Solution · By need

Remote and hybrid work

The Polish Labour Code gained a dedicated chapter on working from home in 2023, yet many firms still depend on a setup improvised years ago: RDP forwarded through the office router and a login several colleagues share. It survives only until a bot scanning the internet finds it. Our approach is the opposite. Nothing on the company network answers to strangers, documents remain in Microsoft 365 or on your own server, and a departing employee loses every entry point with one action.

No RDP
exposed straight to the internet
MFA
required at every sign-in
Minutes
to onboard or offboard a person
PLN 190
per hour of rollout work, excl. VAT

Pieces of the setup

Exactly what we build depends on daily tools. Sales staff juggling email and Word quotes are a different case from a finance team whose Comarch ERP Optima database sits on a server in the back room.

Help me choose an approach

Tunnel or Zero Trust gateway

Staff reach internal resources through a VPN, or each app is published individually behind a Zero Trust broker. Access depends on a company-managed laptop plus a valid work identity, so a leaked password alone is useless.

Hosted desktops

With Azure Virtual Desktop or Remote Desktop Services, Windows sessions live in the data centre and the device at home merely shows them. Company files stay put, even when a laptop gets forgotten on the 7:15 to Kraków.

Bookkeeping and ERP off-site

Symfonia, enova365, Subiekt nexo or demanding CAD work stays responsive because pixels travel over the link, not SQL queries. No one ends up with a copy of the company database on a home PC.

Second factor and sign-in rules

Approval prompts in Microsoft Authenticator, backed by Entra ID policies that reject log-ins from odd locations or unknown hardware. Phished credentials stop being a disaster.

Device management with Intune

Every laptop and phone is enrolled, disks are BitLocker-encrypted and a lost device can be wiped from afar. On someone's final day, identity, tunnel and mail all close together.

The IT side of your remote work policy

Your remote work rules should also cover data protection, and their exact form is best agreed with HR or a lawyer. We write the technical chapter: permitted devices, connection method, where documents belong. Contract terms and health and safety remain with HR.

Choosing an approach

Three typical patterns. What decides it is the sensitivity of your data and the location of your software, far more than headcount.

Option 1

Work laptop plus VPN

Each person has a company machine that dials into the office LAN over an encrypted link.

Fast to deploy
Fewest changes to how people work
Documents stored locally
Needs encryption and Intune
Data in one place

Option 2

Hosted desktop

Software and files run in one central place, and staff see only a live image of the session.

Company data never leaves
Home computers hold no files
New starters get going quickly
No laptop preparation needed

Option 3

Cloud-only with Microsoft 365

Mail, documents and teamwork are all online, and the office LAN plays no part.

Location does not matter
An office outage changes nothing
Leaves on-site software out
A server-based ERP needs extra work

One of the most dangerous gaps is RDP facing the public internet. An open port 3389 is found by automated scans very quickly, brute-force attempts begin, and the story regularly ends with encrypted servers. If this is how your people log in from home, it is job number one, ahead of every other improvement.

Questions and answers

For a hosted desktop, or for browser-based Microsoft 365 with policies that prevent downloads, it can be. Files then never touch the personal disk. Connecting unmanaged home PCs straight into the office LAN via VPN is something we steer clients away from, since their software and security state are unknown. Note also that the Polish Labour Code places obligations on the employer regarding remote work equipment, and using a personal computer needs to be agreed separately. Confirm the details with HR or a lawyer.

We cover the technology part: approved hardware and connections, handling personal data, the steps after a laptop is lost and who must be told. Allowances, the occupational risk assessment and health and safety training for home-based staff belong to HR or your safety adviser, and our section fits in next to theirs without fuss.

Client-server programs chat constantly with their database and suffer from every millisecond of delay; a dropped link can even damage the data. Moving the program onto a hosted desktop fixes it, because only the picture of the screen crosses the connection and the database sits next to the application.

Sign-in records, showing who opened which system at what time, are standard security practice and we keep them. Screen recorders and keyloggers are another matter: we do not deploy them. They can sit uneasily with GDPR and the Labour Code rules on workplace monitoring, which is worth discussing with a lawyer or your DPO, and they erode goodwill faster than they deliver insight.

How long an MFA, Intune and VPN rollout takes depends on the number of people and devices, so we give an indicative plan after the review. The work is charged at PLN 190/hour excl. VAT or included in a monthly contract. Hosted desktops get their own quote, as most of the cost comes from the computing power needed for your peak number of simultaneous users.

Let us set up remote work for your team

Tell us how many people work outside the office and which applications they need. We will recommend the approach that suits your data and your constraints.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.