Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Services
London · IT Services

VPN & Secure Remote Access

A controlled way into the file server, accounts package or line-of-business app that stayed on site — without leaving it exposed to the internet.

Response within 4 hours On-site & remote No long contracts Windows & Mac

Reaching the things that stayed behind

Most of the working day has moved to the cloud. Then there is the rest of it. A file server in the cupboard. An accounts package that expects a mapped drive. A practice-management or design system tied to a licence server. A camera recorder or door controller with a web interface. People still need to reach those from home, from a client’s office, from a hotel on a Tuesday night — and how they get there is the whole question.

The most common answer is the worst one. Somebody forwards port 3389 on the router so a director can use Remote Desktop from home. It works. It also publishes a Windows login prompt on the open internet, where automated scanners find it and start guessing. Remote Desktop exposed this way is still one of the most reliable routes by which a small business ends up encrypted and negotiating with criminals. If your setup includes a forwarded RDP port, treat that as the most urgent item on your IT list this week.

Secure remote access is the alternative: a proper door into your systems, with a lock, a second factor, and a record of who used it.

What we build

  • Client VPN — a real VPN on your firewall or router, so staff laptops connect back to the office network from anywhere
  • Site-to-site VPN — two or more offices joined into one network, so a share or an application at one site is reachable from the other
  • Zero-trust and mesh access — modern tools, usually WireGuard-based, that connect a device to one named application rather than to the entire network
  • MFA in front of it — access tied to your Microsoft 365 or Entra identities with multi-factor authentication, rather than a shared password on a note
  • Sensible split tunnelling — office traffic through the tunnel, calls and general browsing straight out, so video meetings stay usable
  • Published properly, not exposed — where a service truly must be reachable, it goes behind a gateway or reverse proxy instead of a forwarded port
  • Joiner and leaver process — profiles and certificates issued with the account and revoked with it, so nothing outlives the employment
  • Logging — a record of who connected, from where, and when

Where this comes up

Firms with one thing left on site and everyone else scattered. Accountants running a desktop tax or practice package. Law and property firms with a matter archive on a server. Surveyors and architects with drawing libraries too large to shift overnight. Manufacturers with a stock or order system bolted to a local database. It also comes up in businesses across Croydon and Surrey that opened a second office and now need both to see the same files, and with home-workers and hybrid teams getting by on a remote-control tool nobody deliberately chose.

The honest version

A VPN is not a security product. It is a tunnel. It proves where a connection came from and encrypts what travels inside it, and that is all. Connect an unpatched laptop with no endpoint protection, or a shared family PC, and you have extended your network to include that machine and everything on it. Remote access is only as safe as the devices allowed to use it, which is why we pair it with device standards, patching and endpoint protection rather than selling a tunnel and calling the job done.

And sometimes the right answer is no VPN at all. If the tunnel exists only to reach one file share and one application, moving that last piece to the cloud is usually cheaper than maintaining remote access for it forever. We will say so when it’s true, even though it is less work for us.

How we approach it

  1. See what’s already exposed — we check your public address for forwarded ports and open services, and show you what the internet can see today
  2. Agree what needs reaching — which systems people genuinely need remotely, and which people
  3. Choose the method — client VPN, site-to-site link, zero-trust access, or retiring the resource instead
  4. Build and secure — configuration on the firewall or access platform, MFA enforced, split tunnelling set so calls survive
  5. Close the old doors — forwarded ports removed, forgotten remote-control tools retired
  6. Roll out and document — profiles issued, a short guide written for staff, and the joiner and leaver steps handed to whoever manages accounts

Faults and risks we’re called in for

  • Remote Desktop published straight to the internet on port 3389
  • A VPN that drops every few minutes, so people quietly stop using it
  • Video calls that stutter because every packet is routed via the office
  • Leavers whose VPN profile still connects months after they went
  • A remote-access tool installed by a former supplier that nobody can account for
  • Staff emailing files to themselves because the VPN is too painful to bother with
  • Two offices with no link between them and a shared folder copied by hand

Remote access is only as good as the network under it, so if your router and switches are consumer kit added over the years, start with business network setup. The controls that make remote access genuinely safe — patching, endpoint protection, MFA — belong with cyber security. Where the honest fix is retiring the last server, that becomes a cloud migration conversation instead. For a plain-English primer to share with colleagues, read our guide to VPNs for small business, and if you’d like someone looking after the day-to-day once it’s built, see remote IT support.

Frequently asked questions

Is opening Remote Desktop to the internet really that risky?

Yes, and not in a theoretical way. Automated scanners find an exposed RDP port quickly, then work through stolen and guessed credentials around the clock without getting bored. It remains one of the most common entry points in small-business ransomware cases. If port 3389 is forwarded on your router, close it and put the access behind a VPN or a zero-trust gateway instead.

Does a VPN make our data secure on its own?

No. A VPN encrypts the connection and controls who reaches the network. That is the whole job. It does nothing about malware on the connecting laptop, an operating system three years behind on updates, or a home PC shared with the rest of the family. Think of it as a good lock on a door, then decide whether you're happy with what is coming through.

Why do Teams calls get worse when staff are on the VPN?

Usually because everything is being forced down the tunnel. If browsing and video both travel to the office and back before reaching the internet, you have added a detour and a bottleneck to every packet. Split tunnelling sends only office traffic through the VPN and lets Teams and web traffic go direct, which normally fixes it.

Could we get rid of the VPN altogether?

Often, yes. If the tunnel exists purely for one file share and one application that now has a hosted version, moving those removes the need for remote access entirely — and removes a piece of infrastructure to maintain, patch and secure. We look at what the VPN is genuinely carrying before assuming it has to stay.

What clients say

Trusted by London businesses.

“Honest and transparent — they could have charged me more, but instead showed me a simple fix. Trustworthy people.”
— Small business client, London
“One of the most ethical companies I’ve ever dealt with. A genuine pleasure to work with — highly recommended.”
— Managed IT client
“The service was flawless — no bad surprises, everything just worked. Highly recommended.”
— Business client, London
“Thank you very much for your assistance. A pleasure as always.”
— General manager, accommodation business, Chelsea SW3

Feedback from clients of our team, including our sister company PC Macgicians, who deliver much of our engineering work. Names withheld at their request.

Free · no obligation

Need help with VPN & Secure Remote Access?

Tell us what you need and we'll come back with a clear, no-obligation plan and price.