Remote Work IT: Beyond Just a Laptop and VPN
Early in the shift to remote work, many businesses simply gave staff a laptop and told them to connect from home. This works in the short term but leaves significant gaps in security, productivity, and manageability.
A properly set up remote work environment is productive, secure, and manageable — meaning that from a central IT management perspective, a remote device is not fundamentally different from an office device.
Device Setup
- [ ] Laptop or desktop is business-owned or formally approved as a BYOD device
- [ ] Device runs a supported operating system (Windows 11 or macOS Ventura or later)
- [ ] Drive encryption enabled (BitLocker on Windows, FileVault on Mac)
- [ ] Automatic screen lock after 5–10 minutes of inactivity
- [ ] EDR (endpoint detection and response) software installed
- [ ] Automatic security patching enabled
- [ ] Device enrolled in MDM (Microsoft Intune or equivalent) if managed by IT provider
Connectivity
- [ ] Staff understand not to use public Wi-Fi for business work without a VPN
- [ ] VPN available for accessing any on-premise systems or sensitive data
- [ ] Business-grade internet at home for staff who work remotely most of the time (not mandatory, but recommended)
- [ ] Static IP or conditional access policy in place if access restrictions are based on location
Access and Identity
- [ ] MFA enabled on all accounts — email, cloud storage, business applications
- [ ] Staff using their individual business accounts — no shared logins
- [ ] Conditional access policies in place to restrict access from non-compliant devices (Microsoft Intune or Entra ID)
- [ ] Password manager in use — no passwords stored in browser or reused
Collaboration and Communication
- [ ] Microsoft Teams or equivalent collaboration platform configured and in use
- [ ] File sharing through approved business cloud storage (SharePoint, OneDrive) — not personal Dropbox, Google Drive, or USB drives
- [ ] Clear policy on which communication channels are used for which purpose
- [ ] Video conferencing setup tested — camera, microphone, and background appropriate for client-facing calls
Security for Home Environments
- [ ] Home routers: default admin passwords changed, firmware current
- [ ] Guest network used for personal and IoT devices, separate from work devices
- [ ] Staff aware not to let family members use business devices
- [ ] Business devices not used for personal banking, personal email, or unmanaged software installations
Incident Response
- [ ] Staff know what to do if their device is lost or stolen — who to call, what information to provide
- [ ] Remote wipe capability confirmed for all enrolled devices
- [ ] Reporting process for suspicious emails or activity documented and communicated
Getting Remote Work IT Right
The Security Gaps That Remote Work Creates
Remote work introduces specific security gaps that an office-only environment does not have. Understanding these gaps informs the right design for a remote work IT setup.
Home network exposure. A home network typically includes multiple family devices, IoT devices (smart TVs, smart speakers, robot vacuums), and consumer-grade router firmware that may not have been updated in years. Business laptops on this network are one compromised IoT device away from network-level exposure. The mitigation: ensure business traffic goes through a VPN that routes it through your business internet, bypassing the home network's weaknesses.
Shared device risk. In a work-from-home environment, family members may use work computers (particularly if there is only one laptop in the house). A child installing a game, a partner browsing on the work computer, or a visitor using it briefly all create exposure. MDM with a screen lock, encrypted storage, and a policy that the device is for business use only addresses this.
Unsecured Wi-Fi outside the home. Cafes, airport lounges, hotel lobbies, and coworking spaces provide Wi-Fi that is shared with strangers and may be monitored. A VPN ensures that traffic on these networks is encrypted and unintelligible to other users on the same network.
Phishing in a less secure environment. Remote workers do not have the informal security cue of a colleague nearby to ask "does this email look suspicious?" Isolation increases the likelihood that a suspicious email is acted on without a second opinion. More frequent and realistic phishing awareness training is particularly important for remote-heavy teams.
Remote Work Infrastructure: What Your Business Needs to Provide
Corporate VPN or Zero Trust access. All remote workers connecting to internal systems (file servers, practice management software running on-premise, internal websites) need an encrypted path from their location to the business network. A managed VPN (configured with your Static IP as the endpoint) is the standard approach for most small businesses. Zero Trust Network Access (ZTNA) is a more granular alternative that is increasingly accessible to SMBs through tools like Cloudflare Access or Microsoft's Conditional Access.
Device management (MDM). Company-owned or BYOD devices used for remote work should be enrolled in MDM. This enables: remote wipe if a device is lost, encryption enforcement, VPN configuration push, and app deployment. Microsoft Intune (included in Microsoft 365 Business Premium) provides this for both Windows and macOS.
Separate business phone system (for Teams or VoIP). Remote workers who use their personal mobile number for business calls create several problems: they cannot transfer calls to colleagues, clients may call their personal number rather than a business line, and when they leave the business the client relationship goes with them (to the personal number). Microsoft Teams Phone or a cloud VoIP system gives remote workers a business number that rings through any device and stays with the business.
The Home Office Setup Standard
For a remote worker who will work primarily from home, the investment in a proper home office setup pays dividends in comfort, productivity, and security:
Dedicated work device. Not shared with family members. Company-owned where possible; BYOD with MDM if not.
Wired internet connection for video calls. Wi-Fi is adequate for most tasks but Ethernet provides better stability for extended video conferencing. A $30 Ethernet cable from the router to the desk eliminates most video call quality issues.
External monitor. Working on a laptop screen alone is a productivity drag. A single external monitor significantly improves comfort and productivity. Company-supplied as part of the remote worker setup.
Good headset. For video calls and phone calls. Not headphones with a microphone — a headset with noise cancellation that works in the presence of household background noise. Company-supplied.
UPS for the router. If power outages are common in the area, a small UPS keeps the router and modem running during brief outages, maintaining connectivity through NBN interruptions that are power-related.
Netluma IT designs and implements remote work IT setups for SE Queensland businesses. Call 1300 521 162 to discuss what your remote team needs.
Netluma IT sets up and manages remote work environments for SE Queensland businesses. Call 1300 521 162 to review your current remote work security posture and identify gaps.
Tired of Slow IT Support?
96% of issues resolved in the first hour. Priority-based SLAs, a local Gold Coast team, and support that actually picks up the phone.
Related Services