TL;DR: Remote security now extends beyond VPN replacement, because remote privileged access must cover users, devices, sessions, and auditability across internal teams and third parties, according to Arcon. The governance gap is no longer access alone, but whether organisations can continuously answer who accessed what, for how long, and under which device and credential conditions.
NHIMG editorial — based on content published by Arcon: The Crux of Remote Security
By the numbers:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
Questions worth separating out
Q: How should security teams govern third-party remote access in practice?
A: Treat third-party remote access as a governed identity path, not a networking exception.
Q: Why do unmanaged remote sessions create PAM risk?
A: Because PAM depends on knowing who had elevated access, what they did, and when the session ended.
Q: What breaks when remote access logs stop at login events?
A: When logging stops at login events, teams lose the evidence needed to reconstruct queries, commands, and privilege changes inside the session.
Practitioner guidance
- Bind remote sessions to identity and device context Require strong authentication, known device posture, and explicit session scoping before privileged remote access is granted.
- Record and retain privileged session evidence Keep session logs, user activity, and video evidence long enough to support audit, investigation, and vendor accountability.
- Separate monitoring from elevation rights Give administrators visibility into remote displays without automatically expanding the permissions available in that session.
What's in the full article
Arcon's full article covers the operational detail this post intentionally leaves for the source:
- Feature-level description of remote desktop control across multiple displays for administrative oversight
- Archive and purge behaviour for session logs, user records, and device records in remote access workflows
- Standalone thick-client capabilities for secure remote access, collaboration, and file transfer
- Operational claims around privileged elevation, admin-right changes, and credential changes within remote sessions
👉 Read Arcon's analysis of secure remote access and privileged session governance →
Remote access governance: are your controls keeping up with hybrid IT?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Remote access is now a privileged identity problem, not a network problem. The article describes a control model built around external users reaching critical systems from unmanaged or semi-managed environments. That shifts the security question from perimeter defence to identity assurance, session governance, and evidence retention. For practitioners, remote access must be treated as a high-risk identity pathway with PAM-grade controls.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to AI Agents: The New Attack Surface report.
- 52% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, which means governance gaps in remote access will compound quickly.
A question worth separating out:
Q: Who is accountable when privileged access is not removed on time?
A: Accountability should sit with the business owner of the role, the system owner, and the identity governance process that approved and failed to remove the access. In regulated environments, delayed removal is not just a technical issue. It is a control failure that can undermine auditability and compliance evidence.
👉 Read our full editorial: Remote access governance is the real control plane for hybrid IT