A director learns that a colleague’s laptop was left on a train. A supplier’s email account sent a convincing payment request. Nobody knows who still has access to a shared customer folder.
A homeworking policy cannot stop a lost device, phishing click, or exposed password. Practical controls can reduce the damage.
Four controls secure a remote workforce first
Multi-factor authentication (MFA), patching, tested backups, and clear incident reporting should protect key systems first. These systems include email, cloud files, finance tools, and remote access.
A VPN creates a protected route to a network. It cannot stop phishing, weak passwords, or missing updates.
Put MFA on the highest-risk accounts
MFA should cover Microsoft 365, Google Workspace, administrator accounts, payroll, banking, and remote-access tools. Use authenticator apps where possible.
Keep recovery codes in a business password manager. Consider FIDO2 keys for directors, finance staff, and IT administrators.
🎯
Useful for this topic
A FIDO2 security key gives high-risk remote users a second sign-in check. It cannot be copied from a phishing email. It suits banking, Microsoft 365 administrators, and staff approving supplier payments.
- It reduces the risk that a stolen password alone opens a business account.
- It gives finance staff a physical sign-in check for payment and payroll systems.
- It gives a simple record that stronger MFA was issued to key users.
Find on Amazon →
Test backups and reporting routes
Keep one backup separate from everyday accounts. Test a sample restore every 30 to 90 days.
Give every homeworker one reporting route. They should report suspicious emails, lost kit, and unusual pop-ups immediately.
Effective remote working security depends on staff spotting suspicious activity. It also depends on technical controls.
Give staff a short induction before issuing remote access. Follow this with regular phishing tests and real examples.
Use examples of fake supplier bank-detail changes, QR-code scams, and unexpected MFA prompts. Training should explain how to check payment requests through a known phone number.
Staff must report a suspected mistake without delay. They should use approved collaboration tools only.
The most common mistake is treating training as a yearly tick-box task.
A written homeworking policy should cover password managers, screen locking, shared households, and incident reporting. This makes homeworking cyber security, phishing protection, and MFA for workers routine work.
Choose controls by data, size and device type
Risk-based security means matching controls to data, people, and likely harm. Think of it like choosing locks for different doors.
A small studio with managed laptops needs less than a care provider. A care provider may hold health data on personal devices.
Security controls should match the harm a lost account could cause.
| Business situation | Controls to treat as essential | Next sensible layer |
|---|
| 1 to 10 staff, company devices, low-sensitivity data | MFA, updates, encrypted backups, approved storage, incident reporting | Password manager, device list, staff training |
| 10 to 50 staff, client data, hybrid working | Essential controls plus access reviews and endpoint protection | Mobile device management, conditional access, phishing tests |
| Health, financial, or large-scale personal data, frequent BYOD | Managed devices or strict BYOD rules, encryption, logging, rapid offboarding | ZTNA, security monitoring, and specialist review |
A VPN suits limited access to older internal systems. ZTNA gives access to approved apps, not a whole network.
MDM can enforce encryption, screen locks, and remote removal of business data. It is particularly effective on company devices.
A VPN is a guarded tunnel, not a full security system.
| Option | Best fit | Does not solve alone |
|---|
| VPN | Legacy systems and limited remote access | Phishing, weak passwords, or missing patches |
| ZTNA | App-by-app access for hybrid teams | Poor user training or unsafe personal storage |
| MDM | Company laptops and controlled BYOD | A staff member approving a fake payment |
Manage BYOD, home Wi-Fi and shared rooms
Bring your own device (BYOD) needs written limits. Those limits must cover access, storage, and deletion of work data.
Managed company devices are safer for sensitive information. This applies where the business cannot enforce safeguards on personal devices.
Personal devices need rules as clear as company laptops.
Set rules for personal devices
Require approved apps, automatic updates, screen locks, and immediate loss reporting. Ban business files in personal email and consumer cloud drives.
Also ban local downloads and unapproved messaging apps. Remove access when employment ends.
A common case involves a leaver who keeps access to a shared folder. The business then cannot show who copied customer data.
Protect Wi-Fi and physical records
Home routers need changed admin passwords and current firmware. They also need WPA2 or WPA3 encryption.
Workers should lock screens and secure paper records. They should avoid sensitive calls where others can hear them.
A kitchen table can become an office. It is not always a private workspace.
Prove UK GDPR and insurance readiness in 90 days
Evidence of control means dated records that show security works. Keep records of MFA coverage, patch status, backup tests, and training.
Also keep a device list and access-change records. Cyber insurance may fund response, recovery, and business interruption.
Wrong answers or missing declared controls can affect cover. Read the policy terms carefully.
Insurers often ask what you can prove, not what you intended to do.
Build evidence at 30, 60 and 90 days
| Timing | Owner and effort | Evidence to retain |
|---|
| Days 1 to 30 | Director and IT lead, low cost | MFA list, device inventory, approved-app list |
| Days 31 to 60 | IT lead and managers, moderate effort | Patch report, backup restore result, training record |
| Days 61 to 90 | Director, Data Protection Officer, or adviser | Access review, incident drill, insurer questionnaire file |
Copy these three short templates
Homeworking policy: “Staff must use approved accounts and storage. They must enable MFA, lock devices, and report loss or suspicious activity immediately. They must not store business data in personal accounts.”
Remote onboarding and offboarding: “Before start, issue a device and create least-privilege accounts. Enable MFA and record training. On departure, disable accounts, recover equipment, and remove shared access.”
Ransomware playbook: “Disconnect the device. Do not delete files or pay anyone. Report to the incident lead, preserve screenshots, and call the insurer before restoring systems.”
Report qualifying UK GDPR breaches to the ICO within 72 hours where feasible.
Homeworking guidance has less value for businesses with no remote access. It also has less value for businesses with no meaningful digital data or external staff. It does not replace technical investigation after an attack. It does not replace legal advice on a data breach. Read the limits, conditions, and exclusions in your cyber insurance policy.
Cyber Essentials gives UK SMEs a useful baseline for repeatable controls. Its themes include secure settings, access control, malware protection, patching, and firewalls.
These themes closely match insurer questions. Certification does not guarantee that an incident will not happen.
It does not replace a risk assessment. Working towards it can reveal unmanaged devices, unsupported software, and broad administrator access.
Use the assessment to record remote access security decisions. Apply VPN security where older systems need network access.
Consider zero trust network access where staff need only certain cloud or internal apps. Keep policies, device reports, and records of fixes as evidence.
For UK GDPR, document a remote-working risk assessment. It should cover the type and amount of personal data.
It should also cover who can access it and where it is stored. Consider what happens if a device or account is compromised.
Set retention periods for customer files, exports, chat messages, and local downloads. Delete or securely archive data when the business purpose ends.
Check cloud supplier contracts when they process personal data. The contract must include required processor terms.
Access must stay limited to authorised staff. This is like keeping spare keys only with people who need them.
If a breach risks people’s rights and freedoms, notify the ICO within 72 hours where feasible. Tell affected people too where the risk is high.
Frequently asked questions
How do I secure a remote workforce?
Start with MFA, updates, tested backups, approved storage, and a clear reporting route. Check these controls at least every 30 to 90 days.
What are the main homeworking cyber threats?
Phishing, payment fraud, ransomware, lost devices, and unsafe file sharing are common threats. A fake supplier payment request can cause loss within minutes.
Does cyber insurance cover a data breach?
Many policies cover response, recovery, notification, and interruption costs. Cover always depends on policy terms, limits, and declared controls.
Do remote workers need a VPN?
Remote workers need a VPN only for internal systems or where a provider requires it. Cloud work often relies on MFA and conditional access instead.
Can staff work on personal laptops?
Yes, but only under a BYOD policy. The policy should require updates, locks, approved apps, and rapid access removal.
What evidence do insurers ask for?
Insurers commonly ask for MFA, backups, patching, device lists, training, and incident procedures. Keep dated records for at least the last 30 to 90 days.
Keep the controls alive after the first 90 days
Review MFA coverage, unpatched devices, backup restores, and former staff access at least quarterly. A named owner should maintain the device list, access changes, and incident log.
A control that nobody checks soon becomes only a promise.
Related sources
These articles can help you explore the topic in more depth: