The National Cyber Security Council (NCSC) has released new cloud platform guidance urging cloud adopters to protect the use of legacy management protocols, like RDP and SSH.
RDPs, or Remote Desktop Protocol, allow users to access and control a remote device from another device via a network, whereas an SSH, or secure shell, refers to the ability to remotely access and manage virtual machines in a cloud environment, which it can do over an unsecured network.
While these traditional cloud connection methods are relatively well understood in the tech sphere, the NCSC is giving special attention to improving the security infrastructure of cloud administration.
In the cloud, management interfaces are often exposed directly or accessed via public internet, meaning that customers have an easy route to administer their infrastructure. But this also transforms the attack surface, making it easier for bad actors to target these cloud-based resources.
The NCSC has seen attackers consistently target exposed cloud management interfaces, exploiting weaknesses such as insecure interface configurations and management protocol vulnerabilities to first gain access. Once this is successful and the infrastructure is compromised, attackers move laterally or try to steal data, deny service, or deploy ransomware.
“Unfortunately, due to the prevalence of exposed infrastructure and the potential gains from successful attacks, exposed management interfaces remain an enticing target for many attackers,” Elliot L, cloud security research at the NCSC, said in a blog post.
To mitigate these risks, the NCSC continues to recommend that management interfaces are protected from untrusted networks.
While traditional protections often include administration proxies, this method can be error prone and resource intensive at scale.
Recommended reading
- NCSC Releases New Email Security Check Tool
- NCSC Issues Guidance for Securing Cloud-Hosted SCADA Systems
- Private Branch Exchange Networks at Risk, NCSC Says
Many organisations offer cloud administration proxy services, and organisations should seek those that are provided as a managed services and prevent interfaces from needing to be exposed directly to untrusted networks. It should also integrate with the cloud’s identity and access management (IAM) mechanisms, and include broader security-enabling features such as session logging or browser-based connectivity.
Other options pointed out by the NCSC include adopting a serverless compute platform to reduce management burdens, as well as minimising the amount of interactive access required to workspaces via automated alternatives.
Whatever methods organisations choose to adopt, the end goal should be to restrict routine access to sensitive workspaces, use manages services where possible, and have no legacy management interfaces publicly exposed.





