Working from home increases risk because home and guest networks are typically less controlled than corporate networks, and personal devices are often more exposed to malware and unsafe software use. When employees access sensitive applications from weaker networks or unmanaged devices, attackers get more opportunities to intercept access, exploit compromised endpoints, or abuse weak authentication. The result is a larger attack surface outside the office.
Why home networks and devices widen the attack surface
Remote work shifts trust boundaries away from managed office infrastructure. At home, the router, Wi-Fi configuration, IoT devices, shared family devices and personal software choices often sit outside corporate baselines, so the organisation inherits more uncertainty about who can observe traffic, what software is installed, and whether a device is patched. That extra uncertainty is what turns normal remote access into a broader exposure problem.
Office networks usually benefit from layered controls such as segmentation, monitoring, and centrally enforced configuration. Home setups rarely have that consistency, so the same application session may now depend on weaker perimeter controls, less reliable DNS and endpoint hygiene, and more opportunities for phishing, malware delivery or credential capture. The core issue is not simply location, it is loss of standardisation and visibility.
When access leaves the office, defenders also lose some of the signals that make abuse easier to spot, such as managed network telemetry and known device posture. A home environment can therefore make a compromise harder to distinguish from routine work, especially when the user connects through consumer-grade networks that may already be shared or poorly secured.
How breaches happen when work happens outside managed controls
Breaches usually do not occur because remote work is inherently unsafe, but because it increases the number of places where a weak link can be exploited. Common failure modes include phishing on unmanaged devices, password reuse against weak authentication, malware on a personal laptop, and insecure remote access over exposed public networks. If an attacker captures a session or token, the move from home to internal systems can be just as damaging as direct office compromise.
One practical pattern is endpoint compromise first, then access abuse. A browser extension, downloaded utility, or unsafe personal application can steal credentials or session material, then reuse that access against corporate services. Another pattern is network interception or rogue infrastructure on an untrusted Wi-Fi network, which can target users who rely on weak authentication or ignore warning signs during login. For this reason, remote work risk is often a chain of small weaknesses rather than a single dramatic flaw.
Evidence from breach analysis shows how often stolen credentials, exposed secrets, and over-privileged access become the enabling path once attackers are inside. NHIMG’s The 52 NHI breaches Report and its 52 NHI Breaches Analysis both show how compromised access material expands blast radius after initial entry.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Remote work weakens control over secrets and session material used off-network. |
| NHI-03 — Privilege and Access Control | Home-based compromise becomes more damaging when remote sessions retain excessive access. | |
| NHI-07 — Visibility and Discovery | Remote work reduces visibility into device posture and access abuse paths. | |
| Recommendation — Centralise and rotate exposed access material used for remote access. Reduce remote session privilege to the minimum required for the task. Monitor remote access paths for unmanaged devices and anomalous session behaviour. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | The breach risk rises when remote access depends on weaker authentication and access control. |
| DE.CM — Continuous Monitoring | Home environments reduce monitoring fidelity and make compromise harder to spot. | |
| Recommendation — Strengthen remote authentication and restrict access to approved users and devices. Continuously monitor remote sessions, endpoints and access anomalies. | ||
| CIS Controls v8 | 5 — Account Management | Remote work increases the impact of weak account lifecycle and shared-access practices. |
| 6 — Access Control Management | Less controlled home access requires tighter authorization limits and device restrictions. | |
| 8 — Audit Log Management | Remote compromise is harder to see without reliable logs from access paths and endpoints. | |
| Recommendation — Remove stale accounts and enforce unique, accountable user access. Limit remote access to approved systems, users and device states. Collect and review logs for remote login, device and session activity. | ||
| NIST SP 800-63 | IAL/AAL/FAL — Identity Assurance, Authenticator Assurance and Federation Assurance | Remote access security depends on how strongly users and authenticators are established. |
| Recommendation — Use higher-assurance authenticators for remote access to sensitive applications. | ||
| NIST Zero Trust (SP 800-207) | Policy and Continuous Verification — Continuous Verification of Access | Remote work changes the trust boundary, so access should be rechecked continuously. |
| Recommendation — Re-evaluate user, device and session trust before granting sensitive access. | ||
Practitioner Guidance
What to verify: Do not treat “remote access works” as proof that the setup is acceptable. Verify device posture, MFA strength, browser and endpoint patching, and whether sensitive applications can still be reached from an unmanaged or shared machine.
Decision rule: If a user can reach production or confidential systems from a device the organisation cannot manage or inspect, treat that access path as higher risk and require tighter authentication, conditional access, or a safer endpoint model before expanding usage.
What practitioners underestimate: The real problem is often not the home network alone, but the combination of home network, personal device habits, and long-lived access sessions. That combination can make one successful phish or device compromise much more valuable to an attacker than it would be inside the office.
Practitioner takeaway: Remote work increases breach probability when it removes the controls that normally bound trust, so the security question is not whether people can work from home, but whether the access path is still observable, strongly authenticated, and limited enough to contain compromise.
Related resources from NHI Mgmt Group
- Why do third-party dependencies increase the chance of a data breach?
- Why does weak board-level cybersecurity oversight increase legal and business risk after a data breach?
- Why do remote access environments increase breach risk when users rely on home networks, VPNs, and third-party connectivity?
- Why does delayed EDR tuning increase the chance of a real breach?