Join our Newsletter — 33% off our NHI Course

How should organisations secure remote workers before a rapid shift to home working?

Start by treating remote work as a security change, not just an access change. Enforce full disk encryption, MFA, and unique credentials on laptops and remote logins. Limit admin rights, require screen locking, and make VPN use mandatory for corporate access. These controls reduce the chance that a lost device, credential theft, or home network exposure becomes an enterprise breach.

Why the first move is treating home working as a control change

A rapid move to home working changes the trust boundary, so the right response is to re-baseline how endpoints, credentials, and access paths are handled. The main goal is to reduce the blast radius of a lost laptop, a reused password, or an exposed home network without slowing routine work to a halt.

That is why the initial control set should focus on device protection, strong authentication, privilege restriction, and managed remote access rather than one-off exceptions for individual users. If the organisation already has gaps in endpoint hardening, account hygiene, or VPN enforcement, the remote-work shift tends to expose them quickly.

remote working also pushes risk out of the office and into environments the company does not directly control. A secure baseline therefore needs to assume unattended devices, mixed-use networks, and weaker physical oversight, then compensate with technical controls that still hold when the user is outside the corporate perimeter.

Which controls matter most on day one?

The most effective first-line controls are the ones that protect both the device and the login path. Full disk encryption reduces the value of a lost or stolen laptop, multi-factor authentication makes stolen passwords less useful, and unique credentials prevent shared accounts from turning a single compromise into broad access. NIST SP 800-63 Digital Identity Guidelines is useful here because it explains stronger authentication choices and why phishing-resistant methods improve remote access assurance.

Privilege control is just as important as authentication. Remove local admin rights unless a genuine business need exists, because admin access turns ordinary malware or user error into a system-wide issue. Screen locking, secure configuration, and mandatory VPN for corporate access all help reduce exposure when users step away from devices or work across less trusted networks.

These controls work best when they are applied consistently rather than as optional guidance. Remote work security usually fails at the edges, where one user keeps admin rights, another reuses a password, or a third reaches internal resources without the same VPN and endpoint requirements as everyone else.

How should organisations keep the policy workable after the rollout?

Usability matters because controls that are too hard to follow quickly get bypassed. The practical aim is to make the secure path the default path: managed devices, centrally enforced encryption, company-approved authentication, and remote access through a small number of well-monitored channels. NCSC UK Advice and Guidance is a solid reference point for this kind of operational remote-access hardening.

It also helps to define what is non-negotiable before people leave the office. If a device is not encrypted, if credentials are shared, or if VPN access is not mandatory for sensitive systems, the safest response is to block access rather than hope users self-correct later. This is a policy enforcement problem as much as a technology problem.

Finally, organisations should think in terms of supportability. The more exceptions they create for urgent home-working access, the harder it becomes to know which users are actually covered by the baseline. A short list of approved configurations, centrally managed by IT and security, is much easier to defend than a long list of temporary workarounds.

Risk and Threat Considerations

Remote work increases the chance that a single weak point becomes an enterprise incident. The most common failure pattern is not sophisticated exploitation, but loss or theft of a device, credential capture through phishing or reuse, and exposure through an unmanaged home network or router.

Failure mechanism: If disk encryption, strong authentication, and privilege restriction are inconsistent, an attacker or opportunistic thief can use a lost laptop or stolen password to reach business data or internal systems with very little resistance.

Impact: The result can be account takeover, unauthorised access, malware spread, or a broader breach that starts with one remote user but reaches shared services and corporate data.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Remote worker access depends on strong user authentication.
IA-5 — Authenticator Management The answer depends on unique credentials and credential hygiene.
AC-6 — Least Privilege Removing admin rights is central to reducing remote-work blast radius.
Recommendation — Enforce strong user authentication for remote employee access. Manage authenticators tightly and rotate or revoke compromised credentials quickly. Apply least privilege and remove unnecessary administrative access.
ISO/IEC 27001:2022 A.8.1 — User endpoint devices Home-working security depends on securing laptops and other endpoints.
A.8.5 — Secure authentication MFA and unique credentials are core to secure remote logins.
A.8.20 — Network security VPN use and home-network exposure are central to the question.
Recommendation — Harden and manage endpoint devices used for remote work. Require secure authentication for remote access and corporate services. Protect remote connections with network security controls and approved access paths.

Practitioner Guidance

What to prioritise: Start with the controls that reduce immediate exposure across the most users, which usually means encryption, MFA, and removal of unnecessary local admin rights before fine-tuning peripheral convenience features.

What to verify: Confirm that the policy is enforced technically, not just documented. A useful test is whether a non-compliant laptop can still reach critical services, because if it can, the baseline is not really in place.

Common mistake: Treating VPN as the only remote-work control. VPN matters, but it does not compensate for weak endpoints, shared passwords, or excessive privilege on the device itself.

Practitioner takeaway: The quickest way to make rapid home working safer is to narrow what a single compromise can do, then make the secure configuration the easiest configuration for every user.