Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do when employees need to…
Governance, Ownership & Risk

What should organisations do when employees need to work on company data while travelling?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Organisations should publish clear travel and mobile work rules before employees leave, including when to use company devices, how to connect securely, and what to do if a device is lost or stolen. If formal guidance does not exist, managers and security teams should provide it. Consistent policy reduces ad hoc decisions that increase risk during travel.

What organisations should put in place before employees travel

Travel creates a predictable gap between policy and reality: people will work from airports, hotels, public Wi-Fi, client sites, and transit hubs, often under time pressure. The right response is to make the travel rules explicit before departure, so employees know which devices, connections, and approval paths are acceptable without improvising in the moment.

That policy should cover device choice, secure connection methods, approved storage and sharing options, and the process for reporting loss, theft, or suspected compromise. For broader access and device-hardening guidance, organisations often anchor these requirements in a baseline control set such as NIST SP 800-53 Rev 5 Security and Privacy Controls and CIS Benchmarks.

Travel policy also needs an ownership model. If security, IT, and managers each assume the other team has already explained the rules, employees default to convenience, and the organisation ends up with inconsistent decisions about VPN use, hotspot use, data download, and whether local copies are allowed. A short, readable travel policy is usually more effective than a dense acceptable-use document that no one consults on the road.

How to keep company data usable without making travel unsafe

The practical goal is not to stop remote work, but to keep data access bounded when people are outside normal office controls. That usually means using managed company devices, enforcing strong authentication, keeping patching and endpoint protections current, and ensuring that sensitive data stays inside approved services rather than being copied into personal apps or unmanaged storage.

For the connection layer, the safest pattern is to require encrypted access to internal resources and to avoid treating public networks as trustworthy. When organisations formalise that approach, they often map it to a zero trust model, where device state, identity, and access context matter more than the network location itself. A useful reference point is NIST SP 800-207 Zero Trust Architecture, which fits travel scenarios well because the user is often outside the corporate perimeter.

Travel is also where data handling discipline matters most. If staff need offline access, the organisation should define which datasets may be cached locally, how long they may remain offline, and what encryption or remote wipe capability must be present. The less ambiguity there is about local storage, the fewer opportunities employees have to create uncontrolled copies of company data on devices they may not be able to protect physically.

What to do when a device is lost, stolen, or exposed while travelling

Loss and theft are among the highest-risk travel events because the issue is not just the device itself, but whatever sessions, cached files, tokens, and access paths it may carry. Organisations should predefine the response so employees know exactly when to report, who to contact, and what actions the security or IT team will take to contain the exposure.

That response should include rapid account review, device isolation, credential reset where appropriate, and a decision on whether the incident is limited to the endpoint or may also affect sensitive data. The requirement is not only to replace hardware quickly, but to cut off lingering access before a lost laptop or phone becomes a persistent entry point. Strong authentication guidance such as NIST SP 800-63 Digital Identity Guidelines helps reduce the value of a stolen password alone, while endpoint control baselines help limit what an exposed device can reveal.

A second issue is reporting speed. If employees are unsure whether a device loss is “serious enough” to escalate, they often wait too long, and delay is what turns a recoverable event into a larger exposure. Clear threshold-based reporting rules, ideally with a 24/7 contact route for travellers, are more important than long after-the-fact investigations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-01 — Identity Management, Authentication, and Access ControlTravel work depends on controlled user access from outside normal boundaries.
Recommendation — Enforce approved authentication and access rules for remote work on travel.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Travel access should rely on strong user authentication before data access.
AC-19 — Access Control for Mobile DevicesMobile work on the road needs explicit controls for device use and protection.
Recommendation — Require strong authentication before granting company data access while travelling. Apply mobile-device access controls to limit data exposure during travel.
ISO/IEC 27001:2022A.8.1 — User endpoint devicesTravel work depends on secure use of laptops and phones outside office premises.
A.5.10 — Acceptable use of information and other associated assetsTravel rules are fundamentally an acceptable-use expectation for company data.
Recommendation — Set endpoint protection requirements for devices used while travelling. Define acceptable-use rules for working on company data during travel.

Practitioner Guidance

What to prioritise: Put travel rules in front of the traveller before departure, not after the first incident. The highest-value controls are the ones that remove ambiguity about approved devices, approved networks, and approved data handling.

What to verify: Confirm that mobile work guidance is actually operational, meaning it covers managed devices, remote access, offline storage, loss reporting, and emergency contact points. If any of those are missing, employees will fill the gap themselves, usually in the least secure way.

Decision rule: If the employee must access sensitive company data, require a managed device and an approved secure connection; if the task can be done without local data copy, keep it that way. The goal is to reduce exposure, not just to document it.

Practitioner takeaway: The most effective travel control is a pre-departure policy that reduces improvisation, because travel risk usually comes from inconsistent judgment under pressure rather than from travel itself.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org