Remote access built in a hurry is still holding your front door open.
Secure remote access for staff, branches and contractors: multi-factor by default, scoped to what each person actually needs, and monitored rather than forgotten.
Engineering offices in Egypt, delivering on site across Egypt and Saudi Arabia, and supporting clients remotely across the Gulf, Africa, Europe and the United States.
Most people call. It is faster, and you speak to an engineer, not a form.
What a free remote-access review looks at
How remote access gets exploited
Most of what we are called in to clean up traces back to one of these. All four were reasonable decisions made quickly, and never revisited.
Remote desktop published to the internet
The fastest way to let somebody work from home in 2020, and the single most scanned-for service on the internet since. One weak password is the whole story.
Leavers who never left
Accounts still active months after the person went, often with the same password they set on day one. Nobody removes access because nobody owns the list.
Multi-factor on some accounts
Rolled out to staff but skipped for admins, service accounts and ‘temporary’ exceptions, which are exactly the accounts worth stealing.
One tunnel to everything
A VPN that drops every connected user onto the full internal network. A compromised home laptop then has the same reach as a machine sitting in your office.
How we build remote access
Convenient enough that people use it properly, restricted enough that one stolen password is not a company-wide incident.
Review of what is currently reachable
We start from the outside, because that is where an attacker starts.
- External scan of what your public addresses actually expose
- Remote desktop, management and legacy services identified
- Every VPN and remote account listed with its last login
- Multi-factor coverage checked account by account
- Contractor and third-party access mapped and questioned
- A prioritised list of what to close first
The review is worth doing even if you change nothing else.
Identity and multi-factor
Remote access security is identity security. Everything else is secondary to this.
- Multi-factor enforced for every account, admins included
- Single sign-on where the platforms support it
- Conditional access by device, location and risk
- Privileged accounts separated from everyday accounts
- Joiner and leaver process so access ends with employment
- Password policy that people can actually follow
See Cyber Security for the wider identity work.
VPN, zero-trust and segmentation
Access scoped to the job. A finance user does not need a route to the server room.
- Site-to-site VPN between offices, branches and cloud
- Client VPN or zero-trust access for staff and contractors
- Access scoped per group, not one tunnel to everything
- Split tunnelling decided deliberately, with the trade-off explained
- Device posture checks before a connection is allowed
- Certificates and keys managed, rotated and documented
Underlying segmentation is designed in Network Security.
Devices people work from
The weakest device on the connection sets the security of the connection.
- Company laptops hardened, encrypted and patched
- Endpoint protection managed centrally, not per machine
- Personal devices given a defined, limited path, or none
- Remote wipe for lost or stolen equipment
- Screen lock, disk encryption and update policy enforced
- A written rule for what may be done from a home PC
Most breaches we investigate start on a device nobody was managing.
Monitoring, review and support
Remote access drifts. New exceptions get added and none of them get removed.
- Alerting on impossible travel and unusual sign-ins
- Access reviewed on a schedule, with owners named
- Logs retained long enough to investigate something
- Support for staff who cannot connect, so they do not work around it
- Documentation kept current as sites and people change
- Incident response if an account is compromised
Day-to-day operation can sit inside Managed IT.
Remote access we have delivered
Real Stark work. Client identifiers are withheld under confidentiality. Sector and scope only.
Branch and home-user access
Site-to-site links between offices plus scoped client access for staff, with multi-factor enforced across every account rather than most of them.
Segmented access to a regulated platform
Remote administration restricted by source, by identity and by device, monitored around the clock.
Controlled access in a restricted environment
Remote paths designed where the default answer is no, and every exception is documented and time-limited.
Contractor access with an end date
Third-party access scoped to a single system and expiring automatically, replacing accounts that used to live forever.
References can be provided directly, on request, with the client’s agreement.
Three things we will tell you not to do
The questions we get asked most
Is a VPN still the right answer, or should we move to zero trust?
Both are legitimate, and the honest answer depends on your size and what you run. VPN is simpler and well understood; zero-trust access scopes better and suits cloud-heavy estates. We will recommend one and explain the trade-off rather than selling the newer label.
Can staff use their own computers?
They can, and we will be clear about the risk. An unmanaged home PC has no patching, no endpoint protection and possibly a shared family login. Where personal devices must be used, we give them a limited path. Typically published applications or web access rather than a full tunnel.
How do we give a contractor access without giving them everything?
Scoped access with an end date. The account reaches the one system they were hired to work on, is logged, and expires automatically. That is normal practice for us and it takes very little longer to set up than an unrestricted account.
Someone left last month. How do we know their access is gone?
You check, and then you build the process so you do not have to. We review every account against the current staff list, then set up a leaver routine so access ends on the last day rather than whenever somebody remembers.
Will this slow people down?
Multi-factor adds seconds; a badly designed remote setup costs hours every week in workarounds. We would rather make the secure path the easy path, because access people find painful is access people route around.
What is reachable from outside your office right now?
Most people are surprised by the answer. Ten minutes on the phone and we can tell you what to close first, whether or not you work with us.
Sunday to Thursday, 9am to 6pm · Egypt, and remote worldwide
Our other IT services
Every service below is delivered by the same team, under the same agreement.
