Skip to content
End This At Any Time You can end a remote session at any time

Remote desktop and remote support

You cannot check what is being done. You can only decide who

Fifty notes on remote access from both ends: what the person being helped actually sees, how to run a session they can follow, the fraud that uses the same tools, and what to do in the first hour if it has already happened.

Core notes remain practice-focused; separate guides compare named tools. No unverified fraud statistics. Nothing here is legal advice.

The trust problem

A remote session asks somebody to trust completely and gives them no means of checking. That is not a flaw in any particular product; it is the shape of the thing.

The practical lesson in “You cannot check what is being done. You can only decide who” is to make responsibility visible without confusing visibility with certainty. A team reviewing employee monitoring software for employee monitoring software can add structured time and project context, provided the purpose is disclosed and the interpretation is checked with the people affected.

The person cannot tell whether the actions on screen match the explanation. They cannot know what a command does, distinguish a diagnostic from a search of their files, or see what was copied. With a tradesperson in your home you can watch. Here, watching does not help, because the activity is technical, fast, and legible only to the person performing it.

For an independent reference related to “You cannot check what is being done. You can only decide who”, consult the ENISA cybersecurity resources; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.

Which means the decision happens before the connection, not during it. Once the session starts there is no meaningful ongoing check. That is why every piece of advice about remote access fraud concerns the moment before, and why pressure to connect quickly is the clearest warning sign there is.

Why the same tools serve help and harm

A tool designed so that access is easy to grant is a tool where access is easy to obtain by deception. The ease is the feature and the vulnerability, and no configuration separates them.

This is not a criticism of the products, which could not do their job otherwise. It is the reason the safeguards in this collection are things people say and do rather than things they switch on.

Four sentences before you connect

"Here is what I think is wrong and what I am going to do." It gives the person a reference to check against. They cannot verify a command, but they can notice that you said you were checking printer settings and are now in their documents.

"You can end this at any time — here is how." Most people do not know they can stop it. That knowledge changes the relationship from permission granted to permission continuing, which is a materially different thing. It is also the single most useful fact a person can carry into any future session, including one they should not have agreed to.

"I will tell you what I am doing as I go." Narration is the only running account the person has.

"Please close anything private before we start." Everybody has something open they would rather not show. Ten seconds, and it signals that you are not interested in anything else.

A minute in total, and almost nobody says them.

The fraud that uses these tools

A substantial and persistent fraud uses remote access against individuals. Its shape is recognisable even when the details change.

Contact comes to the person: an unexpected call claiming to be from a technology company, a bank or a provider, or a message on screen with a number to ring. Access is requested as "checking" or "fixing", never as granting control. Something is then shown that appears to demonstrate a problem or a refund — constructed by the caller and not real. And it ends in a request for an irreversible transfer of value.

The signature is three things together: urgency, secrecy and continuity. It must be now; do not discuss it with anybody, including bank staff; stay on the line. Those three appear in almost no legitimate interaction.

The one-line test is simpler than any of it. Did I contact them, or did they contact me? No legitimate organisation initiates contact and then asks for access to your computer.

Why it works, and on whom

The common explanation is that victims are naive. That explanation is wrong, unhelpful, and it stops the people who hold it from recognising their own exposure.

What produces vulnerability is a set of conditions rather than a trait: being interrupted, being tired or unwell or recently bereaved, having just had a genuine technical problem, being alone with nobody to ask, and being spoken to by somebody calm and competent while you are not. Anybody can be in all five on a given afternoon.

And the active ingredient is isolation. The instruction not to discuss it is the most important thing the caller does, because one conversation with almost anybody ends it. Which is why the single most effective protection is not knowledge but a person who is easy to ring — and why making somebody feel foolish for asking is more damaging than it appears.

What to do if it has already happened

The first hour matters most, and the order is not obvious.

Disconnect the machine. Turn off the wireless, unplug the cable, or switch it off entirely. This ends any active session immediately. Do not try to work out what they did first — that can wait and the connection cannot.

Ring the bank, from a different phone if the call might still be connected, using the number on a card or statement rather than anything provided during the incident. Banks can sometimes stop or recall a transfer in the first hours, and the window closes fast.

Change passwords from a different device, email first because it controls everything else. Then the machine itself: assume anything on it was seen and anything typed was captured, which usually means a clean reinstall rather than removing what you can find.

And expect a second approach. People who have been defrauded once are contacted again, sometimes by somebody offering to recover the money. That offer is part of the same industry.

The conversation afterwards

How this is handled determines whether they tell you about the next one, which is the thing that actually matters.

What they are feeling is shame disproportionate to anything they did wrong, and frequently a specific fear that this will become evidence they can no longer live independently. That fear shapes everything about whether they say anything at all.

Three things make it worse. "How could you fall for that" confirms their worst interpretation and ends disclosure permanently. Taking over removes the competence they are already doubting. And telling the family as a story converts a difficult experience into their identity within the family — they will know.

What helps is the opposite: this happens to a great many people and the people doing it are extremely good at it; here are the steps, done together; and this changes nothing about what you can manage, which is why telling me quickly is useful rather than costly.

For support desks

The professional half of this collection argues that the controls have to work without depending on everybody being thoughtful on every call.

Which means scoping technicians to the machines they actually support, rather than leaving the default of everything. It means logs indexed by machine, because "who connected to my computer last week" is the question people actually ask and most platforms answer only by technician. It means attended sessions by default, with unattended access inventoried and reviewed rather than accumulating.

And it means a handling-time target that allows two minutes for the opening and the summary. If it does not, the target is setting the conduct — which is a management decision rather than a training failure, and saying so is the only way it changes.

There is also a verification that runs the other way and is almost always missing. Users should be able to confirm that a support contact is genuine, because the consumer fraud has an organisational version, and a workforce trained to accept any call from "IT" is the vulnerability.

What the core notes deliberately avoid

No products are named. The tools consolidate and the names date — and naming a legitimate product in a chapter about fraud would misdirect the warning. The rule worth teaching is not about which software: the name of the program does not make it safe or unsafe. Who asked you to install it does.

No fraud statistics, because the available figures vary by orders of magnitude depending on who counted.

And no step-by-step account of the fraud. The recognisable shape is what transfers to variants; the mechanics are not set out, and are not needed.

Product comparisons

Tool guides for support operations

Three detailed shortlists covering remote support, time tracking and IT service management.

8 Remote Support and Desktop Access Tools for Secure Operations

Eight remote support and desktop access tools compared for session control, administration, auditability and responsible operation.

Compare 8 tools →

13 Time Tracking Tools for IT Support Teams

Thirteen time tracking tools compared for tickets, projects, support coverage, corrections and transparent team adoption.

Compare 13 tools →

20 IT Service Management and Workforce Operations Platforms

Twenty IT service management and workforce operations platforms compared for service delivery, endpoint work, reporting and governance.

Compare 20 tools →

Session ended

What was wrong, what changed, what to watch for

Every session should end with those three in two sentences. It is the only durable record the person has, and without it they know a stranger used their computer and nothing else.