Remote work moved the corporate network boundary from a company’s building to every employee’s home office, coffee shop, and hotel room — and most home environments weren’t built to corporate security standards. Remote work security addresses the specific vulnerabilities this shift created: unsecured home networks, personal devices with mixed personal and professional use, public WiFi, distracted environments where devices get left unlocked, and blurred personal-professional account boundaries. You’ll find the complete rundown in our Complete Guide to Online Security and Privacy.
The threat model differs from office-based work in specific ways. In an office, the corporate network provides firewall protection, IT manages device security, and physical access is controlled. At home or in public, none of these apply by default. Remote work security means applying the controls that corporate infrastructure previously provided — or ensuring the employer’s tools provide them and are active before any work begins.
Home office configuration — the network foundation
Remote work security at home starts with the network all work traffic flows through. A home router with default credentials, outdated firmware, and WPA2-TKIP encryption is a significantly weaker perimeter than the corporate firewall a work device previously sat behind.
Apply the home network security configuration:
- Change the router admin password from the factory default
- Update router firmware (admin panel → Advanced/Firmware → check for updates)
- Enable WPA3 or WPA2-AES (not TKIP)
- Create a guest network for IoT devices — smart TVs, speakers, cameras — separate from the primary network where work devices connect
- Disable WPS (WiFi Protected Setup) — it has a known PIN brute-force vulnerability
Our guide on securing your home WiFi network covers the complete router configuration for the strongest available home network security.
Work devices: employer-provided devices typically come with MDM (Mobile Device Management) software that enforces encryption, screen lock, remote wipe, and application controls — configured by IT and not to be disabled. Your contribution on employer devices is mostly additive: use the corporate VPN whenever required, don’t install personal applications on work devices, and maintain a clean separation between work and personal activity.
Personal devices used for work (BYOD): need OS-level security matching work devices — full-disk encryption, strong screen lock, current OS version. Use dedicated browser profiles (Chrome’s multi-profile system or Firefox’s profile manager) to separate work browsing from personal: different cookies, history, and saved credentials, limiting the blast radius if either context is compromised.
Essential remote work security tools
- Corporate VPN (employer-provided): routes all work traffic through the company’s network, encrypting the connection from home or public networks and providing the company’s firewall protection. Connect to the corporate VPN before accessing any work systems. Remote work security is significantly weaker without the VPN active. If the VPN significantly degrades performance for work tasks, raising a split-tunnelling configuration request with IT is the correct escalation — not disabling the VPN.
- Personal VPN (for non-corporate devices on public WiFi): when using a personal device on public WiFi for work-adjacent tasks — checking work email on a phone in an airport — a personal VPN encrypts traffic the corporate VPN doesn’t cover. Mullvad, ProtonVPN, and ExpressVPN are established choices.
- Password manager: all work credentials — applications, internal tools, client systems — should be in the password manager with unique generated passwords. Remote work security is undermined when credentials are written in notes, shared over messaging apps, or reused across systems.
- Multi-factor authentication on all work accounts: remote work expands the credential phishing attack surface because corporate credentials are used from many different IP addresses and devices, making IP-based anomaly detection less effective. MFA compensates for this reduced contextual verification. Every corporate account should have MFA enabled.
- Screen lock with immediate timeout (1–2 minutes): remote environments include more uncontrolled access scenarios than offices — household members, visitors, public spaces where a moment of inattention leaves a device accessible. Screen lock is more important at home than in the office precisely because physical access controls are absent.
- Encrypted communication tools: work communication should use encrypted channels — corporate email (TLS in transit), video calling through employer-provided tools, and instant messaging through corporate communication platforms rather than personal SMS for work-sensitive discussions.
Public networks and travel — heightened vigilance required
Coffee shops, airports, hotel rooms, and other public locations require heightened remote work security compared to the home office. The risks — evil twin networks, shoulder surfing, opportunistic device theft, network eavesdropping — are all more acute in public.
Public network remote work security checklist:
- Connect to the corporate VPN or personal VPN before any work activity
- Set the device network profile to “Public” (Windows: Settings → Network → the connected WiFi → Network profile → Public) — restricts inbound connections and disables network discovery
- Verify the WiFi SSID with staff rather than assuming the visible network is legitimate — evil twin attacks use the same name as the legitimate network
- Use a privacy screen filter for work involving sensitive content visible on screen
- Use headphones rather than speaker output for video calls — prevents conversation content from being overheard
- Never leave the device unattended in a public space, even briefly
Our guide on using public WiFi safely provides the complete public network security checklist and VPN connection sequence.
Hotel networks introduce specific considerations. Hotel WiFi often routes through equipment with limited guest isolation, and hotel networks are frequently targeted because they concentrate business travellers with valuable credentials. For sensitive work in hotels: use mobile data (cellular hotspot) rather than hotel WiFi for work systems requiring the highest security. The speed trade-off is worthwhile for the threat reduction. If hotel WiFi must be used: corporate VPN before any work activity, and avoid accessing financial systems or entering new payment credentials on the hotel network.
Home vs office vs public — security comparison
| Security factor | Corporate office | Home office | Public (café, airport) |
| Network security | Corporate firewall, managed | Home router — configurable but not managed | Untrusted, shared, potentially hostile |
| Physical security | Building access control | Household access only | Open public space |
| Device management | IT-managed (typically) | IT-managed + personal separation | Device must be treated as lost/stolen risk |
| VPN requirement | Internal access, usually not required | Required for corporate systems | Required before any activity |
| Screen lock timing | 5–10 minutes acceptable | 2–5 minutes recommended | Immediate (30 seconds–1 minute) |
| Shoulder surfing risk | Low (known colleagues) | Low (household members) | High — privacy screen filter recommended |
Video call security — overlooked but important
Video calls are the dominant communication medium for remote work, and they introduce specific security and privacy concerns that most security guidance doesn’t address:
- Background visual privacy: household members, physical documents visible behind you, and environmental details revealing your home’s layout or location are visible to all participants — and in recorded calls, to anyone who later accesses the recording. Blurred or virtual backgrounds are the simplest solution.
- Background audio: household conversations audible in the background may reveal personal information or sensitive family situations to meeting participants. A door that closes provides the separation that matters here.
- Screen sharing discipline: before any screen share, minimise or close all applications not relevant to the meeting topic, disable notification previews (these can show personal message previews during shared presentations), and confirm no sensitive content is visible. Share a specific application window rather than the entire desktop when possible — this limits what participants can see to only the intended content.
- Recording and transcription: more video meetings are being automatically transcribed and recorded with AI tools. If a meeting is being recorded, treat everything said as potentially persistent. Sensitive information that wouldn’t be shared in a written email shouldn’t be shared verbally in a recorded call.
Remote work offboarding — the transition that creates the most risk
When a remote work arrangement ends — whether through resignation, redundancy, or contract completion — remote work security requires deliberate offboarding actions. The majority of remote work security incidents happen at transition points, not during stable ongoing work where habits are established.
- Return or wipe employer devices according to the company’s offboarding process
- Revoke all active sessions for corporate accounts
- Remove corporate account email profiles from personal devices
- Delete corporate apps that accessed sensitive data
- If personal accounts were used for any work-adjacent tasks: review and change passwords for those accounts
Remote work security offboarding protects both the individual (ensuring corporate monitoring software isn’t continuing on personal devices after employment ends) and the employer (ensuring access to corporate systems terminates cleanly). The offboarding conversation with IT — confirming what needs to be returned, wiped, or revoked — should happen on the last working day rather than after it. Access that persists beyond employment is a liability for both parties.
Managing data separation between personal and work
One of the most persistent remote work security challenges is data that bleeds between personal and work contexts on devices that serve both purposes. Practical controls for maintaining the separation:
- Separate browser profiles for work and personal browsing: Chrome’s multi-profile system and Firefox’s profile manager both maintain entirely separate cookie stores, browsing history, saved credentials, and extensions per profile. Switch profiles when switching contexts rather than using the same browser for both.
- Dedicated work email client: if work email is accessed on a personal device, use a dedicated email app for the work account rather than adding it to the same app as personal email. This keeps the work and personal inboxes visually and physically separate and makes it clearer when notifications are from work vs personal sources.
- Separate password manager entries or vault for work credentials: don’t mix work credentials with personal ones. Bitwarden allows organising entries into Collections; 1Password uses Vaults. This makes credential auditing easier and prevents work credentials from appearing in personal password health reports.
- Avoid syncing work data to personal cloud storage: downloading a client file to the desktop and having it automatically sync to your personal iCloud or Google Drive creates data residency issues and potential confidentiality breaches. Save work files to work-designated locations (corporate SharePoint, Google Workspace, Box) rather than personal cloud storage.
Home lab and development environments
For remote workers who maintain development environments, home servers, or home lab setups accessible from outside the home network, remote work security extends to the infrastructure layer:
- Never expose RDP (port 3389) or SSH (port 22) directly to the internet. These are among the most scanned ports on the internet, and exposure with anything less than perfect credential hygiene is a significant compromise risk. Access through a VPN or a service like Tailscale instead.
- Use fail2ban or equivalent on Linux systems accessible from external networks — automatic IP blocking after repeated failed login attempts dramatically reduces the impact of brute-force credential attacks.
- Separate home lab traffic from work and personal traffic using network segmentation (VLAN if the router supports it, or at minimum a separate guest network). A compromised home server shouldn’t have network access to work devices or personal computers.
For technical resources on remote work security policies, the NCSC (UK) and NIST (US) both publish guidance on secure remote working for organisations — the NCSC’s home working collection covers the organisational and individual controls in technical detail appropriate for IT professionals and security-conscious individuals working remotely.
Remote work security ultimately comes down to applying to the home and public environments the same discipline that corporate environments enforce structurally. The controls — VPN, screen lock, encrypted communication, data separation, regular updates — are the same controls that IT enforces at scale in an office. The difference is that remote workers must apply them individually and deliberately rather than having them enforced automatically. That discipline, maintained consistently, is what makes a distributed workforce’s security posture comparable to a centralised one. If this sounds familiar, Network Security Basics is worth a look.







