Vendor-neutral guide · 8 min read

Matching business support technology to the pace of transformation

Shape of the topic

Several managed endpoints and servers connecting through attended and unattended paths into one operator console.Several managed endpoints and servers connecting through attended and unattended paths into one operator console.
Mixed estate, mixed access model: attended sessions, unattended agents and a single console that sees both.

In short

The working landscape changed permanently, and so did where company technology sits. Alongside hybrid staff there are now millions of devices operating outside office walls: card readers, point-of-sale terminals, kiosks, waiting-room screens, ATMs, delivery hardware and production machinery. When those go down, productivity drops, targets slip and transactions fail. Supporting them well comes down to three things: the ability to reach any device at any time whether or not someone is present, a zero-trust security posture around that access, and structured training so people can use the technology they have been given.

Key takeaways

  • Company technology permanently operates outside premises, so support capability has to be location-independent.
  • Downtime is one of the highest costs in any organisation, which is what makes reach and speed of access a financial matter rather than a convenience.
  • Support tooling is an investment in throughput, not an extra line of spend.
  • Attended and unattended access are both required: staff need on-demand help, unmanned devices need reaching with nobody there.
  • Assume nothing is trusted by default. Strong encryption and authentication between technician and device is the baseline.
  • Old systems compromise both performance and security, and staff increasingly expect their employer to keep pace.
  • Budget training into the purchase from the start, and keep the ability to walk someone through a task on their own screen afterwards.

The estate moved, and it did not move back

It is not only where people work that changed after the pandemic; it is how the world transacts. Online ordering and delivery expanded sharply, and the shift toward cashless payment accelerated, with a large number of outlets trading through compact card readers. None of that was possible without technology behind it, and it demonstrated how quickly organisations can adapt under pressure.

The consequence for IT is structural. Every one of those changes put more devices outside a building that somebody still has to maintain and secure. Hybrid working compounds it: with around two-thirds of staff favouring a hybrid model, according to survey work by Bankrate, leaders cannot plan support around the assumption that a technician and a device will be in the same place.

So the practical question is no longer whether to support off-premise technology, but how to do it in a way that is fast, secure and does not scale with headcount.

  • Hybrid and remote staff laptops, in homes and on the move
  • Point-of-sale terminals and card readers in retail and hospitality
  • Kiosks, waiting-room terminals and digital signage
  • ATMs, lockers and self-service hardware
  • Manufacturing and logistics equipment on the line or in the yard
  • Delivery and field-service devices that are rarely in one place twice

Why downtime is the number that matters

When an off-premise device fails, productivity plummets, targets go unmet and transactions go uncompleted. That is a revenue event, not a ticket. Downtime is one of the highest costs in any organisation, and the cost accrues for as long as the device is unavailable, which means the time to establish a support session is part of the loss.

This reframes what a support tool is for. Technicians need secure, capable solutions that let them reach and support any device immediately, whether or not someone is at it. The measure of that capability is how quickly a fault stops costing money.

  • Cost per hour of outage, per device class, not per ticket
  • Time to first session on an unattended device
  • Share of incidents resolved without a site visit
  • Transactions or output lost during the last significant outage

Extra spend, or vital investment

Support tooling is often assessed as an additional cost rather than as the thing that extends the reach of a team. In cost terms, having capable tools that broaden what a small IT team can cover delivers a return, because the alternative is either more travel, more headcount or more downtime.

New technology is better understood as the engine that drives progress and creates the efficiencies that improve turnover. Framed that way it belongs in the growth conversation, not only in the IT budget line, and it should be evaluated on the outages it prevents and the engineer hours it recovers.

There is a security dimension to the same argument. Staff running old systems are compromised on performance and expose the organisation to more risk, so deferring the investment is not a neutral decision.

Essential one: anytime and just-in-time support

In a dispersed estate, IT support has to be able to connect to devices wherever they are. That includes a point-of-sale device, a waiting-room terminal, a manufacturing robot or an ATM, none of which has anyone standing next to it ready to accept a session. It equally includes a member of staff working remotely who needs help right now.

Both cases have to be covered by tools that are already deployed, already tested and ready to go. A support capability that has to be installed at the moment of failure is not a support capability. The goal is to jump in, fix the issue and minimise downtime and the costs attached to it, while operating as securely as possible.

  • Unattended access, pre-deployed on every fixed and unmanned device
  • Attended, consent-based access for staff who need on-demand help
  • Sessions that work across networks without asking the user to configure anything
  • Regular testing that access still works before you need it in anger
  • Wake and reboot handling, so an offline device is not automatically a site visit

Essential two: trust nothing and no one

A zero-trust approach is the sensible posture for a flexible working landscape, where the network a device sits on tells you almost nothing about whether the request should be allowed. Every access attempt is authorised on its own merits rather than inherited from a location.

In practice that means the connection between technician and device, attended or unattended, carries strong encryption and authentication, so that bad actors are kept out and company data is protected. It also means named operator accounts with multi-factor authentication, least-privilege scoping and a session record that is complete enough to be evidence.

  • Named accounts and multi-factor authentication for every operator, never shared logins
  • Strong encryption in transit between technician and device
  • Authorisation checked per session, not assumed from the network
  • Least privilege: operators reach the device classes their role requires and no more
  • Full session logging: who connected, to what, when, for how long
  • Prompt offboarding when a person or supplier relationship ends

Essential three: training is not the place to save money

Installing technology that fits the organisation is straightforward reasoning. Cutting the training that goes with it is counterproductive, and it is the most common way a sound purchase produces a poor outcome. Structured user training should be factored into any IT purchasing plan from the outset rather than found later out of an operational budget.

Even after training, people forget things. That is exactly why a support tool should let a technician connect to someone's screen and walk them through the steps in place, rather than emailing instructions. Guided help of that kind is part of an integrated support plan, not an admission that training failed.

  • Budget training inside the purchase, with a named owner and a date
  • Keep short reference material available after the session
  • Use screen-sharing walkthroughs for the questions that recur
  • Track which questions keep coming back, and fix the training rather than the ticket

Being future-ready

Nobody can say where the balance between in-person, hybrid and remote work will finally settle. One thing is not in doubt: some part of every organisation's technology will now always be operating outside its premises. Whether that is one yard or a thousand miles away, the requirement is the same, which is timely, effective and secure support.

Planning for that condition rather than treating it as a temporary state is what distinguishes an estate that can absorb the next change from one that has to be rebuilt each time.

Best-practice checklist

  1. 1. Inventory every off-premise device

    Include staff laptops, terminals, kiosks, signage, self-service hardware and machinery. A device not on the list will not be patched, supported or reclaimed.

  2. 2. Classify attended versus unattended

    Decide per device class whether access requires consent or should be reachable with nobody present, and record the decision before deployment.

  3. 3. Pre-deploy and test access

    Confirm a session can actually be established to every device now, not at the moment of failure. Re-test after network or OS changes.

  4. 4. Apply a zero-trust posture to support

    Named operator accounts, multi-factor authentication, per-session authorisation, encryption in transit and least-privilege scoping.

  5. 5. Turn on and retain session logging

    Capture operator, target, time and duration for every session, retain it long enough to be useful, and test that you can retrieve a record.

  6. 6. Cost the downtime

    Put a figure on an hour of outage for each device class. That number is what justifies the tooling and prioritises which devices get covered first.

  7. 7. Budget training into the purchase

    Fund structured user training as part of the buying plan, and keep screen-guided help available for the things people forget afterwards.

  8. 8. Review access on a schedule

    Remove operators who changed role, devices that were decommissioned and third parties whose contract ended.

Common pitfalls

  • Treating support tooling as discretionary spend while carrying the cost of downtime instead
  • Covering staff laptops but leaving terminals, kiosks and machinery without unattended access
  • Installing remote access at the point of failure rather than before it
  • Relying on network location as a proxy for trust
  • Sharing a single operator login, which makes every session log unattributable
  • Cutting user training to protect a purchase price
  • Leaving old systems in place and absorbing both the performance and the security cost
  • Never testing whether a session log can actually be retrieved

What to measure

Metrics for Supporting off-premise devices
Cost per hour of downtimeEstimated per device class, and used to prioritise coverage
Off-premise devices under managementTarget 100% of known devices, inventory-verified
Time to first sessionMeasured separately for attended and unattended devices
Site visits avoidedCount per month across all sites
Session log completenessTarget 100% of sessions attributable to a named operator
Training coverageShare of staff who completed training, not who were invited

Select any column heading to sort, or filter with the box above.

Frequently asked questions

What counts as an off-premise device?
Anything the organisation depends on that is not inside a managed office: hybrid and remote staff laptops, point-of-sale terminals and card readers, kiosks, waiting-room screens, digital signage, ATMs and self-service hardware, field and delivery devices, and manufacturing or logistics equipment. If its failure stops work or stops a transaction, it needs a support route.
Why does unattended access matter as much as helping staff?
Because a large share of off-premise technology has nobody standing next to it. A terminal, a robot or an ATM cannot accept a support session, so if access depends on consent then the only remaining option is a site visit, and the outage lasts as long as the journey.
How does zero trust apply to remote support specifically?
It means the support session is authorised on its own merits rather than because the device sits on a particular network. In practice: named operator accounts with multi-factor authentication, strong encryption between technician and device, least-privilege scoping by device class, and a complete session log.
Is support tooling really an investment rather than a cost?
Judge it against the alternative. Without it the same incidents are absorbed as travel time, additional headcount or downtime, and downtime is one of the highest costs an organisation carries. Tooling that extends what a small team can reach returns the spend through outages prevented and engineer hours recovered.
Why not save money by skipping formal training?
It is counterproductive. Untrained users generate support demand and use less of the capability that was paid for. Structured training belongs inside the purchasing plan from the start, and screen-guided walkthroughs should stay available afterwards, because people forget steps even after good training.
What is the risk of leaving staff on older systems?
Two costs, not one. Performance is compromised, and the security exposure rises, at a time when staff increasingly expect their employer to keep the technology current. Deferring the upgrade is a decision to carry both.

Sources

Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.

Putting it into practice

This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.

More best-practice guides