Blog

Work-From-Home Security

Work-From-Home Security: The journey ahead for organizations and employees. Find out what’s needed for safer telecommuting. As workplace flexibility becomes more common, the need for a shared physical space is diminishing. For organizations, this means less overhead costs. For employees, it means more flexibility and a potential for better work-life balance. But despite the benefits, […]
PX
Propelex team September 26, 2023 - 4 minutes read

Work-From-Home Security: The journey ahead for organizations and employees. Find out what’s needed for safer telecommuting. As workplace flexibility becomes more common, the need for a shared physical space is diminishing. For organizations, this means less overhead costs. For employees, it means more flexibility and a potential for better work-life balance.

But despite the benefits, working remotely introduces new risks. In fact, the majority of damaging cybersecurity breaches occur on remote workers’ devices.

2. Lack of Training

As a company, you need to take the time to train remote workers on best practices and rethink communication policies to ensure that people who work remotely don’t feel like second-class citizens. For example, many remote workers might attempt to sidestep security protocols such as storing passwords in their browser for convenience but that can lead to real consequences for your business. Murphy suggests that managers provide training specifically for remote workers to make sure that they are aware of these risks.

4. Lack of Security Tools

As COVID-19 pandemic activity continues, many of the same work-from-home security blunders are still being committed by telecommuters. These missteps range from the simple to the incredibly risky, and can expose remote employees and their organizations to serious financial loss and damage.

During a time of uncertainty, some remote workers may seek out shortcuts to increase productivity and make their work easier. For example, Murphy warns that storing passwords in a browser or using autofill can be risky and lead to credentials being exposed.

And since they operate outside the corporate firewall, remote workers are often less protected by security tools and systems such as SIEM, DLP, firewalls and VPNs. They also tend to use personal devices and home Wi-Fi networks that are not as secure as company-issued equipment. This makes them more susceptible to attacks, especially when it comes to privileged access management. To help mitigate these vulnerabilities, implementing and enforcing multi-factor authentication is essential for remote employees, as well as creating clear security guidelines and encouraging employees to use password managers. For instance, requiring password changes on a regular basis can be a great security measure for remote workers to help minimize threats.

5. Lack of Security Awareness

While Covid-19 brought a sudden refocus on work-from-home security, it also highlighted the lack of preparedness around this issue in many businesses. As the CSBS 2020 research shows, only 54% of businesses have any formal, cyber security-framed rules in place for home and mobile working that they expect staff to adhere to.

For those organisations that have put policies and training in place, the challenge is often in driving up employee awareness and understanding of what they are meant to do – and not do. This requires the right mix of education and motivation, backed up by a solid framework to ensure that everyone is trained at least on an annual basis.

This training should include all three categories of users: managers, technical staff and end-users. This enables an effective training program that can be tailored to different needs and triggers. The goal should be to mitigate the human errors that are the biggest cause of data breaches. While it is impossible to reduce this risk to zero, training can significantly lower it and so it should be a key component of any business’s overall cybersecurity strategy.

There are plenty of tools available for companies to develop and implement information security awareness programs. These range from colorful posters that remind people about password best practices to the more standard, periodic cybersecurity trainings required of all employees. However, the problem with these programs is that they are usually seen as a tick box exercise that is used to satisfy compliance and reinforce internal security frameworks, rather than being considered a core part of a people-centric security strategy that addresses the needs of all user groups.

Learn more about our solutions

Work with Propelex

Ready to build AI
into your stack?

Propelex helps teams evaluate, integrate, and scale AI workflows — from MCP strategy to full agentic architecture. Let's find the right entry point for your organization.