Remote Desktop Protocol (RDP)
In one sentence
A Windows feature for controlling a computer remotely. Safe behind protections, dangerous when exposed to the internet.
RDP lets someone operate a Windows machine from elsewhere. Exposed directly to the internet without protection, it's one of the most common ransomware entry points; it should sit behind a VPN with MFA.
Why it's on your cyber insurance application
Applications ask whether RDP is exposed to the internet; 'no' or 'only behind VPN+MFA' is the safe answer.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
MFA & identity
Is MFA required for remote access (VPN, remote desktop) and administrator accounts?
Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.
If the answer is no: Inventory every remote entry point (VPN, RDP, remote-support tools) and privileged account; enforce MFA on each or shut it off.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.