The short answer
Remote IT support is safe when it is attended, logged and initiated by you. A technician connecting to an attended session can see the screen and use the keyboard and mouse — nothing more and nothing less than someone sitting at that desk. You approve the connection, you watch the whole session, and you can end it at any moment. The danger is not remote support; it is unsolicited remote support.
What a technician can see
During an attended session, exactly what is on the screen. If a document is open, it is visible. If you minimise it, it is not. They can use the mouse and keyboard as if sitting at that desk, which is what makes the fix possible — and which is also the whole extent of it.
What they cannot do is browse quietly in the background, read email you have not opened, watch through the webcam, or connect without a prompt appearing. Those capabilities exist in surveillance software, not in support tools, and any provider whose setup blurs that line is one to question.
Who controls the access
- You approve every attended session. A prompt appears and somebody there accepts it.
- You can end the session instantly, at any point, from your own machine.
- You see every action as it happens — there is no hidden screen.
- Unattended access to servers and shared machines is set up deliberately, with your knowledge, and is the exception rather than the default.
- Every session is logged. You are entitled to ask for that log, and a provider who cannot produce one has a problem.
Before a session, do this
Nothing elaborate, and it takes ten seconds: close anything you would not show a contractor standing at your desk. Personal banking, private correspondence, a payroll spreadsheet. Not because we are looking, but because it removes the question entirely, and good practice does not depend on trust.
The scam version, and how to tell
Nobody legitimate rings you out of the blue about a problem you had not noticed. Not Microsoft, not Telstra, not the ATO, and not us. A real support session starts because you contacted somebody. If a call arrives claiming your computer is infected and asking you to install something, hang up — do not argue, do not stay on the line.
Five signs the call is a scam
- They rang you, rather than you ringing them
- They claim to be from a company you have no support arrangement with
- There is urgency, or a threat about your account being closed
- They ask you to install something from a website you have never heard of
- At any point the conversation turns to a payment, a gift card, or your bank
The tell that matters most is the first one. A genuine technician is responding to something you reported. If in doubt, hang up and ring the number you already had — never a number the caller gives you.
What to ask your provider
Four questions, and any competent provider will answer all four without hesitating:
- Do your sessions require someone here to approve them?
- Which machines do you have unattended access to, and why those?
- Are sessions logged, and can I see the log?
- If a technician leaves your business, how quickly is their access revoked?
The fourth is the one people forget, and it is the one that matters most in a small provider. Access should be tied to individuals, revoked the day someone leaves, not shared through an account everyone uses.
If you think something has already happened
If someone was given access who should not have had it, disconnect that machine from the network but leave it powered on, change the passwords for anything used on it from a different device, and call someone. Do not delete anything, including the email or the call log. Emergency IT support has the full first-ten-minutes list.
Can a technician access my computer when I am not there?
Not for an attended session — those require somebody at the machine to accept a prompt. Unattended access exists for servers and shared machines that nobody sits at, and it is set up with your knowledge and logged. If you are not sure which of your machines have it, ask; you should be given a straight list.
Is remote support less secure than someone coming to the office?
No, and in one respect it is more secure: every action is on a screen you are watching and in a log you can request. A technician physically at a desk while you are in a meeting is far less observed than one in a remote session.
Should I change my password after a support session?
If you typed a password while the technician could see the screen, yes. Better practice is that they should not need it — most work should be done through an administrative account of their own rather than by borrowing yours.