Remote Access and Homeoffice Extent
Remote access and homeoffice extent records how many employees connect to corporate systems remotely, through which technical channel, and under what security controls, a significant driver of the attack surface in cyber underwriting.
- Category
- IT/Cyber
- Data type
- Enumeration
- Risk drivers
- Severity, Frequency
- Underwriting impact
- Premium, Condition/Warranty, Exclusion
Typical proposal-form questions
- What proportion of employees regularly access corporate systems remotely, and through which technical means (VPN, RDP, virtual desktop, direct cloud access)?
- Is remote desktop protocol (RDP) exposed directly to the internet, and if so, is it protected by multi-factor authentication and a gateway or VPN?
- Are personal devices permitted to access corporate systems (BYOD), and what device security requirements apply?
Evidence
- Remote access policy
- Network diagram showing remote access gateways and exposure
- VPN or remote access system configuration export
Why it matters for underwriting
The shift toward widespread remote and hybrid working has expanded the attack surface of most organisations substantially, since every remotely accessible endpoint and gateway is a potential entry point that did not exist, or existed only for a small subset of staff, before that shift. Directly internet-exposed remote desktop protocol in particular is one of the most heavily scanned and exploited entry points for ransomware actors, who routinely brute-force or credential-stuff exposed RDP endpoints to gain an initial foothold. Underwriters use the extent and technical configuration of remote access, not merely the fact that remote work occurs, to assess both the size of the exposed surface and the quality of the controls protecting it, since a large remote workforce behind a well-secured gateway can present less risk than a small one with an unprotected direct connection.
Capturing the attribute and evidence
Proposal forms ask what proportion of staff work remotely on a regular basis, which technical channel is used to connect, such as a VPN, remote desktop gateway, virtual desktop infrastructure or direct cloud application access, and specifically whether RDP is exposed directly to the internet without an intermediary gateway. Underwriters request the organisation’s remote access policy, a network diagram identifying all remote access gateways and any direct internet exposure, and a configuration export from the VPN or remote access system confirming which authentication and access controls actually apply. Use of personal devices to access corporate systems is queried separately, since bring-your-own-device arrangements introduce endpoints outside the organisation’s direct security management and typically require distinct compensating controls.
Effect on coverage, premium and conditions
Remote access channelled exclusively through a well-configured VPN or gateway with multi-factor authentication and no direct internet exposure of RDP supports standard terms and pricing. Direct internet exposure of RDP or other remote administration protocols without compensating controls is one of the most common single triggers for a specific warranty, premium loading, or an outright exclusion of losses traceable to that exposed service, and in severe cases can lead to declinature. Unmanaged or unrestricted bring-your-own-device access, particularly to systems holding sensitive data, commonly results in a condition requiring device management controls or a sublimit on losses originating from personal devices.
Mitigation measures
Closing direct internet exposure of remote desktop protocol and routing all remote access through a VPN or a dedicated, monitored remote access gateway protected by multi-factor authentication is the primary recommendation. Segmenting remote access so that connecting devices reach only the specific systems required rather than the full internal network limits lateral movement should a remote endpoint be compromised. For personal devices permitted under bring-your-own-device policies, mobile device management enforcing encryption, minimum security patch levels and remote wipe capability is recommended as a compensating control where full device standardisation is not feasible.