Jobicy Journal

Cybersecurity Best Practices for Remote Work

Protect remote work with stronger authentication, secure devices, safer file sharing, approved AI tools, tested backups, and a clear incident response plan.

Cybersecurity Best Practices for Remote Work

A message asks you to sign in again to view a shared document. A caller claims to be IT support. A colleague needs a confidential file, but your usual sharing tool is unavailable.

These ordinary moments are where remote-work security becomes practical. The risk is not limited to the connection between a home laptop and an office network. It includes the accounts you use, the software you install, the permissions you grant, and where company information goes.

Good cybersecurity combines habits employees can follow with controls employers maintain. A worker can report an unexpected login prompt; the organization must provide secure authentication, supported devices, and someone who can respond.

The following practices apply to home offices, coworking spaces, and work while traveling. Use them alongside your organization’s requirements for its systems and data. For more background on the risks, see Jobicy’s overview of cybersecurity threats in remote work.

1. Use approved, properly secured devices

Start with a device your organization has approved for work. This may be a company-issued laptop or a personal device covered by a bring-your-own-device policy.

A personal laptop should not become a work device simply because it can open company email. The UK National Cyber Security Centre’s BYOD guidance explains that device management, corporate data protection, usability, and the owner’s privacy all need consideration.

For day-to-day work:

  • Keep the screen lock enabled and lock the device when you step away.
  • Use the required firewall and endpoint protection.
  • Have IT confirm that storage encryption is enabled and recovery information is securely managed.
  • Install applications and browser extensions through approved channels.
  • Keep work accounts separate from household members’ use of the device.

Encryption helps protect stored data if a device is lost or stolen. It does not prevent someone using an unlocked session or accessing a compromised account.

Physical security belongs in your home office setup, too. Avoid leaving equipment unattended in shared spaces, protect sensitive papers, and check what nearby people can see on your screen.

2. Prefer phishing-resistant authentication

Multi-factor authentication adds protection beyond a password, but different methods offer different resistance to attacks.

CISA’s MFA guidance recommends moving toward phishing-resistant authentication, including FIDO/WebAuthn. Organization-approved passkeys and FIDO security keys can provide this protection when appropriately configured.

One-time codes and conventional approval notifications remain useful, but attackers may trick users into entering codes on a fake site or approving an unexpected request. They should not be treated as equivalent to phishing-resistant methods.

Employees should enroll using the organization’s instructions and know how to recover access if a phone or key is lost. Never approve a login you did not initiate or share an authentication code with someone claiming to provide support.

Employers should prioritize email, remote access, administrative accounts, and systems containing sensitive data. Protect enrollment and recovery processes as well as the normal login. A secure sign-in method loses value if an attacker can persuade support staff to replace it.

3. Use unique passwords without unnecessary rotation

Where passwords are still required, use a long, unique password for each account and store it in an approved password manager. A generated password is a practical way to avoid reuse.

The current NIST digital identity guidelines, SP 800-63B-4, tell password verifiers not to require routine periodic changes or arbitrary character-mixture rules. They require a change when there is evidence of compromise.

For organizational policy, this means focusing on password length, blocking common or compromised choices, and supporting password managers instead of relying on a monthly reset routine.

For employees, the immediate priorities are simpler: avoid reuse, protect your password manager, and report suspected exposure promptly. If a work password has been entered on a suspicious site, involve IT and follow its recovery instructions. Changing a password may be only part of the response; active sessions or other access may also need revocation.

Keep recovery codes in the approved secure location, separate from the device or account whose loss would make them inaccessible.

4. Keep software supported and install security updates

Update the operating system, browser, work applications, security software, and any remote-access client. Routers and other network equipment need maintenance as well.

On a managed device, follow the organization’s update process. Complete required restarts and report installation failures rather than repeatedly postponing them. Download updates through the software’s built-in mechanism or another approved source, not an unexpected “urgent update” link.

The NCSC’s device-update guidance provides a framework for managing this work.

Employers need an inventory of devices and software, visibility into update status, and a way to replace products that no longer receive security fixes. Automatic updates are useful, but they do not prove that every device has successfully installed a patch.

Treat a security exception as something with an owner and a resolution date. A critical work application that blocks updates should trigger an IT decision about mitigation or replacement.

5. Use the company’s approved remote-access method

A corporate VPN can create an encrypted tunnel between a device and the organization’s VPN gateway. It protects traffic routed through that tunnel and can provide access to internal resources.

It does not automatically protect every application, prevent phishing, or make an infected laptop safe. Its coverage depends on configuration. A consumer VPN is also not a substitute for the company’s access controls.

The NCSC’s VPN guidance notes that the need for a VPN depends on network architecture. Some organizations use other approved approaches to reach applications securely.

Use whichever method your organization requires. If a required connection fails, contact support rather than disabling controls or moving files into personal accounts to continue working.

Employers should maintain the access infrastructure, require appropriate authentication, limit what users can reach, and remove obsolete remote-access services. Secure remote access is an ongoing operational responsibility, rather than something solved by installing a client once.

6. Secure home Wi-Fi and assess public connections sensibly

At home

Use WPA3 Personal where supported, or WPA2 Personal when necessary. Replace outdated equipment that cannot support secure configurations or receive updates.

Change the router’s default administrative password and use a separate, strong Wi-Fi password. Maintain firmware updates and disable unnecessary internet-facing router administration. The FTC’s home-network guidance explains these settings.

Where your router supports it, use guest or separate networks for visitors and smart-home devices. Check the isolation settings: a second network name alone does not prove that devices cannot communicate with one another.

In hotels, airports, and coworking spaces

Public Wi-Fi does not automatically expose the contents of every connection. The FTC explains that widespread website encryption has changed the risk. HTTPS protects the connection to a website, but it does not establish that the website itself is trustworthy.

Follow the employer’s rules for public networks. Confirm the network name with the venue, keep local sharing disabled when it is unnecessary, and use the required secure-access method. Do not bypass certificate warnings or install software or certificates from an unexpected captive portal.

A trusted mobile hotspot may be a practical alternative where policy permits. It still requires secure accounts and an updated device.

7. Verify unusual requests before acting

Phishing can arrive through email, chat, text messages, QR codes, shared documents, or a phone call. A request can appear to come from a familiar person and still need verification.

Pay particular attention when someone asks you to:

  • Sign in through a new link.
  • Install remote-control software or run a command.
  • Share credentials, authentication codes, or confidential files.
  • Change payment details or bypass an approval process.
  • Act immediately while keeping the request secret.

Confirm sensitive or unusual requests through a known channel. Call a contact using a number already in the company directory, or open the service through a saved bookmark. A number supplied inside the suspicious message is not independent verification.

A familiar voice, polished writing, or company branding is insufficient evidence of identity. Verify the requested action and the sender’s authority.

Employers should make reporting easy and teach staff how to handle realistic requests. Training and simulations should help people recognize and report problems, without discouraging disclosure after a mistake.

Security awareness also starts before employment. Jobicy’s guide to protecting personal information during a job search covers related privacy concerns when communicating with unfamiliar recruiters.

8. Share files through approved services with limited access

Use the organization’s approved storage and collaboration tools. Sending a document to personal email or uploading it to a convenient file-conversion service creates another place where the information needs protection.

Before sharing, check the recipient, the file, and the permission level. Prefer access for named recipients or the intended group over a public link. Grant editing rights only when needed and use expiry settings where appropriate.

A document can also reveal information through comments, tracked changes, hidden worksheets, or included attachments. Review the actual material you are sharing, not just the filename.

Keep meeting recordings and transcripts in approved locations. Consider what your screen share reveals: notifications, browser tabs, and background documents may contain information outside the meeting’s purpose.

If an approved tool does not meet a genuine business need, raise the problem with IT. A usable alternative is more sustainable than a rule employees must work around to finish their tasks.

9. Treat AI tools as part of the data-security boundary

An AI assistant, meeting bot, browser extension, or connected agent may receive company information and access other services. That makes its approval and permissions relevant to cybersecurity.

In its September 2026 guidance on the risks of shadow AI, the NCSC highlights the loss of visibility and control that can follow use of unapproved tools. It also explains that an exploited agent may expose the data and privileges available to it.

Use the approved account and tool for the task. Check which data types are permitted before uploading customer records, contracts, internal code, or meeting transcripts. Do not submit passwords, authentication codes, or access keys as prompt content.

For connected tools, review the services and permissions being requested. A tool that only needs one document should not casually receive access to an entire mailbox or shared drive.

Employers should provide clear examples of allowed use, assess data handling and retention, and make approved alternatives accessible. Employees need a workable way to ask about a new tool before adopting it.

10. Back up work data and test recovery

Use the organization’s designated storage and backup process. Important work should not exist only on one laptop.

The NCSC’s backup guidance emphasizes keeping copies of important data, protecting them, and checking that they can be restored.

For employees, confirm that the required folders and files are covered. Report backup failures, and avoid making personal copies of corporate data as an improvised backup.

Employers should establish what is backed up, how often, who can change or delete backups, and how recovery works. Protect backup access separately and keep recovery copies that are suitably isolated from routine user access.

Cloud synchronization can copy changes—including unwanted changes or deletions. Check the service’s actual recovery capabilities, retention, and account protections rather than assuming that “stored in the cloud” means recoverable after any incident.

Run restore tests. A successful backup notification is useful, but restoring the required data is the stronger check.

11. Limit access and make security part of onboarding

Give people the access needed for their responsibilities. Review it when roles change and remove it when employment or a contract ends.

CISA’s cybersecurity priorities include separating everyday user access from privileged accounts. Administrative permissions should serve a defined need, rather than being the default for everyone.

Employers should also review external collaborators, shared links, connected applications, and service credentials. Removing a user from one system may leave other access active.

During onboarding, explain approved devices, authentication, file handling, AI use, travel rules, and the reporting channel. Include these in your remote hiring and onboarding process.

Maintain appropriate security logs and assign responsibility for reviewing alerts. The NCSC’s monitoring guidance explains how logs support detection and investigation. Employees should understand what monitoring applies to their devices, especially when personal equipment is permitted.

12. Know what to do when something goes wrong

Save the security-reporting contact somewhere you can reach if your work account is unavailable. Know the alternative channel for an urgent incident.

Report a suspicious login, lost device, mistaken disclosure, unexpected authentication approval, or possible malware promptly. You do not need to prove an attack occurred before asking for help.

Give the response team the time, affected device or account, what happened, and what you clicked, entered, or shared. Preserve relevant messages and screenshots without spreading sensitive information to additional people.

If malware is suspected, follow the organization’s isolation procedure; this commonly involves disconnecting the affected device from networks and contacting support using another device. Avoid wiping or attempting to repair it before responders can assess the situation.

For possible credential theft, use a trusted device and work with IT to recover access and revoke affected sessions or permissions. For a lost laptop, report promptly so the organization can assess account exposure and available device-management actions.

The NCSC’s response and recovery guide provides a starting framework for employers. Practice the process before an incident and update it after lessons emerge.

A practical remote-work security check

Before your next work session, confirm that:

  • Your device is approved, updated, encrypted, and protected by a screen lock.
  • Your work accounts use the organization’s required authentication.
  • Your files stay in approved locations with appropriate sharing permissions.
  • You know which network and remote-access methods are allowed.
  • Any AI tools or connected applications are approved for the data they receive.
  • Your important work is covered by the backup process.
  • You can reach the security-reporting contact even if work email is unavailable.

Employers should make these checks achievable through clear instructions, reliable tools, and responsive support. Review the arrangements when roles, tools, devices, or working locations change. Remote-work cybersecurity works best when the safe way to complete a task is also a practical one.

Natalya Luft About the author Natalya Luft

Remote Culture Consultant · Former HR Director I’m Natalya -- originally from Kyiv, now based in NYC. I’ve spent 15+ years building and managing distributed teams across Europe. I write about culture, communication, and leadership in remote-first organizations. I believe remote work is about trust, not tools.

Share this article
Jobs Talent AI Tools Salaries
Menu