Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Mobile Working
Governance, Ownership & Risk

Mobile Working

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Governance, Ownership & Risk

Mobile working is a work pattern where employees access business systems from different locations and devices rather than a fixed office desk. It increases flexibility and productivity, but it also raises security demands for authentication, device control, and secure access to data and applications.

What Mobile Working Means in Practice

Mobile working is not just remote access from a laptop. It is a shift in how people, apps, and data are used across cafés, homes, client sites, airports, and shared devices, which changes the trust assumptions that traditional office-centric security often relies on.

That shift matters because the business is no longer protecting a single controlled endpoint and network path. Instead, it must support varied connectivity, variable device posture, and a wider set of user behaviours without making access so permissive that security becomes fragile.

Authentication, Devices, and Access Paths

Mobile working usually depends on stronger authentication because location is no longer a reliable signal of trust. Phishing-resistant sign-in, step-up verification, and careful session handling become more important when users connect from unmanaged networks and personal devices.

Device control is equally important. A phone or laptop used for work can carry cached sessions, files, browser tokens, or corporate apps, so security has to consider whether the device is encrypted, patched, and able to enforce local protections before it touches sensitive systems.

Access paths also need to be narrower. Rather than exposing broad network reach, organisations usually want application-level access, conditional access, and segmentation that limit what a mobile worker can reach if the device, account, or connection is compromised.

Data, Applications, and User Experience

Mobile working changes how data is consumed, stored, and shared. The key question is not whether work can happen outside the office, but whether business data remains protected when it is viewed through apps, synced to endpoints, or passed between collaboration tools and cloud services.

Well-designed mobile access should minimise local data exposure and avoid unnecessary duplication across devices. That is why secure app design, strong encryption, and clear handling of download, copy, and offline modes matter so much in this pattern.

There is also a usability trade-off. If mobile security becomes too restrictive, employees find workarounds such as shadow IT, personal file-sharing tools, or unsanctioned messaging apps. The control design therefore has to balance convenience with the need to keep business data inside approved channels.

Governance and Operating Model

Mobile working is ultimately a governance problem as much as a technology one. Organisations need clear rules for who can work this way, what devices are acceptable, which data classes are permitted, and what happens when a device is lost, stolen, or no longer compliant.

It also creates cross-team dependencies between security, IT, HR, legal, and business leaders. Policies around acceptable use, monitoring, privacy, and support all affect whether mobile working is safe and sustainable rather than ad hoc.

For mobile access to stay trustworthy at scale, the operating model must treat identity, device health, and data sensitivity as linked decisions rather than separate afterthoughts. That is why modern access models often pair mobile work with NIST Privacy Framework thinking for data handling, NIST Cybersecurity Framework 2.0 for operational structure, and NIST AI Risk Management Framework only where AI-enabled productivity tools are part of the mobile workflow.

Risk and Threat Considerations

Mobile working increases exposure to account takeover, device theft, session theft, and unsafe networks because users operate outside the protections of a fixed office environment. The main risk is not mobility itself, but the larger attack surface created when trust is extended across many locations and endpoint conditions.

Failure mechanism: Weak authentication, unmanaged devices, or overly broad access can let an attacker reuse a stolen session, intercept data on insecure networks, or move from a compromised endpoint into business systems.

Impact: The result can be data exposure, unauthorized access, lateral movement, and loss of control over corporate information on endpoints that are hard to supervise continuously.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Managed Access ControlMobile working depends on limiting access based on user, device, and context.
PR.DS-01 — Data-at-Rest ProtectionMobile working increases the chance that data resides on endpoints and portable devices.
PR.PS-03 — Platform SecurityMobile working relies on hardened, patched endpoint platforms and secure configurations.
Recommendation — Use PR.AA-05 to enforce contextual access decisions for mobile users and devices. Apply PR.DS-01 to encrypt sensitive data stored or cached on mobile endpoints. Use PR.PS-03 to baseline and harden mobile endpoints before allowing business access.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Mobile working requires strong user authentication before business access is granted.
AC-6 — Least PrivilegeMobile working should limit what a user can reach from outside the office.
SC-13 — Cryptographic ProtectionMobile working depends on protecting data in transit across untrusted networks.
Recommendation — Use IA-2 to require strong authentication for employees accessing systems remotely. Apply AC-6 to restrict mobile users to only the resources they need. Use SC-13 to protect mobile sessions and traffic with approved cryptography.
ISO/IEC 27001:2022A.8.1 — User Endpoint DevicesMobile working directly depends on the security of laptops and phones used outside the office.
A.5.15 — Access ControlMobile working requires policy-driven access decisions across locations and devices.
A.8.24 — Use of CryptographyMobile working needs cryptography to protect data and sessions over public networks.
Recommendation — Apply A.8.1 to control and secure endpoints used for mobile work. Use A.5.15 to define and enforce access rules for mobile users. Apply A.8.24 to secure mobile data exchanges with approved cryptography.

Practitioner Guidance

What to watch for: The most useful control signal is whether mobile access decisions are tied to device state, user identity, and data sensitivity at the moment of access. If those checks are missing, mobile working usually becomes a convenience layer over weak trust assumptions rather than a secure operating pattern.

Practitioner takeaway: Treat mobile working as a security architecture choice, not only a workplace policy, and make sure the controls match the degree of data sensitivity employees can reach from outside the office.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org