Guide
How to Secure Remote Workers
Remote access should be designed around identity, least privilege, device security, monitoring, and a support process users can follow.
By Austin Hadley, Founder and Chief Executive Officer Published Updated
Remote access should be designed around identity, least privilege, device security, monitoring, and a support process users can follow.
Identity first
Remote work moves access decisions beyond the office network, making identity a primary control. Give each person an individual account, require multi-factor authentication for email, remote access, and administrative tools, and remove access promptly when roles change or employment ends. Avoid shared credentials because they weaken accountability and make revocation difficult.
Use least privilege: employees should receive the applications and data required for their role, not broad network access by default. Protect password resets and account recovery, review privileged roles regularly, and keep an emergency administrative account secured separately from daily work.
- Require phishing-resistant authentication where risk and platform support justify it.
- Review sign-in alerts, forwarding rules, recovery methods, and inactive accounts.
- Document onboarding, role change, lost-device, and offboarding procedures.
Remote access design
Choose access methods according to the application. A managed cloud application may only need strong identity controls, while an internal system may require a VPN, application proxy, or managed remote desktop. Limit exposure to the smallest practical set of services and users, and do not publish administrative interfaces simply for convenience.
Design for unreliable home networks and supportable recovery. Document the approved client, authentication steps, split- or full-tunnel decision, DNS behavior, logging, timeout rules, and what should happen if the primary connection fails. Test from networks outside the office before rollout.
- Use encrypted, individually authenticated access rather than open inbound services.
- Restrict users and devices to the specific networks and applications they need.
- Monitor failed sign-ins, unusual locations, configuration changes, and access outside expected patterns.
Endpoint basics
A secure connection does not make an unmanaged computer safe. Establish minimum standards for operating-system and application updates, disk encryption, screen locking, malware protection, local administrator rights, backups, and device inventory. Company-managed devices make these controls easier to apply and verify consistently.
Decide what business data may be downloaded, printed, copied to removable media, or synchronized to personal services. If personal devices are permitted, define the boundaries clearly and use application-level management or browser controls where appropriate instead of assuming full control of an employee-owned device.
- Keep an inventory with device owner, operating system, encryption, and support status.
- Set deadlines for critical updates and remove unsupported devices from access.
- Prepare a remote lock, credential reset, and incident process for lost or stolen equipment.
Support process
Controls are more effective when employees know how to use them. Provide short instructions for connecting, verifying unusual login prompts, handling sensitive information, reporting suspected phishing, and getting help. Make the support contact easy to verify so an attacker cannot impersonate the help desk.
Track recurring access and device problems rather than solving each ticket in isolation. Review authentication failures, VPN capacity, update compliance, lost devices, and support trends. Periodic exercises for phishing reports, account compromise, and unavailable remote access help expose unclear responsibilities before a real disruption.
- Publish a verified support channel and an after-hours escalation path.
- Teach users to report suspicious prompts without approving them first.
- Test account containment and remote-work continuity with named owners.