CyberElements
Back

Remote maintenance: Which tools should you choose?

CyberElements,

Share via

Although remote maintenance is essential for ensuring organisational efficiency, it comes with cybersecurity risks related to remote access. These risks can be mitigated or even eliminated with the right IT solutions. Various tools are commonly used for remote maintenance, including remote control software, VPNs, ZTNA (Zero Trust Network Access) and PAM (Privileged Access Management). But not all of these offer the same level of cybersecurity.

A performance challenge and a cyber risk

Remote maintenance is designed to resolve IT issues or carry out operations by remotely accessing a system or network. It enhances responsiveness and convenience, ensuring seamless business continuity. It covers two things.

  • Helpdesk, for solving isolated problems on a device.
  • Remote administration, where a service provider intervenes on a customer’s systems for administration purposes.

This second scenario poses the greatest security risks to the information system. When a service provider remotely controls a system, several challenges must be addressed.

  • Access and activity traceability, allowing organisations to trace the source of any issues that arise.
  • Authentication, which verifies a user’s identity before granting access to resources, and which must be strengthened to prevent identity theft attempts.
  • Limiting any possibility of lateral movement within the IT system.

To avoid: remote desktop solutions

While remote control software is well suited to internal helpdesk tasks — the organisation’s own IT department and employees — it lacks the security features needed for remote access by service providers performing system maintenance.

Agent-based solutions

An agent must be installed to enable external access. That agent can be detected by tools that scan for open ports, making it a potential entry point for hackers.

Unrestricted access for service providers

A service provider accessing a device remotely is granted full access rights. Their permissions should instead be restricted based on their specific role, to minimise security risks and prevent lateral movement.

Lack of strong authentication

Remote desktop solutions do not offer enhanced authentication to strengthen security. Traceability is also limited to basic log records stored only on the workstation itself, which provides insufficient oversight.

To avoid: VPN

VPNs, commonly used by organisations to grant remote access to service providers, do not fully meet all security requirements. VPNs were originally designed to connect two trusted networks within the same organisation.

An untrusted network

From the organisation’s perspective, the service provider cannot be considered fully trustworthy, as there is no control over their network.

The principle of least privilege

VPNs do not support the implementation of the principle of least privilege, a critical requirement for securing IT systems.

An agent-based solution

Like remote control software, VPNs require agent installation, and those agents must be regularly updated to patch vulnerabilities. Since it typically takes a month on average for a vendor to release a patch and another month for an organisation to deploy it across all agents, the system remains exposed for a long period.

Recommended: ZTNA (Zero Trust Network Access)

For remote maintenance by external service providers, ZTNA (Zero Trust Network Access) is the recommended solution, as its security features are specifically designed for remote access from untrusted devices. CyberElements, as a Zero Trust secure remote access solution, provides the following.

Agentless access and the least privilege principle

CyberElements restricts external service providers’ rights and permissions to the necessary applications.

The accessed resources are hidden from the internet. The connection to the resource is made through an internal gateway, so the resource is not exposed: it is isolated from the internet while still reachable via the ZTNA solution. Access to resources is granted only when needed and used, through temporary and random ports.

Advanced traceability

CyberElements provides detailed traceability, so you know who connected to what.

Device posture check

By defining your own security measures, the integrity of each device is checked before access to applications and systems is granted.

Strong authentication

CyberElements allows strong authentication, supporting a range of solutions, and offers single sign-on (SSO) for backend resources.

VPNZTNA
PerimeterOrganisation’s networkUser’s context
Access levelNetworkApplication
End user terminal softwareMandatory clientClientless possible
Access control granularityDevices–network servicesIdentities–applications
Mobility and cloud1:1 connectionAnywhere/anything
Resource location1 site / VPNMulti-sites, multi-VLANs
User experiencePoorBest (1 portal, SSO, …)
Computing resources and scalabilityHeavy and costlyLight, cost-effective
SecurityClient software update, limited traceabilityNo software update if clientless, full traceability
ArchitectureSingle barrier, IT system exposureDouble barrier, IT system unexposed

Recommended: Zero Trust remote PAM (RPAM)

PAM solutions provide full control and monitoring capabilities, real-time analysis, and access activity logs — allowing the organisation to track who connected to what, and for what purpose.

CyberElements, the Zero Trust remote Privileged Access Management solution, allows:

  • Session recording in a video format.
  • Content analysis, to retrieve the context and the changes made.
  • Secure access to resources by strengthening authentication and automatically injecting passwords into privileged accounts.
  • Continuous authentication, to verify a user’s identity in real time.

By applying Zero Trust principles, CyberElements enables organisations to implement the principle of least privilege, based on the assumption that all users and privileged endpoints are potential security threats. It is designed to secure privileged access, particularly that of external service providers.

FeaturesVPN toolRemote support toolsOn-demand / dynamic access toolClassical session management PAMZero Trust RPAM tools
Identity managementNoneLimitedPartialPartialSubstantial
Authentication, MFA and SSOPartialPartialPartialSubstantialFull
Access policy managementLimitedNoneSubstantialSubstantialFull
Detailed audit trail and session recordingPartialLimitedSubstantialSubstantialFull
Zero Trust policy enforcementLimitedNoneFullPartialFull
Remote accessSubstantialSubstantialPartialLimitedFull

Tags

  • Articles
  • ZTNA
  • PAM
  • MSPs
  • Secure Remote Access
  • Third-Party & Vendor Access

Let’s secure your access together