
Remote work is normal. Exposing Remote Desktop (RDP) straight to the internet is not. A VPN—or a modern zero-trust remote access design—creates an encrypted path so staff can reach files and apps without advertising open ports to the whole world.
Hard rules for remote access
- Do not publish RDP (port 3389) or random remote tools directly on the public internet
- Require MFA on VPN and any remote access portal
- Keep VPN software and firewall firmware patched—VPN appliances are frequent attack targets
- Use unique accounts per person; no shared “remote” logins
- Disable access the day someone leaves the company
Home office basics for staff
- Prefer company-managed laptops when possible
- Avoid public Wi‑Fi for finance work without VPN
- Lock the screen when stepping away
- Store work files in approved cloud or server locations—not only the Downloads folder
CISA has published guidance on securing remote access and VPNs for organizations: CISA cybersecurity resources (start from their remote work / VPN advisories). For hands-on help, see remote support.
Need help putting this into practice for your business? Contact SabatAge or call (845) 475-8468. We support Hudson Valley and Orange County businesses with practical security and managed IT.

No responses yet