Working From Home: Keeping Your Business Data Safe
Working From Home: Keeping Your Business Data Safe
Remote and hybrid working stopped being an emergency measure some time ago. Most businesses now have people working from home at least part of the week, and the arrangements that were improvised in a hurry have quietly become permanent.
That’s the problem. A temporary setup nobody expected to last is now how the business runs, and much of it was never revisited.
This is a practical look at what actually needs protecting when work happens outside the office, and what tends to get missed.
Start With a Question Most Businesses Can’t Answer
Where is your company data right now?
Not in principle. Actually. On which devices, in which accounts, in which locations.
For most businesses with remote staff, the honest answer includes some combination of: cloud services, company laptops, personal laptops, personal phones, home computers used occasionally, a USB stick someone used to move a file, and downloads folders on machines nobody has looked at in two years.
You can’t protect data you can’t locate, so this is the first job rather than the last.
The Device Question
Company devices are considerably easier
A company-owned laptop can be encrypted, patched, monitored and, if it’s lost or someone leaves, wiped remotely. A personal one usually can’t, at least not without agreements most people won’t sign.
If your business can supply devices, it removes a whole category of problem. It isn’t always affordable, but it’s worth knowing what you’re accepting if you don’t.
If people use personal devices, be deliberate about it
Personal devices in a work context are extremely common and not automatically wrong. What matters is that it’s a decision rather than a drift.
The practical middle ground for most small businesses is to allow personal devices for access, but not for storage. People can read email and work in cloud applications through a browser, but company files don’t get downloaded onto the machine. That way, if the device is lost or the person leaves, the data isn’t on it.
That’s enforceable with the right configuration, and it’s a great deal easier than trying to manage someone’s own laptop.
Encryption
Every device holding company data should have full disk encryption enabled. It’s built into modern Windows and macOS, it costs nothing, and it turns a lost laptop from a potential data breach into a lost piece of hardware.
Worth actually verifying rather than assuming. It is not always on by default.
Access, Not Perimeter
The old model was a network with a boundary: inside was trusted, outside wasn’t. Remote working dismantles that, because there is no meaningful inside any more.
What protects you now is control over who can access what, and from where.
Multi-factor authentication, everywhere
This matters more with remote working than it ever did in an office. A stolen password used from an unfamiliar location is the single most common route into a business’s data, and multi-factor authentication is the control that stops it.
Everywhere means everywhere: email, cloud storage, finance systems, your domain registrar, remote access, administrative accounts especially. A single system without it is where an attacker will go.
Least privilege
People should have access to what their role needs and not much else. In an office this feels pedantic. With remote access it matters more, because a compromised account reaches whatever that account could reach.
Worth reviewing periodically. Access accumulates, particularly when people change roles.
Know how people are connecting
If staff need to reach systems on your office network, that should be through a properly configured VPN or equivalent, not an open remote desktop connection. Exposed remote desktop is one of the most reliably exploited weaknesses there is.
If everything is cloud-based, you may not need a VPN at all, which is simpler and often safer.
Home Networks
You have limited control here, which is worth acknowledging honestly. But a few things are reasonable to ask.
Change the router’s default admin password. Many home routers still have the credentials printed on the side.
Keep router firmware updated. Rarely done, and it’s the device sitting between the home and the internet.
Use a strong Wi-Fi password, and be wary of shared or guest networks in flats and shared houses.
Avoid public Wi-Fi for work, or use a VPN if it’s unavoidable. Mobile tethering is usually the better option and is now cheap.
The realistic position is that you protect the device and the data rather than trying to secure someone’s home network. If the laptop is encrypted, patched and requires multi-factor authentication, a weak home network matters much less.
The Human Side
Most incidents don’t involve anything technically clever. Someone is asked to do something plausible and does it.
Remote working makes this harder to catch, because the informal check disappears. In an office, someone asked by email to change a supplier’s bank details might turn to a colleague and say “does this look right to you?”. At home, they just reply.
What helps:
Tell people plainly that they will never be asked to move money, change payment details or share credentials by email alone, and that verifying by phone is always the right response, never an inconvenience.
Make it easy to report a mistake. Someone who clicks something and says so within ten minutes has given you a manageable problem. Someone who says nothing because they’re embarrassed has given you a much worse one. That depends entirely on how the business has responded to mistakes previously.
Cover it at induction. New starters working remotely from day one never absorb the informal norms that office staff pick up by osmosis.
Backup Still Matters, Perhaps More
Cloud storage is not backup. It protects you against losing a device. It does not reliably protect you against someone deleting a folder, ransomware encrypting files that then sync, or a mistake nobody notices for weeks.
With remote working there’s an additional gap: files saved locally on someone’s laptop and never synced anywhere. Those aren’t backed up by anything, and people do it constantly, usually without realising.
Two things to check: that your cloud data is genuinely backed up, and that people are actually working in synced locations rather than on their desktop.
What Happens When Someone Leaves
This is the most commonly missed piece, and remote working makes it worse.
When someone leaves an office, there’s a physical moment: they hand back a laptop and a pass. When someone remote leaves, there may be no moment at all. The laptop is at their house. The phone with company email on it is theirs. Access to eleven cloud services sits in a list nobody has.
What you need: a written offboarding process covering every system they had access to, retrieval of company equipment, removal of company data from personal devices, and prompt revocation of access rather than “when we get round to it”.
Departed staff retaining access is one of the most common problems we find, and it’s entirely preventable.
It’s one of several routine jobs that quietly go undone in most businesses. Our checklist of the IT jobs small businesses forget until something breaks covers the others.
A Practical Checklist
- List every device that touches company data, including personal phones with work email.
- Confirm encryption is enabled on all of them.
- Confirm multi-factor authentication on every system, particularly admin accounts.
- Decide your personal device position and configure it, rather than leaving it ambiguous.
- Check how people connect to anything on the office network.
- Review who has access to what, and remove anything unnecessary.
- Check your backups, including whether anyone is working locally and unsynced.
- Write down your offboarding process and use it every time.
- Tell your team what they’ll never be asked to do by email, and that reporting mistakes is welcomed.
- Revisit it annually, because devices and people change.
The Point
Remote working isn’t inherently less secure. Plenty of businesses run it well.
What causes problems is arrangements that were improvised quickly and never reviewed, on the assumption they were temporary. If your remote setup dates from a rush and hasn’t been looked at since, that’s worth an afternoon of someone’s time.
Want Someone to Review It?
CCSW helps businesses across Cardiff and South Wales work securely from anywhere, covering cyber security, Microsoft 365, cloud services, backup and disaster recovery and IT support.
If you’d like someone to look at how your team works remotely and where the gaps are, get in touch or call 0333 014 4544.
