Processing...

 Remote Access - Who do you trust

The Curious Codex

             0 Votes  
100% Human Generated
2026-07-30 Published, 2026-07-30 Updated
677 Words, 4  Minute Read

The Author
GEN Blog

Matt (Virtualisation)

Matt has been with the firm since 2015.

 

Remote access software sits in an awkward category: essential for IT support, managed services, home working, and server administration, but also one of the fastest ways to hand an attacker the keys if it is deployed carelessly. In 2026 the market is crowded with well-known names, newer challengers, open-source options, and specialist enterprise platforms, all promising convenience, performance, and security. The problem for buyers is that the sales pitch is usually much simpler than the real risk profile.

The biggest concern is unattended access. Once a device is configured so that somebody can connect without a person on the other end explicitly approving each session, that tool becomes part of your permanent attack surface. If credentials are stolen, a vendor environment is compromised, a vulnerability is exposed, or security settings are left weak, unattended remote access can turn a routine support product into a direct path to sensitive systems. For consumers this may mean personal files, banking sessions, or saved passwords. For businesses it can mean domain compromise, ransomware deployment, data theft, and an incident response exercise that costs far more than the software licence ever did.

That does not mean remote access tools are inherently unsafe. It means they should be treated with the same seriousness as VPNs, identity platforms, and endpoint protection. Buyers should be asking how access is authenticated, whether MFA is enforced, what logging is available, how quickly vendors respond to security issues, whether the product can be self-hosted or segmented, and what the company's real-world security track record looks like when things go wrong.

Tool Company Origin / Ownership Base Breach History
AnyDesk AnyDesk Software GmbH Germany Yes — 2024 production-system compromise.
Splashtop Splashtop Inc. United States No publicly verified vendor breach found.
TeamViewer TeamViewer SE Germany Yes — 2024 internal corporate IT compromise.
LogMeIn / GoTo Resolve GoTo Technologies United States Yes — 2022 unauthorised access to development systems and some customer data.
ConnectWise ScreenConnect ConnectWise United States Yes — Reported vendor compromise; critical product flaws exploited in the wild.
BeyondTrust Remote Support BeyondTrust United States Yes — 2024 incident affected certain SaaS customers; later active exploitation of product flaws.
Zoho Assist Zoho Corporation India Partial — Exploited ManageEngine vulnerabilities at parent/product-family level; no confirmed Zoho Assist-specific breach.
RealVNC RealVNC Ltd United Kingdom No publicly verified vendor breach found.
RemotePC IDrive Inc. United States No publicly verified vendor breach found.
RustDesk RustDesk China-origin, distributed operations No publicly verified vendor breach found.

The table below is not a league table of winners and losers, and it should not be read that way. A previous breach does not automatically make a product untrustworthy, just as a clean public record does not prove a vendor is risk-free. What it does show is that remote access providers operate in a high-value, high-pressure environment where security failures, development system compromises, exploited vulnerabilities, and third-party knock-on effects are all realistic concerns. Buyers who only compare price or ease of use are ignoring the factor that matters most once a remote support tool is embedded in daily operations.

Some names on the list remain broadly reputable and, at the time of writing, do not have a publicly verified vendor breach attached to them in the same way as others in the table. Splashtop, RealVNC, and RemotePC stand out on that narrow measure, while RustDesk appeals to organisations that prefer open-source transparency and greater hosting control, albeit with a different trust and operational model. That should not be mistaken for a blanket endorsement. Procurement decisions should still include architecture review, regulatory fit, support quality, default security posture, and whether the vendor's ownership base and operating model align with your own risk appetite.

The fixed-point-in-time nature of this article matters. A vendor that looks clean today may disclose an incident tomorrow; a vendor with a previous breach may now have a much stronger security posture than less-tested competitors. The sensible conclusion is not to pick a brand on familiarity alone, but to choose deliberately: do your research, enable MFA, restrict unattended access to genuine business need, review logs regularly, and assume that convenience without security controls is a liability waiting to mature.


             0 Votes  
100% Human Generated

×

--- This content is not legal or financial advice & Solely the opinions of the author ---

Contact Us