Guides · RDP-FIDO-GATE

RDP, MFA and the cyber-insurance questionnaire

Cyber-insurance applications have converged on a handful of remote-access questions, and “no” on any of them can raise the premium or end the conversation. This guide explains what is being asked and how a small business can honestly answer “yes” for Remote Desktop.

Updated

The questions you will meet

The wording differs between insurers, but the intent is the same: exposed RDP with password-only logins is one of the most common ways ransomware gets in, and underwriters want to see it closed.

What “phishing-resistant MFA” means

Not all second factors are equal. SMS codes can be intercepted or redirected, app codes can be read out to a caller, and push prompts can be approved by a tired user. CISA's guidance on implementing phishing-resistant MFA and NIST SP 800-63B both single out authenticators where the secret never leaves the device and the response is cryptographically bound to the service — in practice, FIDO2 / WebAuthn security keys and platform authenticators.

An application may not use the phrase, but a hardware-key answer is the one that never needs a follow-up question.

Meeting the RDP questions with a port gate

RDP-FIDO-GATE addresses both RDP questions with one control on the host:

A rollout plan for a small office

  1. List every machine reachable by RDP from outside — including the forgotten port forward on the router.
  2. Buy two FIDO2 keys per person who needs remote access: one to use, one as a spare kept in a safe place.
  3. Install the gate on each host and enroll both keys. The setup guide covers it.
  4. Confirm from outside that 3389 does not answer: Test-NetConnection <host> -Port 3389 must fail before a key touch.
  5. Keep evidence for the application: a dated external scan showing 3389 closed and a short written procedure for enrolling and revoking keys.

What this does not cover

A questionnaire asks about more than RDP: e-mail MFA, backups, endpoint protection, patching. The gate is a technical control for remote desktop access only. It is not legal or insurance advice — read your insurer's definitions and answer each question as it is written.

RDP-FIDO-GATE

RDP-FIDO-GATE keeps port 3389 closed and opens it for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. The Free edition covers 10 saved sessions.

Frequently asked questions

Will an insurer accept this as MFA for remote access?

The control matches what the questions ask for: a second factor before access and no exposed RDP. Acceptance is the insurer's decision; describe the setup accurately — port closed by default, FIDO2 key required to open it, Windows password after — and keep evidence.

Is an authenticator-app code enough?

For most questionnaires app-based codes count as MFA. They are not phishing-resistant, so where the form distinguishes methods, hardware keys are the stronger answer.

What does it cost?

The Free edition covers up to 10 saved sessions. Pro is a one-time $49 with unlimited sessions and no ads; regional prices are shown at checkout. FIDO2 keys are bought separately from any vendor.

Related guides