CIO Brief: Exposed Remote Access Is Still the Front Door for Ransomware
Retrospective: this article looks back at events from May 2019, written in 2026 with the benefit of hindsight.
The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop connections without a password. The bigger lesson: remote access left open to the internet remains one of the top ways ransomware gets in.
Why exposed remote access is so dangerous
Remote desktop and similar tools let administrators manage servers from anywhere. When they are reachable from the whole internet, attackers can try stolen passwords, guess weak ones, or exploit vulnerabilities — automatically, around the clock.
The business impact
- Ransomware entry point: exposed remote access is consistently among the most common initial access methods reported by incident responders.
- Cloud servers are not exempt: cloud virtual machines are often exposed for convenience.
Questions to ask your team
- Do any of our servers, in the office or the cloud, accept remote desktop connections from the internet?
- How do administrators connect to servers today?
- Is multi-factor authentication required for all remote access, including VPNs?
- Are any servers still running unsupported operating systems?
What good looks like
No management ports open to the internet. Administrators connect through secured gateways that require strong authentication. Unsupported systems are retired or isolated.
The decision
Ask for a report of every system with remote access exposed to the internet. The goal is zero; any exceptions should have an owner and a date to fix.
- BlueKeep (May 2019): Wormable RDP and the Risk of Internet-Exposed Azure VMs Incident Teardowns
- How to Replace Public RDP With Azure Bastion and Just-in-Time Access How-To & Hardening
- Detecting Exposed RDP Exploitation: Defender for Cloud and Sentinel KQL Detection & Response