Staying secure while working remotely

Why remote and hybrid work changes your security risks
When you work outside a traditional office, the protective layers your organisation has built around its network no longer surround you automatically. In the office, firewalls, monitored connections and managed equipment quietly reduce many risks before you ever notice them. At home or in a café, much of that responsibility shifts onto you and your immediate setup. This is not a reason to feel anxious, but it is a reason to stay aware. The convenience of hybrid work comes with a wider attack surface: more devices, more networks, and more moments where a quick decision matters. A colleague connecting to a hotel Wi-Fi, a family member borrowing a work laptop, or a phone left unlocked on a train are all everyday situations that carry real consequences. Attackers understand this shift too. They know remote workers are often distracted, isolated from colleagues who might spot something odd, and eager to keep tasks moving. Understanding how your risks change is the first step toward building simple habits that keep both your data and your colleagues safe. The good news is that most protective measures are practical, repeatable and quickly become second nature once you understand why they matter.
Securing your home network and Wi-Fi
Your home network is now part of your working environment, so it deserves the same care you would give a workspace. Start with the router, which is the gateway between your devices and the internet. Many routers still use the default administrator password printed on the box, which anyone can look up. Change it to something unique. Next, check that your Wi-Fi uses modern encryption, ideally WPA3 or at least WPA2, and set a strong, memorable passphrase rather than the factory default. If your router allows it, create a separate guest network for visitors and smart home gadgets such as televisions, speakers or cameras. Keeping these away from the network your work laptop uses limits the damage if one of them is ever compromised. Router firmware also needs updating from time to time, as manufacturers release fixes for security flaws; some routers do this automatically, while others require you to log in and check. Finally, be mindful of who has access to your network. A guessable password shared widely among neighbours or old tenants can quietly undermine everything else. These steps take an afternoon at most, and they protect every device in your home, not only your work equipment.
Protecting devices used outside the office
Whether you use a company laptop or your own device, a few core protections apply. Keep the operating system and applications updated, because updates frequently close the exact gaps attackers rely on. Enable full-disk encryption so that if the device is lost or stolen, the data cannot simply be read by removing the drive; most modern laptops and phones offer this in their settings, sometimes switched on by default. Use a strong screen lock with a short automatic timeout, so an unattended device does not stay open. Install reputable security software if your organisation recommends it, and avoid disabling it for convenience. Be cautious about what you plug in: unknown USB drives and public charging cables can carry malware or attempt to access your data. Carrying your own charger and plugging into a wall socket rather than a public USB port is a small, effective habit. If you share a device with family, create separate user accounts so work files stay isolated. Above all, treat the physical device as valuable in itself. A locked laptop in a bag is far safer than one left visible on a passenger seat or an unattended table.
Safe practices for public spaces and travel
Cafés, coworking spaces, airports and trains offer flexibility, but they also expose you to onlookers and untrusted networks. The most common risk is simply someone reading your screen over your shoulder. A privacy filter that narrows the viewing angle is inexpensive and effective, and positioning yourself with your back to a wall makes a real difference. Avoid discussing sensitive matters on calls where strangers can overhear you. When it comes to Wi-Fi, treat any public network as potentially observed. If your organisation provides a VPN, use it consistently on public connections, as it encrypts your traffic between your device and a trusted point. Where no VPN is available, using your phone's mobile hotspot is often safer than an open café network. Never leave a device unattended, even briefly; ask a genuinely trusted companion to watch it or take it with you. When travelling, carry only the data you need and be aware that in some situations devices may be inspected. Lock everything before you set off, keep chargers and cables with you, and remain calm and deliberate rather than rushing, since haste is when mistakes and thefts most often happen.
Managing passwords and multi-factor authentication
Passwords remain a frontline defence, and remote work often means logging into more services from more places. The reliable approach is to use a unique, long password for every account, which is only realistic with a password manager. A good manager generates and stores strong credentials, so you only need to remember one strong master password. This prevents the common disaster where one leaked password unlocks many accounts because it was reused. Just as important is multi-factor authentication, often shortened to MFA. This adds a second step beyond your password, such as a code from an app or a physical security key. Even if an attacker learns your password, MFA usually stops them from getting in. Prefer authenticator apps or hardware keys over text-message codes where possible, as SMS can be intercepted or redirected. Enable MFA on every account that offers it, especially email, since email is often the key to resetting other passwords. Be wary of fatigue attacks, where you receive repeated approval prompts hoping you will tap accept out of frustration; if a prompt appears when you are not logging in, deny it and report it. These two habits together dramatically reduce your exposure.
Recognising phishing and social engineering when working alone
Working alone removes a quiet safeguard: the colleague at the next desk you might turn to and ask, 'Does this email look right to you?' Attackers exploit that isolation, and remote workers see a steady stream of messages designed to trick them into clicking links, sharing credentials or transferring money. Phishing has grown more convincing, often referencing real projects, using correct branding and creating a sense of urgency. Learn the common signals: unexpected requests, pressure to act immediately, slight misspellings in sender addresses, and links whose destination does not match the visible text when you hover over them. Social engineering extends beyond email to phone calls, text messages and even video calls, where someone may impersonate a manager, an IT helpdesk or a supplier. A safe rule is to verify through a separate, trusted channel before acting on any unusual request, especially those involving money, credentials or sensitive data. If your finance colleague suddenly asks for an urgent payment by email, call them on a known number to confirm. When something feels off, that instinct is worth trusting. Slowing down and checking costs a few minutes; acting on a convincing fake can cost far more. You are never bothering anyone by verifying.
Handling sensitive data on personal and shared devices
Remote work blurs the line between personal and professional equipment, and sensitive data can drift into places it should never be. Where possible, keep work data on approved systems and storage rather than saving copies to personal drives, personal cloud accounts or messaging apps. If you must use a personal device, follow your organisation's guidance and avoid downloading files that contain personal, financial or confidential information unless it is genuinely necessary. Be especially careful with shared or family computers, where another user could stumble upon work files. Separate user accounts, encryption and prompt deletion of temporary downloads all help. When sending sensitive information, use the secure channels your organisation approves rather than personal email. Printing at home introduces another gap: documents left in a printer tray or thrown into household recycling can expose data, so shred what you no longer need. Be mindful of backups too, since automatic photo or file backups may sync work documents to personal cloud services without you realising. Finally, remember that data protection rules such as the GDPR apply wherever you work, so personal data about customers or colleagues must be handled with the same care at your kitchen table as in the office.
Knowing when and how to report a security concern
The single most valuable habit for a remote worker is knowing that reporting a concern quickly is always the right choice. Many incidents grow worse only because someone hesitated, hoping the problem would resolve itself or fearing they would look foolish. A fast report gives your security team the chance to contain a problem before it spreads. Know in advance how to reach them: the email address, phone number or internal tool your organisation uses, and keep that information accessible even if your main device is unavailable. Report anything unusual, such as a suspicious email you clicked, a lost or stolen device, an account you can no longer access, or an unexpected login alert. You do not need to be certain something is wrong; near-misses and simple doubts are worth flagging, because they help everyone learn. A healthy security culture treats honest reports as a contribution, not a failure. If you are responsible for supporting colleagues, reinforce this message often, respond without blame, and make reporting as easy as possible. When people trust that raising a concern will be met with help rather than criticism, they report sooner, and the whole organisation becomes safer.
Example
Quick reference: common remote work situations and safer responses
| Situation | Risk | Safer response |
|---|---|---|
| Connecting in a café | Untrusted network, onlookers | Use a VPN or mobile hotspot; add a privacy filter |
| Unexpected urgent payment request | Business email compromise | Verify via a known phone number before acting |
| Lost or stolen laptop | Data exposure | Report immediately; rely on disk encryption and screen lock |
| Sharing a home computer | Work files accessed by others | Use separate accounts; avoid saving sensitive files locally |
| Repeated MFA approval prompts | Fatigue attack | Deny the prompt and report it |
| Public USB charging point | Malware or data theft | Use your own charger in a wall socket |
FAQ
Do I really need a VPN when working from home? At home, a properly secured router and encrypted Wi-Fi already provide good protection, so a VPN is most valuable on public or untrusted networks. That said, follow your organisation's policy, as some services and internal systems are only reachable through the company VPN. Using it consistently also builds a reliable habit for when you do work in cafés, hotels or coworking spaces.
Is it safe to use my personal phone or laptop for work? It can be, provided you follow your organisation's guidance and apply core protections: updates, encryption, a strong screen lock and multi-factor authentication. Keep work data on approved systems rather than personal cloud accounts, and use separate user accounts if the device is shared. If your role involves highly sensitive information, a managed work device is usually preferable, so check what your policy requires.
What should I do if I think I clicked a phishing link? Act quickly and calmly. Disconnect the device from the network if you can, do not enter any further information, and report it to your security team straight away using the contact details you have saved. If you entered a password, change it immediately from a device you trust and enable multi-factor authentication. Reporting early is far more helpful than staying silent, even if it turns out to be harmless.
How do I keep family members from accidentally seeing work data? Create a separate user account for work on any shared computer, so files and browsing stay isolated. Lock your screen whenever you step away, even for a moment, and avoid saving sensitive documents to shared folders. Be cautious with home printing by shredding documents you no longer need, and check that automatic backups are not syncing work files to a personal cloud account.
When is a concern serious enough to report? If you are unsure whether something is worth reporting, report it. Security teams would much rather review a harmless near-miss than discover a real incident too late. Suspicious emails you interacted with, lost devices, unexpected login alerts and accounts you can no longer access are all worth flagging. A good security culture treats every honest report as helpful, never as a mistake to be embarrassed about.
Read next
Get structured security awareness guidance for you and your team.