Join our Newsletter — 33% off our NHI Course

Remote work security habits: what IAM teams still miss

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Credential misuse drives 80% of security breaches, while more than 40% of companies had not provided remote-work training and 32% of employees had received none in six months, according to Axiad. The identity lesson is that distributed work turns everyday user behaviour, device choice, and credential handling into governance controls, not just awareness issues.

Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “5 Tips to Take Control of Your Home Cybersecurity”.

Key questions

Q: How should security teams reduce identity risk in remote work environments?

A: Security teams should combine stronger authentication with device posture, access segmentation, and fast response to suspicious sessions.

Q: Why does remote work increase the risk of phishing and data compromise during a crisis?

A: Remote work increases risk because attackers exploit urgency, distraction, and unfamiliar routines to make malicious messages seem legitimate.

Q: What breaks when employees use the same device for personal browsing and corporate access?

A: The organisation loses the separation that makes identity trust manageable.

Practitioner guidance

  • Enforce screen-lock discipline Require automatic device lock after inactivity and reinforce the habit of locking laptops and mobiles whenever users leave their workspace, even briefly.
  • Separate managed and personal devices Limit work access to company-issued endpoints where approved apps, security tools and telemetry can be enforced consistently.
  • Make email verification a default habit Train staff to validate sender addresses, confirm unusual requests through a separate channel and treat urgent credential or data requests as suspicious until verified.

Bottom line: Remote work shifts identity risk into everyday behaviour, where screen locks, device choice and message verification become part of security control.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Remote work has turned human routine into an identity control. The article shows that security outcomes depend on whether users lock screens, hide sensitive information and pause before sharing data. Those habits are not peripheral to IAM; they are the behavioural layer that determines whether identity assurance holds outside the office. Practitioners should treat user routine as part of access governance, because unmanaged behaviour can defeat otherwise sound policy.

A question worth separating out:

Q: What should teams do when remote workers have not received recent security training?

A: Treat the training gap as an access-risk issue, not a communication issue. If users have not recently been trained on phishing, credential handling and remote-work policy, their ability to apply the right judgement drops quickly. Teams should make completion and acknowledgement part of access governance so policy updates and user behaviour stay in sync.

👉 Read our full editorial: Remote worker identity risk is still driven by human habits


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.