We had trouble working from home and needed access to the office computers, so we enabled RDP. We turned on Windows built-in Remote Desktop, Port 3389. We emailed passwords to all employees (standard passwords, not complex). Maybe it was wrong to do, but now all computers are accessible from the internet.
A friend told us today: 'Opening RDP to the internet is bad'. Why? The password is strong, we have antivirus. Are people trying to attack via SSH or similar methods?
I can't disable RDP right now (employees are working remotely). But how can I secure it? Do I need to set up a VPN? Or is there another way?