By NHI Mgmt Group Editorial TeamBased on Axiad: “Remote Workforce Security Survey shows access control policies providing hackers with more routes into organizations” (September 16, 2025)

TL;DR: Remote workforce security remains inconsistent, with 79% of security professionals enforcing the same controls for all roles remotely, while 52% said remote employees found workarounds and 71% cited phishing as a top threat, according to Axiad and Cybersecurity Insiders. Identity assurance now has to account for user behaviour, not just policy design.


At a glance

What this is: This survey shows that remote workforce security controls are breaking down because organisations apply the same policies across roles while employees work around authentication and device controls.

Why it matters: It matters because identity teams cannot protect remote access with one-size-fits-all policy design when users, devices and threats differ across roles and working patterns.

By the numbers:

  • More than half, 52%, of tech leaders said their remote employees had found workarounds to company security policies.
  • Phishing threats, at 71%, emerged as the most significant new threat vector concerning remote work environments.

Context

Remote workforce security is the problem of controlling access, authentication and device posture when users no longer sit inside a trusted office perimeter. The article argues that remote work exposed a gap between policy design and actual user behaviour, especially where MFA, mobile device management and password managers become friction points.

The identity governance issue is not simply more remote access. It is that remote access policies are often applied uniformly even when roles, data sensitivity and device trust differ, which weakens assurance and creates a larger attack surface for phishing, malware and privilege misuse.


Key questions

Q: What breaks when remote teams apply the same identity controls to every role?

A: Uniform remote controls break when privileged users, standard users and unmanaged devices all receive the same access treatment. The result is policy that looks consistent but fails to reflect real risk, so users either work around controls or remain overexposed. Effective remote identity governance depends on differentiating access by role, device trust and data sensitivity.

Q: Why do contractors and other third parties increase identity risk in remote work environments?

A: Contractors often need short-term access to email, collaboration tools, and business systems, but that access is harder to govern when work is remote. If credentials or one-time codes are shared, the organisation may lose assurance about who is actually using them. The risk grows when subcontractors are never vetted as carefully as the original contractor.

Q: How should security teams measure whether authentication controls are actually working?

A: Measure the full path, not just successful login. Teams should track completion rates, latency, recovery effort, suspicious attempts, and downstream fraud or support load. For NHIs, add provisioning, rotation, revocation, and offboarding completion. If the metric does not change a control decision, it is not yet useful for governance.

Q: What should teams do when phishing becomes the main remote access threat?

A: They should treat phishing as an identity compromise path and tighten verification, recovery and step-up access decisions around remote login flows. Education helps, but it is not enough on its own. The security model has to assume that one compromised remote account can become a route into corporate resources if authentication is weak or inconsistent.


Technical breakdown

Why uniform remote access controls fail

Uniform controls assume that every remote user presents the same risk, uses the same device posture and needs the same access path. In practice, remote work mixes corporate-managed endpoints, personal devices, privileged users and casual users, so a single control set creates blind spots. When MFA, MDM and password managers are treated as one-size-fits-all requirements, users often route around them, and the security model measures policy compliance instead of effective assurance.

Practical implication: segment remote access policy by role, device trust and data sensitivity instead of enforcing the same control set everywhere.

Authentication friction and user workarounds

Authentication fails when the user experience is so difficult that people choose shortcuts. The article links resistance to MFA, mobile device management and password managers to workaround behaviour, which means the control may exist on paper but not in practice. This is a classic identity governance failure: the organisation can describe the policy, but it cannot guarantee the user follows it consistently across every application and device.

Practical implication: measure real authentication completion and workaround rates, not just policy deployment counts.

Remote phishing changes the identity risk model

Remote phishing is more effective when workers rely on asynchronous communication, cloud access and multiple endpoints outside supervised office conditions. Phishing is not just a malware delivery path here; it is an identity compromise path that targets authentication decisions and recovery workflows. Once a remote account is compromised, the attacker gains a broader route into corporate resources because the perimeter has already dissolved.

Practical implication: treat phishing resistance, recovery and step-up verification as core access controls for remote identity programmes.


Threat narrative

Attacker objective: The attacker aims to turn one compromised remote identity into access to corporate resources and confidential data.

  1. Entry begins when a remote worker is targeted through phishing, the article's top threat vector, rather than through a defended office perimeter.
  2. Credential or session compromise is amplified when employees bypass MFA, mobile device management or password managers, because the attacker can exploit weaker authentication behaviour.
  3. Escalation occurs as the compromised remote account becomes a route into corporate resources and confidential data, especially where broad access policies are applied uniformly.
  4. Impact is the increased likelihood that hackers can reach sensitive systems and data through one remote worker's system, with remote workarounds widening the blast radius.
  • Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Policy uniformity is now an identity control failure, not a convenience choice. When 79% of professionals apply the same controls to all remote roles, the programme stops distinguishing between low-risk users, privileged users and unmanaged devices. That erases one of the most important design assumptions in identity governance: access policy should vary with context. The implication is that remote access governance must be role-aware, not blanket-based.

Workarounds are evidence that authentication design has lost operational authority. The article's 52% workaround figure shows that users are not merely resisting policy, they are revealing where policy friction exceeds acceptable workflow cost. When MFA, MDM or password managers are bypassed, the control exists only nominally. The practitioner lesson is that enforcement quality matters more than control presence.

Phishing has become a remote identity problem before it is a malware problem. With 71% citing phishing as the leading threat, the attack path now starts at identity verification and behavioural deception, then moves into resource access. That places phishing resilience, recovery controls and user verification discipline inside the identity programme, not only the SOC. Teams should treat remote identity compromise as an access governance issue.

Remote workforce security needs an assurance model, not a policy library. Axiad's survey points to a governance gap where organisations describe controls broadly but cannot assure how those controls behave across varied remote conditions. The better lens is whether authentication, device posture and access scope together reduce exploitability. Practitioners should use that lens to decide which controls deserve tighter enforcement, and where exceptions are unavoidable.

What this signals

Role-aware remote access is the next governance requirement. The article shows that remote work breaks the old assumption that one policy can safely cover every user. Security teams need to align access, authentication strength and device trust to the actual risk presented by the user and the endpoint.

Identity assurance must now account for human behaviour, not just technical control design. When users route around MFA or device management, the control stack has failed operationally even if it exists in architecture diagrams. That makes user friction a governance signal, not just a UX complaint.


For practitioners

  • Segment remote access by role and trust level Define separate access policies for privileged users, standard staff and unmanaged devices so remote security does not collapse into one baseline control set.
  • Reduce authentication friction Rework MFA, password manager and device management flows so users can complete them reliably without creating incentives to bypass controls.
  • Measure workaround behaviour Track where users bypass or delay controls, then treat those patterns as assurance failures rather than user training noise.
  • Harden phishing-resilient access Pair phishing education with stronger identity verification and recovery controls for remote access paths that can be reached outside the office.

Key takeaways

  • Remote workforce risk increases when organisations enforce one access model across all roles and endpoints.
  • The most important evidence in the survey is behavioural, with users finding workarounds and attackers focusing on phishing.
  • Teams should redesign remote access around role, device trust and authentication assurance rather than assuming one policy fits all.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationRemote access weakness here is driven by authentication friction and user bypass behaviour.
NHI-05 — Overprivileged NHIRemote workers given uniform access treatment can end up effectively overexposed across roles and data sets.
Recommendation — Reduce insecure authentication paths by tightening remote login flows and eliminating easy bypasses. Limit access scope by role and device trust so remote users do not inherit unnecessary privileges.
NIST SP 800-63SP 800-63B — AuthenticationThe article centres on authentication reliability for distributed users.
Recommendation — Apply SP 800-63B to strengthen remote authentication and reduce reliance on fragile user workarounds.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsRemote workforce policy depends on correct access assignment and enforcement across roles.
Recommendation — Align remote entitlements to PR.AA-05 so access reflects role and context instead of one uniform baseline.
CIS Controls v8CIS-5 — Account ManagementThe report is about managing distributed user access and the controls that govern it.
Recommendation — Use CIS-5 to review account access, remove excessive permissions and detect bypass-prone remote access patterns.

Key terms

  • Remote Access Assurance: Remote access assurance is the degree to which an organisation can trust that a user, device and session are authenticated and governed as intended outside the office perimeter. It combines identity proofing, authentication strength, device posture and policy enforcement into one operational measure.
  • Security Workaround: A security workaround is an informal method people use to get work done when approved access is too slow or inconvenient. Examples include shadow accounts, shared credentials, and unmanaged tools. Workarounds usually emerge from process failure, and they create blind spots that make governance, monitoring, and incident response harder.
  • Role-Aware Access Control: Role-aware access control adjusts authentication and entitlement decisions based on the sensitivity of the role, device and resource. For remote work, it prevents the common failure mode where all users receive the same security treatment even though their risk and privilege profiles differ materially.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or NHI governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org