Exposed Remote Desktop: the Standing Problem
Remote desktop reachable from the open internet remains one of the most reliable routes into organisations. Why it persists.
A remote desktop service listening on the public internet is attacked continuously and compromised routinely. It is also still there in a great many organisations.
The support work behind “Exposed Remote Desktop: the Standing Problem” is often spread across tickets, projects and handoffs. Teams researching employee monitoring software with screenshots can use learn more here to connect time and project context with that work, while the remote-support platform remains the source of truth for technical actions and session access.
Why it is there
Somebody needed access from home, quickly, and it worked.
For an independent reference related to “Exposed Remote Desktop: the Standing Problem”, consult the CISA cyber-threat guidance; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.
A vendor asked for it.
A temporary arrangement during an incident became permanent.
Or it was never deliberately exposed: a firewall rule, a forwarded port on a router, a cloud instance with a default configuration.
Almost none of it was a considered decision, which is why finding it requires looking rather than asking.
Why it is attacked
It is a login prompt reachable by anybody, guarding something valuable.
Automated scanning finds it within hours of exposure.
Credential guessing runs continuously and costs the attacker nothing.
And a successful login is full interactive access to a machine inside the network, which is the most useful possible outcome for an intruder.
Finding yours
Scan your own external addresses for the standard ports.
Check cloud instances, which frequently expose management access by default.
Check home-working arrangements set up in a hurry.
And ask vendors whether anything they installed listens externally, which they will answer if asked and not otherwise.
What to do instead
A gateway or broker that authenticates before the desktop service is reachable.
A virtual private network, with strong authentication.
Or a zero-trust style access service that mediates the connection.
All three mean the desktop service is not reachable until the person is already authenticated, which is the whole of the difference.
Where exposure is unavoidable
Restrict by source address.
Enforce multi-factor at the gateway.
Rate-limit and lock out.
Log and alert on failures and on successes from unusual places.
And review whether it is still needed, which is the control most likely to actually remove it.
The home-user version
Consumer routers forwarding ports to a desktop, usually set up for remote access to a home computer or a games server.
Same exposure, less monitoring, and the machine frequently has no separate administrator account.
Worth checking on a family member's router, which takes a minute and is rarely done.
Why it persists despite being well known
It works, removing it breaks somebody's arrangement, and nobody owns the external surface.
Which means finding it is an exercise somebody has to be assigned, rather than something that happens.
What to check
Have you scanned your own external addresses this year?
Does any cloud instance expose management access?
Is anything reachable without authenticating at a gateway first?
And does a family member's router forward anything?