateway (often 192.168.1.1 or 10.0.0.1) is your router. Type it into a browser, sign in with the router's admin password, and find the section called Port Forwarding, Virtual Servers, NAT or Firewall rules (the name varies by brand). Every rule there is a door from the internet to a device inside your office. Write down each one and what it points to. A rule for port 3389 is Remote Desktop, and it's the one to worry about first.
  2. Check whether Remote Desktop is turned on. On each Windows 11 PC, go to Settings > System > Remote Desktop. If the switch is on and nobody can tell you why, that's a finding. On its own it only allows connections from inside your network; combined with a port forward from step 1, it's open to the whole internet.
  3. List the remote support tools. On each PC, go to Settings > Apps > Installed apps and look for remote control software: TeamViewer, AnyDesk, ScreenConnect (ConnectWise Control), LogMeIn, Splashtop, Chrome Remote Desktop and similar. For each one, you should be able to name who uses it and whether that login has two-step sign-in. If nobody recognizes it, find out before you remove it, then remove it.

Optional fourth step: search "what is my IP" from the office, then look that address up at https://www.shodan.io/host/ followed by the number. Shodan is a search engine that indexes services exposed to the internet. If it lists open ports for your office, so can everyone else. An empty result doesn't prove you're safe; Shodan doesn't catch everything.

If all three checks come back clean and explained, you're ahead of most offices. If they don't, the rest of this post is how to close what you found.

Why this is the ransomware story

The Verizon Data Breach Investigations Report (DBIR) is the yearly study of real breaches that most of the security industry works from. In the 2026 edition, which looked at incidents from late 2024 to late 2025, something changed for the first time in the report's 19-year history: exploiting a software vulnerability became the most common way attackers got their first foothold, at about 31% of breaches. Stolen passwords had held the top spot every year before that.

The software getting exploited is mostly the equipment whose job is to let people in from outside: firewalls, VPN boxes and remote desktop servers. And ransomware showed up in 48% of the breaches Verizon analyzed, up from 44% the year before.

CISA, the federal cybersecurity agency, has named Remote Desktop exploitation, along with phishing and unpatched software, as one of the top three ways ransomware gangs got in, and its advisory on weak controls attackers routinely exploit lists exposed remote services and missing multi-factor sign-in near the top.

The reason is economics. Phishing needs a convincing email and a person who clicks. An exposed remote desktop needs neither. Automated tools try logins against the whole internet around the clock, and when one works, the attacker doesn't land in an email inbox. They land on a desktop inside your network, often with admin rights.

We've written about the 3-2-1 backup rule, which is how you survive ransomware. This post is the other half: keeping it from getting in.

Three terms, briefly

Remote Desktop (RDP) is Microsoft's tool for controlling a Windows computer from somewhere else. You see that machine's desktop on your screen.

A VPN is an encrypted tunnel from a laptop at home into your office network, so the laptop behaves as if it were plugged in at the office. The tunnel ends on a box at your office, often a feature of your firewall.

A port is a numbered doorway on a device. Remote Desktop normally listens on port 3389. "Exposed to the internet" means a port is open and anyone on Earth can knock on it.

All three exist to accept connections from outside your building. Every remote access setup is a deliberate hole in the wall. The question is how well it's guarded.

The three ways it goes wrong

The forgotten remote desktop

Someone needed to reach the office PC from home, and the quickest fix was a port forward on the router straight to that machine. It worked, so it stayed. Public scanners index exposed services constantly, so "nobody knows it's there" was never true. Login attempts start within hours and don't stop.

CISA's advice is plain: no machine should have Remote Desktop open to the internet. If someone needs it, put it behind a VPN or a secure access service and require multi-factor sign-in.

The VPN or firewall nobody patched

Firewalls and VPN boxes get security updates like everything else, but they're the one device you can't casually restart at 2pm, because it disconnects everyone working remotely. So the update waits for a quiet moment that never comes.

The DBIR shows how that plays out. Of the flaws on CISA's Known Exploited Vulnerabilities catalog (bugs confirmed to be under active attack), only 26% were fully fixed in the organizations Verizon had data on, down from 38% the year before. Fixing is getting slower while attacking is getting faster. When a flaw in your firewall becomes public, the attacker doesn't need a password or a phishing email. They need your firewall's version number.

Your IT vendor's support tool

Every IT provider, bookkeeper and software vendor who supports you remotely has a way into your systems. That's normal. But your exposure now includes their security habits. The 2026 DBIR found a third party involved in 48% of breaches, up from 30% the year before. CISA published a whole Guide to Securing Remote Access Software because these legitimate tools are abused so often, and in your logs, abuse looks exactly like support.

How it usually plays out

A six-person office has one server running its industry software. Years ago a previous IT person forwarded Remote Desktop to it so the owner could work weekends. The login is a local admin account with a password that has never changed and no second step.

Automated guesses run against that port for months. Nobody notices, because nobody collects the logs. Eventually one works, using a password that leaked in an unrelated breach and was reused. The attacker looks around quietly for a couple of weeks and finds the backup folder, mapped as a drive on the same server with full write access. On a Friday night they encrypt the files and the backups together.

No employee clicked anything. The way in was a router setting everyone had forgotten, and the damage was doubled by a backup that lived on the same box it was backing up.

The good news from the same report: 69% of ransomware victims didn't pay. Refusing is much easier when your backups survived, which is why entry-side controls and the 3-2-1 rule are two halves of one plan.

How to lock it down

Do these three first

  1. Get Remote Desktop off the internet. Delete the port forward from your 5-minute check. If people need to reach office machines, put that access behind a VPN or a zero-trust access service, which checks the person and device for each app instead of dropping them onto your whole network.
  2. Put multi-factor sign-in on every remote entry point. VPN, remote desktop gateway, remote support tools, email and every admin account. This is CISA's headline recommendation because it breaks automated password guessing outright. If you use Microsoft 365, our guide to the Microsoft 365 security settings small businesses never turn on covers the email side.
  3. Make one backup copy unreachable from the network. Offline, immutable, or in a separate account with separate credentials. If a compromised server can write to your backups, you don't have backups.

Then work through the rest

  1. Patch firewalls and VPN boxes on a schedule. Edge devices first, ahead of workstations. Subscribe to your vendor's security notices and check the Known Exploited Vulnerabilities catalog. Anything on that list is an emergency, not a maintenance item. Book a recurring update window so it isn't a decision every time.
  2. Retire equipment past end of support. A firewall that no longer gets firmware updates can't be fixed. Check the model on the vendor's end-of-life page.
  3. Turn off UPnP on the router unless you know you need it. It lets devices open ports on their own, which is how port forwards appear that nobody created.
  4. Follow the VPN hardening guidance. NSA and CISA's Selecting and Hardening Remote Access VPNs is short and free.
  5. Audit your vendors' access. Ask everyone who can remote in: which tool, which accounts, is multi-factor enforced, and is access logged? Remove accounts for vendors you no longer use.
  6. Start collecting logs. Even basic alerts on repeated failed logins at your firewall or VPN turn months of invisible guessing into something you can see and fix.

A stolen password is the other common way in, which is why credential stuffing is worth reading next.

When to call someone

  • Your check found a port forward or remote tool and you can't tell whether it's still needed or who set it up.
  • Your firewall or VPN box is past end of support, or you can't find out what firmware it runs.
  • You see signs someone already got in: unknown admin accounts, remote sessions nobody started, files renamed with odd extensions.

In the last case, disconnect the affected machine from the network (unplug the cable or turn off Wi-Fi, don't shut it down) and get help before you change anything else. If you'd rather have someone go through this with you, our cybersecurity team does it every day. Already have an IT person or provider? Co-managed security adds round-the-clock threat detection and response alongside them, plus log collection, so months of guessing don't go unseen.

Related reading