TL;DR: Remote workforce security remains inconsistent, with 79% of security professionals enforcing the same controls for all roles remotely, while 52% said remote employees found workarounds and 71% cited phishing as a top threat, according to Axiad and Cybersecurity Insiders. Identity assurance now has to account for user behaviour, not just policy design.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Remote Workforce Security Survey shows access control policies providing hackers with more routes into organizations”.
By the numbers:
- More than half, 52%, of tech leaders said their remote employees had found workarounds to company security policies.
- Phishing threats, at 71%, emerged as the most significant new threat vector concerning remote work environments.
Key questions
Q: What breaks when remote teams apply the same identity controls to every role?
A: Uniform remote controls break when privileged users, standard users and unmanaged devices all receive the same access treatment.
Q: Why do contractors and other third parties increase identity risk in remote work environments?
A: Contractors often need short-term access to email, collaboration tools, and business systems, but that access is harder to govern when work is remote.
Q: How should security teams measure whether authentication controls are actually working?
A: Measure the full path, not just successful login.
Practitioner guidance
- Segment remote access by role and trust level Define separate access policies for privileged users, standard staff and unmanaged devices so remote security does not collapse into one baseline control set.
- Reduce authentication friction Rework MFA, password manager and device management flows so users can complete them reliably without creating incentives to bypass controls.
- Measure workaround behaviour Track where users bypass or delay controls, then treat those patterns as assurance failures rather than user training noise.
Bottom line: Remote workforce risk increases when organisations enforce one access model across all roles and endpoints.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Policy uniformity is now an identity control failure, not a convenience choice. When 79% of professionals apply the same controls to all remote roles, the programme stops distinguishing between low-risk users, privileged users and unmanaged devices. That erases one of the most important design assumptions in identity governance: access policy should vary with context. The implication is that remote access governance must be role-aware, not blanket-based.
A question worth separating out:
Q: What should teams do when phishing becomes the main remote access threat?
A: They should treat phishing as an identity compromise path and tighten verification, recovery and step-up access decisions around remote login flows. Education helps, but it is not enough on its own. The security model has to assume that one compromised remote account can become a route into corporate resources if authentication is weak or inconsistent.
👉 Read our full editorial: Remote workforce security survey shows identity controls breaking down