Quick answer
Remote access that isn’t governed costs an organization twice —
once in the on-site visits it should have prevented, and again in the breach it opens
when nobody controls who can reach a machine, from where, and for how long.
- A single truck roll costs close to $1,000 once labor, travel
and lost productivity are counted, against roughly $150-$300 on the surface - Perimeter and remote access compromise — VPNs, firewalls, remote desktop —
started 58% of ransomware claims in 2024, plus another 18% via
exploited remote desktop products - The turn: most IT teams can name their ticketing tool. Few can produce, on
demand, a list of every machine someone can reach remotely right now
A technician opens a personal remote-access app to fix
one laptop. It works. Nobody asks how they got in.
Three months later the same app is still installed, on
a machine that changed owners twice.
Nobody remembers granting that access. Nobody revoked
it, because nobody knew it existed.
This is not a hypothetical. It’s the default state of
remote access at most companies: useful, invisible, and ungoverned.
The visit it saved is real. So is the door it left
open.
The remote session that never left a trace
Ad hoc remote tools solve the problem in front of the
technician: reach a machine, fix it, close the window. What they don’t solve is the
problem in front of the IT manager: who has access to what, since when, and why.
Most personal remote-access apps leave no session log an
auditor can pull later. No record of which machine was touched, what changed, or who
was on the other end. The fix happened. The evidence of the fix did not.
dispatch once travel, labor and lost productivity are includedTSIA,
cited by VSight, 2026
compromised VPN or firewallCoalition, 2025 Cyber Claims Report
fails first-contact resolution and escalates a tierScreenMeet, IT Help
Desk Benchmarks, 2026
Why an ad hoc tool passes every daily check and fails
every audit
Day to day, an unmanaged remote-access app looks
identical to a governed one. The technician connects, the user’s screen shares, the
problem gets fixed. The difference only shows up when someone has to answer for it.
| Question an auditor asks | Personal remote app | Governed remote access |
|---|---|---|
| Who connected, and when | Not recorded | Logged per session, per user |
| What was that person allowed to do | Full control, no limit | Scoped to the task |
| Which machines currently have an open door | Unknown | Listed and current |
| Can access be revoked centrally | Only by finding the install | One action, applies everywhere |
What stays invisible when remote access isn’t governed
No session record
Without a central log, a session that never happened
and a session that fixed a real problem look exactly the same after the fact —
because there’s nothing to look at.
No scoped permissions
Most personal remote tools grant full control by
default. There’s no version of “just enough access to reset a password” — it’s all
or nothing, every time.
No inventory of open doors
Every ad hoc install is a standing entry point that
outlives the ticket that justified it. Nobody’s job is to go back and close it.
An auditor doesn’t ask whether remote access is useful. They ask who could reach
which machine on a given date. “We don’t log that” is not an answer that survives an
ISO 27001 review or a breach investigation — it’s the finding.
The tool that saved the site visit is the same tool nobody can
account for later.
It isn’t a people problem, it’s a visibility problem
Technicians reach for whatever gets the machine fixed
fastest. That’s not negligence — it’s the job working as designed, with no governed
alternative in front of them.
The gap isn’t discipline. It’s that IT has no single
place to see, grant, and revoke remote access across every endpoint it’s responsible
for.
How to close the gap, in five steps
- Inventory every open door.List every remote-access tool
currently installed across endpoints, not just the one IT sanctioned. - Move to one governed channel.Standardize on a remote-access
platform that logs sessions by default, with no opt-out. - Scope permissions to the task.Grant control for the duration
of the fix, not a standing key to the machine. - Revoke on offboarding, same day.Access tied to a person who
left the company is the easiest breach to prevent and the most common to miss. - Review the access list monthly.An inventory that’s accurate
once a year is a snapshot of the past, not a control.
Session logging only helps if it captures who connected, from what device and IP,
and what was changed — not just that a connection happened. A log with a timestamp
and nothing else answers “was someone in” but not “what did they do,” which is the
question that actually matters in an incident.
How INGITE helps
Cloud Remote Access
Reach any managed endpoint from anywhere, with every session logged, scoped
and revocable from one console — no personal app installed on company
machines.
Cloud EndPoint Security
Enforce which tools are allowed to run on an endpoint in the first place, so
an unsanctioned remote app never gets the chance to become a standing entry
point.
How many machines can be reached right now, and by
whom?
Answer honestly, not from memory.
- Could you produce a list, today, of every remote-access tool installed across
your endpoints? - If a former employee’s laptop still had one installed, would anyone notice
before it mattered? - Can you show an auditor who connected to a specific machine on a specific
date?
If the honest answer is no to any of these, the risk
isn’t the next site visit. It’s the one that already happened and left no record.
What is governed remote access?
that logs every session, limits what the connecting user can do, and lets IT
revoke access centrally — as opposed to ad hoc personal apps installed
machine by machine with no oversight.
Why is remote access such a common ransomware entry
point?
the network, which is exactly what an attacker also wants. When that access
isn’t scoped, logged or centrally managed, a single compromised credential or
misconfigured tool opens the same door to an attacker that it opens to IT.
Coalition’s 2025 Cyber Claims Report found compromised VPNs and firewalls
behind 58% of 2024 ransomware claims.
How much does an unnecessary on-site visit actually cost?
labor, travel time, vehicle costs and lost productivity are included, well
above the $150-$300 that shows up on a simple mileage-and-hours calculation.
Can remote access tools be audited after the fact?
apps don’t keep a record an auditor can pull later, which means access used
months ago is effectively unaccountable — there’s nothing left to review.
Know who’s inside every machine, every time
Cloud Remote Access replaces the personal app nobody can audit with a governed
channel IT actually controls.