I would definitely stop allowing RDP from any and limit to your supplier's IP address at minimum. If your supplier only needs it at specific times, you can set a rule to deny RDP traffic from the supplier, then when the supplier needs access you can change the rule from deny to allow. This would control the window of time when RDP is actually accessible and can help with security on your side. If your supplier was ever compromised, and you have the rule open 24/7, that could open you up to a potential lateral attack. Manually allowing at specific times will at least block from that potential threat. a 3rd party software similar to LogMeIn or TeamViewer is probably best since they would need software authentication and typically uses 443 to connect to your server.
... View more