The emergency phase of remote work is long over. Most businesses in Denton County have settled into an arrangement that works: fully remote for a few roles, two or three days in the office for others, and a sales team that has not sat at a desk in years. The security around it is often whatever got stood up in a hurry.

That gap is worth closing, and the practices are now settled. There is a clear set of things that work, and a short list of gaps we still find at almost every office we walk into. Here is the honest version, including the coffee shop question everyone asks and most articles answer badly.

Start With the Device Question

Most small businesses have never explicitly made this decision. Whose computer is your work happening on? There are two defensible answers and one bad one: the accidental middle, where personal laptops do full company work with no rules and no visibility.

  • Company managed devices. You buy the hardware, enroll it in management, control encryption, updates, and endpoint protection, and can wipe it remotely. Worth the cost for any role touching customer data.
  • Personal devices with a clear boundary. If people use their own machines, define exactly what those machines may reach. NIST’s Guide to Enterprise Telework, Remote Access, and Bring Your Own Device Security, published in 2016, calls this tiered access: the most-controlled devices get the most access, the least-controlled get minimal access.
  • Browser only access as a middle path. A personal machine reaching email through a browser, with nothing saved locally, is a cheap compromise.

Whichever you choose, write it down. The common failure is not a wrong choice, it is no choice, which quietly becomes shadow technology spread across a dozen kitchen tables, a pattern we described in our post on shadow IT and the risk inside your own organization.

Identity Is the New Perimeter

The old model was a wall around a building. When half your people work from home and your files live in a cloud service, that wall describes nothing real. NIST states the assumption plainly in that same 2016 guidance: plan remote access security on the assumption that the networks between the telework device and the organization cannot be trusted. What matters now is whether the person signing in is who they claim to be.

  • Multifactor authentication everywhere, starting with email. Email resets every other account. If you do one thing from this article, do this.
  • Single sign on where you can get it. One identity across your applications means one place to turn access off the day somebody leaves.
  • Least privilege, checked periodically. The Federal Trade Commission’s Start with Security guide advises that administrative access, which lets a user make system-wide changes, be limited to the employees tasked with that job.
  • Conditional rules where your platform supports them. Blocking sign ins from countries you never do business in is a few clicks in a system you already pay for.

The Home Network, and the Coffee Shop Question

Home network guidance should be short, because a long list will not get done.

  1. Change the router’s default administrator password. Not the wireless password, the login for the router itself. Most people have never seen it.
  2. Let the router install its updates. Turn on automatic firmware updates. If the manufacturer no longer supports the model, replace it.
  3. Use modern wireless encryption with a strong passphrase. The current standard your equipment supports, not an older option kept for one ancient device.

Now the coffee shop question, answered honestly rather than dramatically. Public wireless is far less dangerous than a decade ago, because nearly all web traffic is now encrypted in transit by default. The old picture of someone in the corner reading your email off the air is largely obsolete on an updated device.

That does not mean it stopped mattering. The real risks shifted: the person reading your screen, the laptop left on a table while you get a refill, the fake network with a plausible name. Our guidance is that a managed, encrypted, updated laptop on public wireless is fine for normal work, a cellular hotspot is better for sensitive work, and no network security helps if the screen is visible or the machine walks away.

Physical Security and Offboarding Remote Staff

Physical security quietly disappeared when the office emptied out. A laptop in a car, a screen visible through a window, invoices on a dining table, and a device that never comes back are all ordinary now.

NIST’s 2016 telework guidance recommends assuming the worst: that telework client devices will be acquired by malicious parties who will either recover sensitive data from them or use them to reach the enterprise network. Its mitigations are encrypting the device’s storage, encrypting sensitive data on it, or not storing sensitive data on it at all. Full disk encryption ships with the business version of every major operating system. Turn it on and verify it.

The FTC’s small business physical security guidance adds two points. Staff should know what to do if equipment or paper files are lost or stolen, including whom to notify. And do not rely on delete alone, because that does not actually remove the file; erase data with software before discarding old equipment.

Offboarding a remote employee needs a written sequence, because the informal version fails. In an office, the laptop is on the desk. At a distance, it is in a spare bedroom in another county.

  1. Disable accounts at the identity provider first. One place, timed to the conversation.
  2. Revoke active sessions and application passwords. Disabling an account does not always end sessions already signed in.
  3. Arrange hardware return in writing, with a prepaid label and a date.
  4. Wipe the device before it is reissued. A full wipe and rebuild, not a file cleanup.
  5. Change shared credentials that person knew. Departure day is when shared logins come due.

What to Write Into a Remote Work Policy

NIST recommends a telework security policy that defines telework, remote access, and BYOD requirements, specifying permitted forms of access, device types, and access levels for different users. Two pages beats forty, because two pages gets read.

  • Which devices are allowed for which work. The decision from earlier, in plain language.
  • Where company data is allowed to live. Name the approved storage locations, and say that personal cloud accounts and personal email are not among them.
  • What happens at the end. Return expectations, timelines, and what gets wiped, agreed at hire.
  • Security requirements for company work. Encryption on, updates installed, screen lock enabled, endpoint protection running.
  • What to do when something is lost or looks wrong. One contact, one method, and a promise that fast reporting is welcomed.

The Bottom Line

Remote and hybrid work is not less secure. It is differently secure, and the businesses that struggle are running an office shaped security model over a workforce that no longer sits in an office. Decide the device question and write it down. Move your controls to identity, starting with multifactor on email. Answer the coffee shop question honestly. Encrypt the disks. Write the offboarding sequence before you need it.

None of this requires a large budget. Most is configuration in systems you already pay for. The businesses that get burned are rarely the ones that could not afford the fix. They are the ones that never made the decision, the same pattern we described in our post on why cybersecurity is no longer optional for mid-sized businesses.

If you want someone to look at how your remote setup is actually configured, rather than how it was described when it was built, we do that work. We will check device management, encryption, identity, and offboarding, then give you a prioritized list. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).