Skip to main content

Ports

RDP on the public internet: the single biggest ransomware vector for UK small businesses.

Published 2026-04-09 · Last updated 2026-04-09 · Vantyris editorial

Remote Desktop Protocol (RDP) on port 3389, reachable from the public internet, is the single most-exploited entry vector in UK SME ransomware incidents. NCSC reports consistently put it in the top three. The usual story starts in 2020. Someone opened the port to work remotely through COVID, and it was meant to be temporary. Nobody closed it. Five years later it's still there. Vantyris flags it because closing it is one of the highest-impact 30-minute fixes a small business can make. Bots scanning for open RDP try every weak password they have within minutes of finding the port.

What this means for your business

How to fix

Close port 3389 at your firewall. Provide remote access through a VPN (WireGuard, Tailscale, Cloudflare WARP) or a Zero Trust gateway (Cloudflare Access, Tailscale, Twingate). Most modern options are free for small teams.

  1. Confirm the exposure. From outside your network, try connecting to your office's public IP on port 3389. Or look up your IP on shodan.io. If you see an RDP listener, the port is exposed.
  2. Decide your replacement remote-access path. There are two cheap options. (1) Tailscale is free for up to 100 devices. Install the agent on the laptops and the office machine, and remote access works without exposing any ports. (2) Cloudflare WARP + Cloudflare Tunnel has a similar free tier and works the same way. Either one gets rid of the exposed port.
  3. Roll out the VPN client to anyone who needs remote access. Install the chosen client on every remote worker's laptop and test that they can reach the office machine over the VPN. Write down how access works, so new hires don't ask 'but why can't I just RDP'.
  4. Close port 3389 at your firewall. On your router or office firewall, remove the port-forward rule for 3389 (and any other admin port: 22 for SSH, 5900 for VNC, 5985-5986 for WinRM). Then test both ways. RDP should work over the VPN and fail from the public internet.
  5. Audit other admin ports. While you're in the firewall, look for other commonly exposed admin services: SSH, MySQL, RDP, VNC, WinRM. Close anything without a deliberate business reason. The rule is 'admin services live behind the VPN, and only public-facing services (HTTP, HTTPS, SMTP) face the public internet'.

Owner: Your IT administrator or web host. For small businesses with no IT, your web host's support team can usually make the firewall changes. The VPN setup might need an outside contractor. · Time: 1-2 hours including VPN rollout to a small team.

Common gotchas

How to verify the fix

A Vantyris verified scan checks for exposed RDP and other admin ports in the Exposure category. Or look up your public IP on shodan.io after closing the port. Within 24-48 hours of the firewall change, it should show no RDP listener.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

We're a 5-person firm. Is a VPN really worth the setup?

Yes. Modern VPNs (Tailscale, Cloudflare WARP) take 15 minutes to set up and are free at your size. The attack they prevent, ransomware through exposed RDP, is the most expensive incident class a small UK firm typically faces. The ROI is overwhelming.

What about cloud RDP services like Azure Bastion or AWS Session Manager?

Both are excellent if you already use Azure / AWS. They tunnel RDP over your cloud login instead of the public internet. For firms running on-premises Windows with no cloud presence, Tailscale or Cloudflare is the lighter-weight choice.

Will closing RDP break our remote staff?

Yes, temporarily, until they install the VPN client. Plan the cutover, and don't close the port at 5pm on a Friday.

Is RDP the only port we should worry about?

It's the highest-risk single one. Other admin ports that commonly end up exposed: SSH (22), MySQL (3306), MongoDB (27017), Redis (6379), Elasticsearch (9200), WinRM (5985-5986), SMB (445). Close all of them, and leave only your web and mail services (HTTP, HTTPS, SMTP) open to the internet.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris