Ports
RDP on the public internet: the single biggest ransomware vector for UK small businesses.
Published 2026-04-09 · Last updated 2026-04-09 · Vantyris editorial
Remote Desktop Protocol (RDP) on port 3389, reachable from the public internet, is the single most-exploited entry vector in UK SME ransomware incidents. NCSC reports consistently put it in the top three. The usual story starts in 2020. Someone opened the port to work remotely through COVID, and it was meant to be temporary. Nobody closed it. Five years later it's still there. Vantyris flags it because closing it is one of the highest-impact 30-minute fixes a small business can make. Bots scanning for open RDP try every weak password they have within minutes of finding the port.
What this means for your business
- Port 3389 (the standard RDP port) is the first thing every credential-stuffing botnet checks. Once they find an open one, they hit it with weak-password lists scraped from old data breaches. Multiple successful logins per day is the norm on any open port.
- Once an attacker gets in, they have an interactive Windows session as the user they compromised. From there they install ransomware, steal data, or use the foothold to move deeper into the network.
- The fix is almost never 'use a stronger password' or 'enable MFA on RDP'. Strong passwords and MFA help, but the underlying problem is exposing administrative services to the public internet at all. The fix is to put RDP behind a VPN or a Zero Trust gateway, so the port isn't directly reachable.
How to fix
Close port 3389 at your firewall. Provide remote access through a VPN (WireGuard, Tailscale, Cloudflare WARP) or a Zero Trust gateway (Cloudflare Access, Tailscale, Twingate). Most modern options are free for small teams.
- Confirm the exposure. From outside your network, try connecting to your office's public IP on port 3389. Or look up your IP on shodan.io. If you see an RDP listener, the port is exposed.
- Decide your replacement remote-access path. There are two cheap options. (1) Tailscale is free for up to 100 devices. Install the agent on the laptops and the office machine, and remote access works without exposing any ports. (2) Cloudflare WARP + Cloudflare Tunnel has a similar free tier and works the same way. Either one gets rid of the exposed port.
- Roll out the VPN client to anyone who needs remote access. Install the chosen client on every remote worker's laptop and test that they can reach the office machine over the VPN. Write down how access works, so new hires don't ask 'but why can't I just RDP'.
- Close port 3389 at your firewall. On your router or office firewall, remove the port-forward rule for 3389 (and any other admin port: 22 for SSH, 5900 for VNC, 5985-5986 for WinRM). Then test both ways. RDP should work over the VPN and fail from the public internet.
- Audit other admin ports. While you're in the firewall, look for other commonly exposed admin services: SSH, MySQL, RDP, VNC, WinRM. Close anything without a deliberate business reason. The rule is 'admin services live behind the VPN, and only public-facing services (HTTP, HTTPS, SMTP) face the public internet'.
Owner: Your IT administrator or web host. For small businesses with no IT, your web host's support team can usually make the firewall changes. The VPN setup might need an outside contractor. · Time: 1-2 hours including VPN rollout to a small team.
Common gotchas
- Don't replace one exposed admin port with another. Some businesses 'fix' the RDP exposure by moving it to port 3390 or 33890. Bots scan every port, standard or not. The port number doesn't matter. The public exposure does.
- Strong passwords + MFA on RDP help but aren't the right fix. They're a partial mitigation. A VPN puts authentication in front of the port BEFORE the RDP layer, so the attacker can't even attempt the RDP login.
- Some businesses think 'we only allow our office IP through the firewall'. Static IP allow-listing works if your office IP is genuinely static, and most aren't (consumer-grade business broadband rotates). It also breaks the moment someone needs to work from home or travel.
- If an MSP or vendor has an SLA requiring 24/7 remote access, agree the VPN setup and the cutover with them before you close the port.
How to verify the fix
A Vantyris verified scan checks for exposed RDP and other admin ports in the Exposure category. Or look up your public IP on shodan.io after closing the port. Within 24-48 hours of the firewall change, it should show no RDP listener.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A1. Firewalls: boundary protection between the internet and your services.
- A4. User access control: accounts assigned the minimum required privileges.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
We're a 5-person firm. Is a VPN really worth the setup?
Yes. Modern VPNs (Tailscale, Cloudflare WARP) take 15 minutes to set up and are free at your size. The attack they prevent, ransomware through exposed RDP, is the most expensive incident class a small UK firm typically faces. The ROI is overwhelming.
What about cloud RDP services like Azure Bastion or AWS Session Manager?
Both are excellent if you already use Azure / AWS. They tunnel RDP over your cloud login instead of the public internet. For firms running on-premises Windows with no cloud presence, Tailscale or Cloudflare is the lighter-weight choice.
Will closing RDP break our remote staff?
Yes, temporarily, until they install the VPN client. Plan the cutover, and don't close the port at 5pm on a Friday.
Is RDP the only port we should worry about?
It's the highest-risk single one. Other admin ports that commonly end up exposed: SSH (22), MySQL (3306), MongoDB (27017), Redis (6379), Elasticsearch (9200), WinRM (5985-5986), SMB (445). Close all of them, and leave only your web and mail services (HTTP, HTTPS, SMTP) open to the internet.
References
- NCSC: Remote Desktop Protocol NCSC
- CISA: RDP attacks alert CISA
- Microsoft: secure RDP configuration Vendor
Related explainers
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris