Join our Newsletter — 33% off our NHI Course

Why do office-based employees create more data exfiltration risk than remote workers in some organisations?

Office presence can create a false sense of trust and weaker scrutiny over everyday behaviour. In this research, office-based workers were more likely to exfiltrate sensitive data, and offsite office workers were even riskier than when onsite. That pattern suggests location alone is a poor control proxy, especially when access, movement, and sharing habits change.

Why the office setting can inflate exfiltration risk

Office presence changes the social and operational environment around data handling. People move between desks, meeting rooms, printers, hot desks and shared screens, and those transitions can normalise copying, forwarding or briefly exposing information without triggering much attention. In practice, the risk is often less about the building itself and more about weaker behavioural scrutiny around ordinary work patterns.

A key issue is that organisations sometimes treat “onsite” as a proxy for trust. That can reduce review of who is seeing data, where it is being moved, and whether storage or transfer is appropriate for the sensitivity of the material. When the control model assumes the office is inherently safer, everyday leakage paths can be missed.

Research on identity exposure and secret handling reinforces how often mundane workflows become the weak point. NHIMG’s Ultimate Guide to Non-Human Identities notes that 96% of organisations store secrets outside secrets managers and that 79% have experienced secrets leaks, which is a reminder that routine handling errors scale quickly when trust is informal.

Why office behaviour can be riskier than remote work in some organisations

Remote work often forces more deliberate, recorded, and tool-mediated behaviour. People are more likely to use approved collaboration tools, digital approvals, and auditable file transfers because they are not physically co-located with colleagues, printers, whiteboards, or unattended documents. That extra friction can reduce casual exfiltration opportunities even when remote work feels less controlled.

By contrast, an office can create hidden opportunities for quick copying, photographing, printing, or passing data through less monitored channels. The office also introduces access asymmetry, because a worker may be physically near sensitive systems or conversations without needing the same level of digital evidence that remote activity would generate.

This is why location is a weak control variable. A person working offsite in an office, for example, may already be operating outside the strongest direct supervision while still benefiting from the convenience and informality of the office environment. The result is a hybrid risk profile that does not align neatly with “onsite equals safe.”

Well-documented breach patterns show how ordinary access paths can become exfiltration paths once trust is misplaced. NHIMG’s Sisense breach and Schneider Electric credentials breach both illustrate that once access is available, data movement can follow quickly if scrutiny is weak.

What practitioners should change in access and monitoring

The practical response is to control behaviour and data movement, not geography. If you want to reduce exfiltration risk, focus on where sensitive data can be opened, copied, shared, printed, or exported, and make those actions visible regardless of whether the worker is in the office or at home. The control question should be “what is the data doing?” rather than “where is the person sitting?”

  • What to verify: Which office workflows bypass logging, approval, or data loss controls because they are assumed to be low risk.
  • What to measure: The rate of sensitive exports, prints, and cross-environment file transfers by location and by role, not just by device posture.
  • Common mistake: Giving onsite users broader handling latitude simply because they are physically present and easy to reach.

Practitioner takeaway: Treat office presence as a human-factor risk amplifier, not a control. The safer model is consistent policy enforcement, because exfiltration risk usually comes from convenience, weak supervision, and poor data-flow visibility rather than from the office itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS 8 — Audit Log Management Logging data access and transfer helps spot exfiltration regardless of work location.
CIS 3 — Data Protection Office workflows can leak data through copying, printing, and sharing without consistent protections.
Recommendation — Log sensitive file access and transfer events to detect unusual exfiltration patterns. Apply data protection controls to limit export, copy, print, and sharing paths.
NIST CSF 2.0 PR.AC — Access Control Location is a weak proxy, so access should be governed by role and need rather than office presence.
Recommendation — Enforce access based on least privilege and need-to-know, not physical location.