Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why does working from home increase the chance…
Cyber Security

Why does working from home increase the chance of a cybersecurity breach?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Working from home increases risk because home and guest networks are typically less controlled than corporate networks, and personal devices are often more exposed to malware and unsafe software use. When employees access sensitive applications from weaker networks or unmanaged devices, attackers get more opportunities to intercept access, exploit compromised endpoints, or abuse weak authentication. The result is a larger attack surface outside the office.

Why home networks and devices widen the attack surface

Remote work shifts trust boundaries away from managed office infrastructure. At home, the router, Wi-Fi configuration, IoT devices, shared family devices and personal software choices often sit outside corporate baselines, so the organisation inherits more uncertainty about who can observe traffic, what software is installed, and whether a device is patched. That extra uncertainty is what turns normal remote access into a broader exposure problem.

Office networks usually benefit from layered controls such as segmentation, monitoring, and centrally enforced configuration. Home setups rarely have that consistency, so the same application session may now depend on weaker perimeter controls, less reliable DNS and endpoint hygiene, and more opportunities for phishing, malware delivery or credential capture. The core issue is not simply location, it is loss of standardisation and visibility.

When access leaves the office, defenders also lose some of the signals that make abuse easier to spot, such as managed network telemetry and known device posture. A home environment can therefore make a compromise harder to distinguish from routine work, especially when the user connects through consumer-grade networks that may already be shared or poorly secured.

How breaches happen when work happens outside managed controls

Breaches usually do not occur because remote work is inherently unsafe, but because it increases the number of places where a weak link can be exploited. Common failure modes include phishing on unmanaged devices, password reuse against weak authentication, malware on a personal laptop, and insecure remote access over exposed public networks. If an attacker captures a session or token, the move from home to internal systems can be just as damaging as direct office compromise.

One practical pattern is endpoint compromise first, then access abuse. A browser extension, downloaded utility, or unsafe personal application can steal credentials or session material, then reuse that access against corporate services. Another pattern is network interception or rogue infrastructure on an untrusted Wi-Fi network, which can target users who rely on weak authentication or ignore warning signs during login. For this reason, remote work risk is often a chain of small weaknesses rather than a single dramatic flaw.

Evidence from breach analysis shows how often stolen credentials, exposed secrets, and over-privileged access become the enabling path once attackers are inside. NHIMG’s The 52 NHI breaches Report and its 52 NHI Breaches Analysis both show how compromised access material expands blast radius after initial entry.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementRemote work weakens control over secrets and session material used off-network.
NHI-03 — Privilege and Access ControlHome-based compromise becomes more damaging when remote sessions retain excessive access.
NHI-07 — Visibility and DiscoveryRemote work reduces visibility into device posture and access abuse paths.
Recommendation — Centralise and rotate exposed access material used for remote access. Reduce remote session privilege to the minimum required for the task. Monitor remote access paths for unmanaged devices and anomalous session behaviour.
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlThe breach risk rises when remote access depends on weaker authentication and access control.
DE.CM — Continuous MonitoringHome environments reduce monitoring fidelity and make compromise harder to spot.
Recommendation — Strengthen remote authentication and restrict access to approved users and devices. Continuously monitor remote sessions, endpoints and access anomalies.
CIS Controls v85 — Account ManagementRemote work increases the impact of weak account lifecycle and shared-access practices.
6 — Access Control ManagementLess controlled home access requires tighter authorization limits and device restrictions.
8 — Audit Log ManagementRemote compromise is harder to see without reliable logs from access paths and endpoints.
Recommendation — Remove stale accounts and enforce unique, accountable user access. Limit remote access to approved systems, users and device states. Collect and review logs for remote login, device and session activity.
NIST SP 800-63IAL/AAL/FAL — Identity Assurance, Authenticator Assurance and Federation AssuranceRemote access security depends on how strongly users and authenticators are established.
Recommendation — Use higher-assurance authenticators for remote access to sensitive applications.
NIST Zero Trust (SP 800-207)Policy and Continuous Verification — Continuous Verification of AccessRemote work changes the trust boundary, so access should be rechecked continuously.
Recommendation — Re-evaluate user, device and session trust before granting sensitive access.

Practitioner Guidance

What to verify: Do not treat “remote access works” as proof that the setup is acceptable. Verify device posture, MFA strength, browser and endpoint patching, and whether sensitive applications can still be reached from an unmanaged or shared machine.

Decision rule: If a user can reach production or confidential systems from a device the organisation cannot manage or inspect, treat that access path as higher risk and require tighter authentication, conditional access, or a safer endpoint model before expanding usage.

What practitioners underestimate: The real problem is often not the home network alone, but the combination of home network, personal device habits, and long-lived access sessions. That combination can make one successful phish or device compromise much more valuable to an attacker than it would be inside the office.

Practitioner takeaway: Remote work increases breach probability when it removes the controls that normally bound trust, so the security question is not whether people can work from home, but whether the access path is still observable, strongly authenticated, and limited enough to contain compromise.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org