VPN & Remote Work

VPN & Remote Work · Your IT partner since 2016

Remote access built in a hurry is still holding your front door open.

Secure remote access for staff, branches and contractors: multi-factor by default, scoped to what each person actually needs, and monitored rather than forgotten.

Engineering offices in Egypt, delivering on site across Egypt and Saudi Arabia, and supporting clients remotely across the Gulf, Africa, Europe and the United States.

Most people call. It is faster, and you speak to an engineer, not a form.

What a free remote-access review looks at

What is exposed to the internetRemote desktop, management consoles and VPN endpoints reachable from anywhere in the world.

Who still has accessAccounts belonging to people who left, and contractors whose project finished last year.

Whether multi-factor is realEnforced for everyone including admins, or enabled for some and quietly skipped for others.

How much each account can reachWhether a single remote login lands on the whole network or only on what that person needs.
2016
Operating since
50+
IT specialists
40+
Projects delivered
25+
Clients
5.0
Rated on Google
What we see in the field

How remote access gets exploited

Most of what we are called in to clean up traces back to one of these. All four were reasonable decisions made quickly, and never revisited.

Remote desktop published to the internet

The fastest way to let somebody work from home in 2020, and the single most scanned-for service on the internet since. One weak password is the whole story.

Leavers who never left

Accounts still active months after the person went, often with the same password they set on day one. Nobody removes access because nobody owns the list.

Multi-factor on some accounts

Rolled out to staff but skipped for admins, service accounts and ‘temporary’ exceptions, which are exactly the accounts worth stealing.

One tunnel to everything

A VPN that drops every connected user onto the full internal network. A compromised home laptop then has the same reach as a machine sitting in your office.

What we actually build

How we build remote access

Convenient enough that people use it properly, restricted enough that one stolen password is not a company-wide incident.

1

Review of what is currently reachable

We start from the outside, because that is where an attacker starts.

  • External scan of what your public addresses actually expose
  • Remote desktop, management and legacy services identified
  • Every VPN and remote account listed with its last login
  • Multi-factor coverage checked account by account
  • Contractor and third-party access mapped and questioned
  • A prioritised list of what to close first

The review is worth doing even if you change nothing else.

2

Identity and multi-factor

Remote access security is identity security. Everything else is secondary to this.

  • Multi-factor enforced for every account, admins included
  • Single sign-on where the platforms support it
  • Conditional access by device, location and risk
  • Privileged accounts separated from everyday accounts
  • Joiner and leaver process so access ends with employment
  • Password policy that people can actually follow

See Cyber Security for the wider identity work.

3

VPN, zero-trust and segmentation

Access scoped to the job. A finance user does not need a route to the server room.

  • Site-to-site VPN between offices, branches and cloud
  • Client VPN or zero-trust access for staff and contractors
  • Access scoped per group, not one tunnel to everything
  • Split tunnelling decided deliberately, with the trade-off explained
  • Device posture checks before a connection is allowed
  • Certificates and keys managed, rotated and documented

Underlying segmentation is designed in Network Security.

4

Devices people work from

The weakest device on the connection sets the security of the connection.

  • Company laptops hardened, encrypted and patched
  • Endpoint protection managed centrally, not per machine
  • Personal devices given a defined, limited path, or none
  • Remote wipe for lost or stolen equipment
  • Screen lock, disk encryption and update policy enforced
  • A written rule for what may be done from a home PC

Most breaches we investigate start on a device nobody was managing.

5

Monitoring, review and support

Remote access drifts. New exceptions get added and none of them get removed.

  • Alerting on impossible travel and unusual sign-ins
  • Access reviewed on a schedule, with owners named
  • Logs retained long enough to investigate something
  • Support for staff who cannot connect, so they do not work around it
  • Documentation kept current as sites and people change
  • Incident response if an account is compromised

Day-to-day operation can sit inside Managed IT.

Where we have done it

Remote access we have delivered

Real Stark work. Client identifiers are withheld under confidentiality. Sector and scope only.

Multi-site enterprise

Branch and home-user access

Site-to-site links between offices plus scoped client access for staff, with multi-factor enforced across every account rather than most of them.

Fintech · 24/7

Segmented access to a regulated platform

Remote administration restricted by source, by identity and by device, monitored around the clock.

Government & defence · Egypt

Controlled access in a restricted environment

Remote paths designed where the default answer is no, and every exception is documented and time-limited.

Professional services

Contractor access with an end date

Third-party access scoped to a single system and expiring automatically, replacing accounts that used to live forever.

References can be provided directly, on request, with the client’s agreement.

How we advise

Three things we will tell you not to do

Do not publish remote desktop to the internetThere is no configuration that makes this safe enough. Put it behind VPN or a zero-trust broker with multi-factor. This single change removes the most common ransomware entry route we see.
Do not allow multi-factor exceptionsEvery exception becomes permanent, and attackers look for exactly those accounts. If an account genuinely cannot support it, restrict it by source address and review it monthly.
Do not give everyone the same tunnelOne VPN profile that reaches everything is convenient for a week and dangerous for years. Scope by group so a compromised laptop reaches a slice of the network, not all of it.
Before you call

The questions we get asked most

Is a VPN still the right answer, or should we move to zero trust?

Both are legitimate, and the honest answer depends on your size and what you run. VPN is simpler and well understood; zero-trust access scopes better and suits cloud-heavy estates. We will recommend one and explain the trade-off rather than selling the newer label.

Can staff use their own computers?

They can, and we will be clear about the risk. An unmanaged home PC has no patching, no endpoint protection and possibly a shared family login. Where personal devices must be used, we give them a limited path. Typically published applications or web access rather than a full tunnel.

How do we give a contractor access without giving them everything?

Scoped access with an end date. The account reaches the one system they were hired to work on, is logged, and expires automatically. That is normal practice for us and it takes very little longer to set up than an unrestricted account.

Someone left last month. How do we know their access is gone?

You check, and then you build the process so you do not have to. We review every account against the current staff list, then set up a leaver routine so access ends on the last day rather than whenever somebody remembers.

Will this slow people down?

Multi-factor adds seconds; a badly designed remote setup costs hours every week in workarounds. We would rather make the secure path the easy path, because access people find painful is access people route around.

Free remote-access review · no obligation

What is reachable from outside your office right now?

Most people are surprised by the answer. Ten minutes on the phone and we can tell you what to close first, whether or not you work with us.

02 3537 5791

Sunday to Thursday, 9am to 6pm · Egypt, and remote worldwide