The typical weak points
From security reviews I know the same points every time: Remote Desktop reachable directly from the internet, VPN without a second factor, private computers without encryption and updates, company data on local disks without backup, shared passwords for remote access. Each of these points is enough for a successful attack, and ransomware groups look for exactly that.
Access: VPN instead of open ports
No company service should be reachable directly from the internet, neither Remote Desktop nor NAS nor line-of-business software. The way into the company network leads through a VPN with modern encryption, for example WireGuard or IPsec on an OPNsense firewall, with personal access per employee that can be disabled individually. Anyone who exclusively uses cloud services such as Microsoft 365 does not need a VPN, but all the stricter login protection.
Login: second factor and passkeys
Passwords alone no longer protect, they are phished or tried from old data leaks. Multi-factor authentication via app or hardware key belongs on every access: VPN, email, Microsoft 365, customer portals, remote maintenance. Even better are passkeys based on the FIDO2 standard: they are phishing-resistant because they are bound to the real website, and easier for employees than typing codes. A password manager for the team ensures that passwords no longer end up in spreadsheets.
Devices: company devices or clear rules
- Company devices instead of private computers: manageable, encrypted, with updates and without family use
- Disk encryption with BitLocker or FileVault, so a stolen notebook is not a data breach
- No administrator rights in daily work, automatic updates, antivirus with central management
- Screen lock, remote wipe via Intune or a comparable tool in case of loss
- If private devices are unavoidable: access only via terminal server or browser, no local company data
Data: central instead of local
Company data belongs on central, backed-up systems: file server, NAS with snapshots, SharePoint or OneDrive with backup. Local copies on the notebook are working copies, not storage. That way the backup stays in one place, permissions are managed centrally, and when an employee leaves it is clear where the data is.
Checklist to start
- Inventory all services reachable from the internet and put them behind VPN or cloud login protection
- Enable multi-factor authentication everywhere, passkeys where the service offers them
- Encrypt company notebooks, manage updates and antivirus centrally
- Central data storage with backup, avoid local copies
- Put rules in writing: devices, passwords, reporting of incidents, behaviour with suspicious emails
- Have the measures checked once a year to see whether they still work
Frequently asked questions
Is Remote Desktop with port forwarding really that dangerous?
Yes. Open Remote Desktop ports are scanned automatically and attacked with stolen credentials, it is one of the most common entry points for ransomware. Remote Desktop belongs exclusively behind a VPN or a gateway with multi-factor authentication.
Is multi-factor authentication via SMS enough?
Better than nothing, but SMS can be intercepted and redirected. An authenticator app, a hardware key or passkeys are considerably more secure and no more effort for employees in daily use.
What does a secure home office setup cost?
For a small business: a firewall with VPN from about €590 setup, multi-factor authentication is included with most services at no extra cost, encryption is built in. The biggest item is usually the company devices themselves.
Need help implementing this? I implement it for you, remotely or on site in Vienna, at a fixed price or based on effort. Send request →