Although remote maintenance is essential for ensuring organisational efficiency, it comes with cybersecurity risks related to remote access. These risks can be mitigated or even eliminated with the right IT solutions. Various tools are commonly used for remote maintenance, including remote control software, VPNs, ZTNA (Zero Trust Network Access) and PAM (Privileged Access Management). But not all of these offer the same level of cybersecurity.
A performance challenge and a cyber risk
Remote maintenance is designed to resolve IT issues or carry out operations by remotely accessing a system or network. It enhances responsiveness and convenience, ensuring seamless business continuity. It covers two things.
- Helpdesk, for solving isolated problems on a device.
- Remote administration, where a service provider intervenes on a customer’s systems for administration purposes.
This second scenario poses the greatest security risks to the information system. When a service provider remotely controls a system, several challenges must be addressed.
- Access and activity traceability, allowing organisations to trace the source of any issues that arise.
- Authentication, which verifies a user’s identity before granting access to resources, and which must be strengthened to prevent identity theft attempts.
- Limiting any possibility of lateral movement within the IT system.
To avoid: remote desktop solutions
While remote control software is well suited to internal helpdesk tasks — the organisation’s own IT department and employees — it lacks the security features needed for remote access by service providers performing system maintenance.
Agent-based solutions
An agent must be installed to enable external access. That agent can be detected by tools that scan for open ports, making it a potential entry point for hackers.
Unrestricted access for service providers
A service provider accessing a device remotely is granted full access rights. Their permissions should instead be restricted based on their specific role, to minimise security risks and prevent lateral movement.
Lack of strong authentication
Remote desktop solutions do not offer enhanced authentication to strengthen security. Traceability is also limited to basic log records stored only on the workstation itself, which provides insufficient oversight.
To avoid: VPN
VPNs, commonly used by organisations to grant remote access to service providers, do not fully meet all security requirements. VPNs were originally designed to connect two trusted networks within the same organisation.
An untrusted network
From the organisation’s perspective, the service provider cannot be considered fully trustworthy, as there is no control over their network.
The principle of least privilege
VPNs do not support the implementation of the principle of least privilege, a critical requirement for securing IT systems.
An agent-based solution
Like remote control software, VPNs require agent installation, and those agents must be regularly updated to patch vulnerabilities. Since it typically takes a month on average for a vendor to release a patch and another month for an organisation to deploy it across all agents, the system remains exposed for a long period.
Recommended: ZTNA (Zero Trust Network Access)
For remote maintenance by external service providers, ZTNA (Zero Trust Network Access) is the recommended solution, as its security features are specifically designed for remote access from untrusted devices. CyberElements, as a Zero Trust secure remote access solution, provides the following.
Agentless access and the least privilege principle
CyberElements restricts external service providers’ rights and permissions to the necessary applications.
The accessed resources are hidden from the internet. The connection to the resource is made through an internal gateway, so the resource is not exposed: it is isolated from the internet while still reachable via the ZTNA solution. Access to resources is granted only when needed and used, through temporary and random ports.
Advanced traceability
CyberElements provides detailed traceability, so you know who connected to what.
Device posture check
By defining your own security measures, the integrity of each device is checked before access to applications and systems is granted.
Strong authentication
CyberElements allows strong authentication, supporting a range of solutions, and offers single sign-on (SSO) for backend resources.
| VPN | ZTNA | |
|---|---|---|
| Perimeter | Organisation’s network | User’s context |
| Access level | Network | Application |
| End user terminal software | Mandatory client | Clientless possible |
| Access control granularity | Devices–network services | Identities–applications |
| Mobility and cloud | 1:1 connection | Anywhere/anything |
| Resource location | 1 site / VPN | Multi-sites, multi-VLANs |
| User experience | Poor | Best (1 portal, SSO, …) |
| Computing resources and scalability | Heavy and costly | Light, cost-effective |
| Security | Client software update, limited traceability | No software update if clientless, full traceability |
| Architecture | Single barrier, IT system exposure | Double barrier, IT system unexposed |
Recommended: Zero Trust remote PAM (RPAM)
PAM solutions provide full control and monitoring capabilities, real-time analysis, and access activity logs — allowing the organisation to track who connected to what, and for what purpose.
CyberElements, the Zero Trust remote Privileged Access Management solution, allows:
- Session recording in a video format.
- Content analysis, to retrieve the context and the changes made.
- Secure access to resources by strengthening authentication and automatically injecting passwords into privileged accounts.
- Continuous authentication, to verify a user’s identity in real time.
By applying Zero Trust principles, CyberElements enables organisations to implement the principle of least privilege, based on the assumption that all users and privileged endpoints are potential security threats. It is designed to secure privileged access, particularly that of external service providers.
| Features | VPN tool | Remote support tools | On-demand / dynamic access tool | Classical session management PAM | Zero Trust RPAM tools |
|---|---|---|---|---|---|
| Identity management | None | Limited | Partial | Partial | Substantial |
| Authentication, MFA and SSO | Partial | Partial | Partial | Substantial | Full |
| Access policy management | Limited | None | Substantial | Substantial | Full |
| Detailed audit trail and session recording | Partial | Limited | Substantial | Substantial | Full |
| Zero Trust policy enforcement | Limited | None | Full | Partial | Full |
| Remote access | Substantial | Substantial | Partial | Limited | Full |
Tags
- Articles
- ZTNA
- PAM
- MSPs
- Secure Remote Access
- Third-Party & Vendor Access
Check other relevant resources

Meurthe-et-Moselle Departmental Council
Delivering a seamless remote working experience for employees.

Hautes-Alpes Departmental Fire and Rescue Service
Securing and simplifying volunteer firefighters’ access to operational applications.

Bièvre Isère Regional Authority
Bièvre Isère authority chose cyberelements to streamline employee integration and enable staff to be fully operational on their first day.
View All
