From open remote access to controlled access
The terminal server was reachable directly from the internet and protected by a password only, the logs showed thousands of login attempts every day. We replaced the open access with a WireGuard VPN using multi-factor authentication, segmented the network and set up central log monitoring with alerting. Today no administrative service is publicly reachable, anomalies raise an automatic alert, and the security questionnaire from their largest client was passed.