Working remotely from home while drinking coffee in your pajamas is definitely a nice way to live. Indeed, more and more companies are embracing this way of working.
And why not?
Employees can work from home, organize their own schedules and save large amounts of money on daily commutes, while companies can reduce infrastructure costs by leveraging the hardware and software resources of the workforce.
Why invest in expensive products when your employees already have them? Of course, all of this is easier said than done. Since you have no way of knowing how seriously your employees take security, you can open a digital Pandora’s box by letting them process your company’s data without taking the necessary security measures. Companies obviously need to educate themselves on security best practices if they want to operate in a borderless world.
With remote work no longer a privilege for the few, companies large and small have no choice but to embrace it or risk losing talented employees to competitors. The challenges of working from home are just as daunting. A 2018 remote worker security survey by iPass found that 52% of companies across America feared their employees had been hacked in the past 12 months. 67% believe that most attacks have occurred over Wi-Fi connections in coffee shops.
Since working from home is the future, there should be security best practices. Below we will analyze the most basic ones.
Create a remote work policy
In addition to clearly defining how remote workers are expected to behave when working from home, a remote work policy should also list the tools they are allowed to use for remote work. Companies should list the selection of tools they use in their organization to ensure that data is distributed efficiently. Remote team members should also use secure internet connections to access company data and avoid public Wi-Fi.
A remote work policy should include elements such as temporary and permanent positions, reasons why working from home is permitted such as parental benefits, inclement weather, emergencies, geographical distance, etc., as well as best practices for working from home safety.
Get a (really) strong password policy
A whopping 81% of all hacks that happen today are due to weak passwords. Why do people still use weak passwords when their risks are so obvious? Many use the same password to log in to multiple accounts or simply choose pieces of information that they are more likely to remember. Since these are usually a date, an event, or a series of numbers/letters, they are extremely easy to fall into the wrong hands. In this case, “123456” is still the most common password in 2019 with 23.2 million accounts “stored” with it!
You can use a password generation method that follows a unique pattern that only your employees know. This method can be documented in your password policy and employees can be trained on it to ensure compliance when working from home or the office.
Separate personal and work data on a user's computer when working from home
No employee will allow a company to dictate how they can use their own devices. It's also unlikely that employees will remember security best practices when browsing Facebook or casually browsing the web.
However, you can store work data on remote computers so that it is never affected by personal use. A Virtual Machine can be very useful in this case. A VM is essentially a “software computer” with its own operating system that runs separately from the user’s original installation.
A computer's hard drive can also be divided into two partitions. Each partition can have specific operating systems, applications, and security protocols enabled. The method for partitioning a hard drive varies from system to system, so it's best to talk to your IT staff to find the best method to accommodate remote workers.
Finally, remote workers can also have two different user logins, one for work and one for personal use.
Remote data scanning and deletion application for all employees
The problem with remote work security best practices is unfortunately not limited to poor policy. One study found that 86% of companies believe that remote workers have increased the chances of a data breach. The study also noted that while those companies have contingency plans, only 35% have a policy for storing or deleting data remotely, while 54% of companies have no contingency plans at all.
Simply put, enforcing a policy may not be enough. This means that specific disaster recovery measures need to be included. Most operating systems today have a remote data wipe feature that allows administrators and users to wipe their computers from any location. Data can also be selectively removed from some Microsoft in the event that an employee leaves.
Consider using a VPN for business communications
Virtual private networks encrypt all internet traffic to and from devices until they are turned off. They create a secure tunnel between a user and a company over the public internet. VPNs are invaluable for securing data on unsecured networks, stopping any prying eyes (like ISPs) from snooping on the data being sent, and helping your network administrators implement security best practices for remote work.
There are two basic types of VPN technologies, depending on your risk threshold and requirements. Remote access VPN allows a user to connect to a network from any location and is ideal for allowing remote workers to access the company network. “Site to Site” VPN encrypts data between two different geographical locations, such as two offices.
A variety of VPN protocols are available to choose from. While PPTP (Point-to-Point Tunneling Protocols) is the older and more mature technology, OpenVPN is ideal for companies looking for a more secure tool.
Unlike PPTP, IPSec (Internet Protocol Security), and SSTP (Secure Socket Tunneling Protocol), OpenVPN is implemented on all systems and can be customized to your requirements.
Switch to modern cloud productivity tools
Having strong security practices is always a good idea. However, with the number of apps out there, enforcing broad organizational policy can become tedious. A smarter way out is to switch to cloud-based productivity apps.
Not only do they facilitate remote operations with work tracking, scheduling, and communications, but as they are a productivity enabler for remote work, they already have some of the best and most up-to-date security practices that make them ideal for remote work.
The problem with security is that while technologies can offer a lot, the final say lies with the user. No level of technological advancement can prevent data from being compromised if the user simply gives someone else access to it.
Spurious decisions, absent-mindedness, and carelessness are all too common when working from home, so training and developing good habits are just as important as the safety tools themselves.


