Security

How to keep remote work devices secure

2 min read Guillaume Duveau

Remote working takes professional devices outside the controlled office perimeter. Keeping them secure and up to date requires a specific approach, but it is accessible to any small business.

When people work remotely, professional devices leave the company network. They connect through home broadband, public Wi-Fi, sometimes shared networks. Without a specific organisation, that creates blind spots in IT security.

What changes with remote work

In a traditional office, workstations sit behind a firewall, connected to a controlled network, physically in a secure space. With remote working, none of those protections apply automatically. Devices are exposed to less reliable networks, and the user faces phishing attempts or suspicious activity without the nearby support of a team.

That does not mean remote working is inherently dangerous. It means it requires a different kind of organisation.

The essentials to put in place

Consistently configured devices. Ideally, every workstation is delivered with a standard configuration: disk encryption enabled, access protected by a strong password, coherent security settings. A device configured in haste or left to the user’s discretion will reliably have gaps.

Updates applied even off-site. When devices are off the company network, updates are no longer guaranteed if they depend on local infrastructure. Centralised device management (MDM) keeps security policies in place and deploys updates regardless of where the employee is working from.

Strong authentication on every access. A password alone is not enough. Two-factor authentication on professional accounts (email, collaboration tools, data access) is a baseline protection that holds up against stolen credentials.

Separation of personal and professional use. Mixing personal and professional use on the same device creates risk: a poorly secured personal application can expose professional data. When personal devices are unavoidable, minimum rules must apply.

What centralised management changes in practice

Centralised device management, built into InfraPro’s 360 offer, gives a clear picture of the state of every device, lets security policies be applied remotely, and allows quick action when something happens: a lost device, an employee who has left, a detected security event. This is the heart of what managed devices are.

Without that visibility, every off-site device becomes a blind spot. A workstation that hasn’t been updated for weeks can be vulnerable without anyone knowing.

What stays the same

Good practices remain the same wherever your team works: not clicking on suspicious links, reporting unusual activity, not bypassing security procedures. The difference with remote working is that the environment is less controlled, which makes those habits more important, not less.

To learn more about device management and securing remote workstations, visit our cybersecurity page.


Written by Guillaume, InfraPro, IT partner for SMEs and nonprofits.

Frequently asked

Are personal devices used for work a security risk?
Yes. A personal device is not configured to the organisation's standards and may not receive the necessary updates. When it is unavoidable, minimum security rules must apply.
How do you apply updates to devices that are off the company network?
That is one of the key advantages of centralised device management (MDM): security policies and updates are applied regardless of which network the device is on.
Is disk encryption really useful on a laptop?
Yes. If a laptop is lost or stolen, encryption makes the data unreadable without the password. It is a basic protection for any device that travels.
How should you handle a device when an employee leaves?
Remote data wiping is one of the features of centralised management. A departure should trigger a systematic process: revoking access and wiping the device.
Is a VPN connection essential for remote work?
It is necessary for connecting to the company's local network or on-premises servers. For cloud-only work (Microsoft 365, for example), strong authentication can be sufficient if properly configured.

In their words

InfraPro is by far the best managed IT company I've worked with.
Evan Smith — Co-founder, CicadaMedicinal cannabis (EU GMP)

Let's talk.

Book a call