Remote desktop and remote support
You cannot check what is being done. You can only decide who
Fifty notes on remote access from both ends: what the person being helped actually sees, how to run a session they can follow, the fraud that uses the same tools, and what to do in the first hour if it has already happened.
Core notes remain practice-focused; separate guides compare named tools. No unverified fraud statistics. Nothing here is legal advice.
The trust problem
A remote session asks somebody to trust completely and gives them no means of checking. That is not a flaw in any particular product; it is the shape of the thing.
The practical lesson in “You cannot check what is being done. You can only decide who” is to make responsibility visible without confusing visibility with certainty. A team reviewing employee monitoring software for employee monitoring software can add structured time and project context, provided the purpose is disclosed and the interpretation is checked with the people affected.
The person cannot tell whether the actions on screen match the explanation. They cannot know what a command does, distinguish a diagnostic from a search of their files, or see what was copied. With a tradesperson in your home you can watch. Here, watching does not help, because the activity is technical, fast, and legible only to the person performing it.
For an independent reference related to “You cannot check what is being done. You can only decide who”, consult the ENISA cybersecurity resources; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.
Which means the decision happens before the connection, not during it. Once the session starts there is no meaningful ongoing check. That is why every piece of advice about remote access fraud concerns the moment before, and why pressure to connect quickly is the clearest warning sign there is.
Why the same tools serve help and harm
A tool designed so that access is easy to grant is a tool where access is easy to obtain by deception. The ease is the feature and the vulnerability, and no configuration separates them.
This is not a criticism of the products, which could not do their job otherwise. It is the reason the safeguards in this collection are things people say and do rather than things they switch on.
Four sentences before you connect
"Here is what I think is wrong and what I am going to do." It gives the person a reference to check against. They cannot verify a command, but they can notice that you said you were checking printer settings and are now in their documents.
"You can end this at any time — here is how." Most people do not know they can stop it. That knowledge changes the relationship from permission granted to permission continuing, which is a materially different thing. It is also the single most useful fact a person can carry into any future session, including one they should not have agreed to.
"I will tell you what I am doing as I go." Narration is the only running account the person has.
"Please close anything private before we start." Everybody has something open they would rather not show. Ten seconds, and it signals that you are not interested in anything else.
A minute in total, and almost nobody says them.
The fraud that uses these tools
A substantial and persistent fraud uses remote access against individuals. Its shape is recognisable even when the details change.
Contact comes to the person: an unexpected call claiming to be from a technology company, a bank or a provider, or a message on screen with a number to ring. Access is requested as "checking" or "fixing", never as granting control. Something is then shown that appears to demonstrate a problem or a refund — constructed by the caller and not real. And it ends in a request for an irreversible transfer of value.
The signature is three things together: urgency, secrecy and continuity. It must be now; do not discuss it with anybody, including bank staff; stay on the line. Those three appear in almost no legitimate interaction.
The one-line test is simpler than any of it. Did I contact them, or did they contact me? No legitimate organisation initiates contact and then asks for access to your computer.
Why it works, and on whom
The common explanation is that victims are naive. That explanation is wrong, unhelpful, and it stops the people who hold it from recognising their own exposure.
What produces vulnerability is a set of conditions rather than a trait: being interrupted, being tired or unwell or recently bereaved, having just had a genuine technical problem, being alone with nobody to ask, and being spoken to by somebody calm and competent while you are not. Anybody can be in all five on a given afternoon.
And the active ingredient is isolation. The instruction not to discuss it is the most important thing the caller does, because one conversation with almost anybody ends it. Which is why the single most effective protection is not knowledge but a person who is easy to ring — and why making somebody feel foolish for asking is more damaging than it appears.
What to do if it has already happened
The first hour matters most, and the order is not obvious.
Disconnect the machine. Turn off the wireless, unplug the cable, or switch it off entirely. This ends any active session immediately. Do not try to work out what they did first — that can wait and the connection cannot.
Ring the bank, from a different phone if the call might still be connected, using the number on a card or statement rather than anything provided during the incident. Banks can sometimes stop or recall a transfer in the first hours, and the window closes fast.
Change passwords from a different device, email first because it controls everything else. Then the machine itself: assume anything on it was seen and anything typed was captured, which usually means a clean reinstall rather than removing what you can find.
And expect a second approach. People who have been defrauded once are contacted again, sometimes by somebody offering to recover the money. That offer is part of the same industry.
The conversation afterwards
How this is handled determines whether they tell you about the next one, which is the thing that actually matters.
What they are feeling is shame disproportionate to anything they did wrong, and frequently a specific fear that this will become evidence they can no longer live independently. That fear shapes everything about whether they say anything at all.
Three things make it worse. "How could you fall for that" confirms their worst interpretation and ends disclosure permanently. Taking over removes the competence they are already doubting. And telling the family as a story converts a difficult experience into their identity within the family — they will know.
What helps is the opposite: this happens to a great many people and the people doing it are extremely good at it; here are the steps, done together; and this changes nothing about what you can manage, which is why telling me quickly is useful rather than costly.
For support desks
The professional half of this collection argues that the controls have to work without depending on everybody being thoughtful on every call.
Which means scoping technicians to the machines they actually support, rather than leaving the default of everything. It means logs indexed by machine, because "who connected to my computer last week" is the question people actually ask and most platforms answer only by technician. It means attended sessions by default, with unattended access inventoried and reviewed rather than accumulating.
And it means a handling-time target that allows two minutes for the opening and the summary. If it does not, the target is setting the conduct — which is a management decision rather than a training failure, and saying so is the only way it changes.
There is also a verification that runs the other way and is almost always missing. Users should be able to confirm that a support contact is genuine, because the consumer fraud has an organisational version, and a workforce trained to accept any call from "IT" is the vulnerability.
What the core notes deliberately avoid
No products are named. The tools consolidate and the names date — and naming a legitimate product in a chapter about fraud would misdirect the warning. The rule worth teaching is not about which software: the name of the program does not make it safe or unsafe. Who asked you to install it does.
No fraud statistics, because the available figures vary by orders of magnitude depending on who counted.
And no step-by-step account of the fraud. The recognisable shape is what transfers to variants; the mechanics are not set out, and are not needed.
01 — Basics
What a session is
The helper sees everything and knows what they are doing. The person sees their own screen moving and cannot tell whether it matches.
- 01.01What a Remote Session Actually IsExplainer
- 01.02Attended and Unattended: the Distinction That MattersExplainer
- 01.03The Trust Problem at the Centre of ItAnalysis
- 01.04What the Person Being Helped Can and Cannot SeeReference
- 01.05Remote Desktop, Remote Support and Screen SharingReference
- 01.06When Not to Use ItAnalysis
02 — The session
Conducting a session
The protection here is not technical but ritual: what is said before, what is narrated during, what remains after.
03 — At home
Helping people you know
The same tools serve help and harm. Teaching somebody they can end a session is a protection they keep for life.
- 03.01Helping a Relative RemotelyProcedure
- 03.02The Remote Access Scam, DescribedExplainer
- 03.03Why It Works, and On WhomAnalysis
- 03.04The Signs, From the Victim's SideReference
- 03.05What To Do If It Already HappenedProcedure
- 03.06Talking to Someone Who Was Taken InAnalysis
- 03.07Setting Up a Family Member SafelyProcedure
- 03.08Choosing a Tool for Household UseAnalysis
04 — Support desks
Running support
The controls have to work without depending on everybody being thoughtful on every call.
- 04.01Running a Support Desk That Uses ItProcedure
- 04.02Technician Conduct and What to TrainProcedure
- 04.03Consent in a Workplace ContextAnalysis
- 04.04Access to Personal Data During SupportAnalysis
- 04.05Logging What Was DoneProcedure
- 04.06Contractors and Third-Party AccessAnalysis
- 04.07Measuring Support Quality Without SurveillanceAnalysis
05 — Security
Securing the capability
A support platform reaches every machine by design, which is the product and is what an intruder would most want.
- 05.01Exposed Remote Desktop: the Standing ProblemAnalysis
- 05.02Authentication for Remote AccessProcedure
- 05.03Unattended Access and Its RisksAnalysis
- 05.04Lateral Movement From a Support ToolAnalysis
- 05.05Vendor Access and Standing ConnectionsAnalysis
- 05.06Detecting Misuse of Your Own ToolProcedure
- 05.07Incident Response When Access Was AbusedProcedure
06 — Practice
Doing it well
The same session goes differently depending on how it is spoken, and that is entirely within the helper's control.
- 06.01Latency, Bandwidth and Why It MattersAnalysis
- 06.02Multiple Monitors, Scaling and AccessibilityProcedure
- 06.03File Transfer and What It CarriesAnalysis
- 06.04Supporting Someone Who Cannot See the ScreenProcedure
- 06.05Language, Pace and Who You Are HelpingAnalysis
- 06.06Mobile Device SupportAnalysis
- 06.07When the Connection Is the ProblemProcedure
07 — Obligations
Obligations
A session processes personal data about the user and frequently about other people, usually without anybody having said so.
Product comparisons
Tool guides for support operations
Three detailed shortlists covering remote support, time tracking and IT service management.
8 Remote Support and Desktop Access Tools for Secure Operations
Eight remote support and desktop access tools compared for session control, administration, auditability and responsible operation.
Compare 8 tools →13 Time Tracking Tools for IT Support Teams
Thirteen time tracking tools compared for tickets, projects, support coverage, corrections and transparent team adoption.
Compare 13 tools →20 IT Service Management and Workforce Operations Platforms
Twenty IT service management and workforce operations platforms compared for service delivery, endpoint work, reporting and governance.
Compare 20 tools →Session ended
What was wrong, what changed, what to watch for
Every session should end with those three in two sentences. It is the only durable record the person has, and without it they know a stranger used their computer and nothing else.