MiBOT SupportMiBOT Support
7 min read

Is Your Remote Access Setup Quietly Putting You at Risk?

By Herman du PlessisTechnically reviewed by Herman du Plessis

If your team logs in from home, client sites or a Mugg & Bean, remote access is now core infrastructure — and most SA businesses have never audited it. The safest setup combines multi-factor authentication on every account, a modern VPN or Zero Trust access tool, endpoint protection on every device, and a documented list of who has access to what. Set it up once, review it every quarter.

Why is remote access suddenly a security problem?

Before 2020, most SMBs had one office, one firewall, and staff who logged in from their desks. Remote access was a bolt-on — usually a cheap VPN the IT guy configured once and never touched again.

Then everything changed. Sales reps work from client sites. Bookkeepers do month-end from home. Directors check email from Dubai. Loadshedding sends the whole team scattering to coffee shops with dodgy Wi-Fi. And the old remote access setup? Still running. Still using the same shared password from 2019. Still with no idea who's actually connected.

That's the quiet risk. It's not that anyone made a bad decision — it's that nobody made a decision at all. The setup just drifted.

What's the feeling most business owners describe?

When we audit a new client's remote access, the response is almost always the same: "I honestly haven't thought about this in years." Then, once they see the list of dormant accounts, shared credentials and personal laptops connecting to the server — a slow, sinking discomfort. Because if a staff member's home laptop gets compromised, that's a direct route into the business. And they'd have no idea it happened.

That's the gap this article closes.

Key facts about securing remote access

  • Every remote access account should have multi-factor authentication (MFA) — password alone is not enough in 2026.
  • Personal devices connecting to business systems should meet minimum security standards or be blocked.
  • Ex-staff accounts are one of the most common ways businesses get breached — offboarding matters.
  • Under POPIA, if a breach occurs via a compromised remote account, the responsible party must notify the Information Regulator and affected data subjects as soon as reasonably possible after there are reasonable grounds to believe a compromise happened (see the Information Regulator).

What should a modern remote access setup actually include?

Forget the jargon for a moment. A properly secured remote access setup does four jobs:

1. Verifies who you are — twice. Password plus a second factor (an app on your phone, a hardware key, a biometric). If an attacker steals a password through phishing, MFA is what stops them walking straight in.

2. Verifies the device is safe. A staff laptop with up-to-date patches, active endpoint protection and disk encryption is a very different risk from a personal desktop the kids also use for gaming. Your setup should know the difference.

3. Gives access only to what's needed. The receptionist doesn't need access to the financial share. The bookkeeper doesn't need access to HR files. This is called "least privilege" and it's the single biggest limiter of damage when something goes wrong.

4. Logs everything. Who connected, from where, when, and what they touched. Not to spy on staff — to have answers when something looks off.

Most SA businesses have zero, one or maybe two of these four. The gap is usually device verification and access scoping.

VPN or Zero Trust — which fits an SMB?

This is where buyers get confused, so here's the plain-English version:

ApproachHow it worksBest for
Traditional VPNStaff connect to a "tunnel" into the office network, then access everything as if they were on-siteSmall teams with an on-premise server they need to reach
Cloud VPN (e.g. built into your firewall or Microsoft 365)Same idea, but managed centrally and easier to enforce MFAMost SA SMBs with a mix of on-prem and cloud
Zero Trust accessEvery request is verified individually — user, device, and app — instead of trusting the whole networkBusinesses that are mostly cloud already and want tighter control

For a professional-services firm with 10-80 staff, a well-configured cloud VPN with MFA and device checks is usually the sweet spot. Zero Trust is where you're heading, not necessarily where you start.

What can you actually do this week?

You don't need to boil the ocean. Start here:

  • Pull the list of everyone who has remote access. Compare it to your current staff list. Every mismatch is a live account for someone who no longer works there. Disable immediately.
  • Turn on MFA for every remote account. Not "most". Every. The one exception is always the account that gets breached.
  • Ask staff what device they're using. Personal laptops running Windows 10 with expired antivirus need addressing. So does the shared home desktop.
  • Check who has access to what. If your file server or SharePoint has "Everyone — Full Control" anywhere, fix it.
  • Document the setup. One page. What tool, who has access, how it's configured. If your IT provider can't produce this, that's a red flag on its own.

Good cyber security services will do this as part of onboarding — and it should be reviewed quarterly, not once.

What happens if you leave it as-is?

Two futures. In the good one, staff connect from wherever, work productively, and you sleep because you know the setup is tight, monitored and documented. Client tender questionnaires about remote working security get answered in a morning, not a panicked week.

In the bad one, a phishing email catches a staff member on a Tuesday afternoon. Their password is stolen. Because there's no MFA, the attacker logs into your systems that evening. By Friday, they've mapped your network, found the backup share, and either encrypted everything or quietly exfiltrated client data. Then comes the POPIA notification, the awkward client calls, and the tender you were about to win — gone.

We've seen both. The gap between them is usually a weekend of proper setup.

Frequently asked questions

Is a free VPN enough for business use?

No. Consumer VPNs (the ones advertised on YouTube) are designed to hide your browsing from your ISP, not to secure business access to company systems. They don't offer central management, MFA enforcement, device checks or logging. Use a business-grade solution.

What about staff using their personal laptops?

It's common in SA SMBs, and it's manageable — but only if those devices meet minimum standards: current OS, active endpoint protection, disk encryption, and a screen lock. If you can't verify that, the safer path is a company-issued device or a locked-down virtual desktop.

How often should we review remote access?

Quarterly at minimum. Staff change, roles change, and dormant accounts pile up faster than anyone expects. A quick 30-minute review with your IT provider catches almost everything.

Does this apply if we're fully on Microsoft 365?

Yes — even more so. Your Microsoft 365 tenant IS your business now. Proper conditional access, MFA and device policies within Microsoft 365 management matter more than any VPN. And with proactive monitoring in place, unusual sign-ins get flagged before they become breaches.

If remote access has been sitting on the "I'll get to it" list, that's the sign it's time. A short audit will tell you exactly where you stand — and the MiBOT Support team is happy to walk through it with you when you're ready to book a free consultation.

Last reviewed: August 2026

Ready to Experience IT That Actually Works?

Let us take care of your technology so you can focus on growing your business.

  • 25+ years supporting SA businesses
  • Under 1-hour response
  • ISO/IEC 27001:2022 certified
Book a callCall