Cyber SecurityInternationalCybersecurity, Privacy & Compliance

How to Secure a Remote Workforce

A layered security model for remote and hybrid work covering identity, managed devices, collaboration, data, support and incident readiness.

MENTARA Editorial
On this page
Quick orientationCybersecurity, Privacy & Compliance

A layered security model for remote and hybrid work covering identity, managed devices, collaboration, data, support and incident readiness.

Remote WorkforceCyber SecurityIdentityEndpoint Security

The perimeter is the identity now

Remote work did not add a few new risks to the old model — it removed the model. When everyone was in an office, the network was the boundary. With a distributed workforce, the only consistent control point is who is signing in, from what device, to what.

Everything below follows from that. If you do only three things, do these:

  1. Phishing-resistant MFA on every account — no exceptions for executives
  2. Device health as a condition of access — an unmanaged laptop should not reach your data
  3. Fast offboarding — access removed in hours, not weeks

Priorities in order of return

ControlEffortImpactNotes
MFA everywhereLowVery highPrefer passkeys/FIDO2; SMS is the weakest form and is phishable
Single sign-onMediumVery highOne place to grant and revoke; makes offboarding real
Device management (MDM)MediumHighEncryption, patching, screen lock, remote wipe
Conditional accessMediumHighBlock legacy protocols, risky sign-ins, unmanaged devices
Patch disciplineLowHighUnpatched endpoints remain a leading entry route
Endpoint detection (EDR)MediumHighAntivirus alone is insufficient
Backup with recovery testingMediumVery highThe actual ransomware control — untested backups are decoration
Password managerLowMediumRemoves reuse; makes strong credentials practical
Security awarenessLowMediumFocus on reporting culture, not annual click-through training
VPNMediumLow–mediumLargely superseded — see below

The VPN misunderstanding

Many organisations still equate remote security with "connect to the VPN". If your applications are SaaS — Microsoft 365, Google Workspace, Salesforce — traffic goes to the internet regardless, and a VPN adds latency without adding protection.

VPN remains appropriate for reaching internal, non-internet-facing systems. For everything else, conditional access on identity plus device posture is the stronger and less annoying control. Users bypass slow VPNs; they cannot bypass a conditional access policy.

BYOD, decided properly

The unresolved BYOD position is one of the most common gaps. Pick a model deliberately:

ModelHow it worksTrade-off
Corporate devices onlyCompany issues and manages everythingCleanest security, highest cost
Managed BYODPersonal device enrolled in MDMCheaper; genuine privacy objections, and works council issues in Europe
Application protection onlyData controls inside apps; device unmanagedGood middle ground — protects company data without managing the personal device
Unmanaged accessAnything can connectNot a position, an absence of one

For most European organisations, application-level protection is the pragmatic answer — it protects company data in company apps without asserting control over an employee's personal phone, which sidesteps both the privacy objection and the works council conversation.

The controls people skip

  • Offboarding speed. Ex-employee accounts active weeks later is extremely common and entirely preventable with SSO.
  • Shared and service accounts. Often no MFA, shared passwords, and no owner.
  • OAuth app grants. Staff connect third-party apps to company data; nobody reviews them. Audit these — it is usually revealing.
  • Home network and travel. Less critical than assumed if devices are hardened and traffic is encrypted, but public-network guidance is still worth stating.
  • Physical security. Screen locks and encryption matter more when laptops travel.

For a small business without a security team

An honest minimum that genuinely reduces risk:

  1. Turn on MFA everywhere, preferring app-based or passkeys over SMS
  2. Use your existing platform's security features — Microsoft 365 Business Premium and Google Workspace include substantial capability most organisations never enable
  3. Enable device encryption and automatic updates
  4. Deploy a password manager
  5. Back up, and test a restore at least once
  6. Write and rehearse a three-page incident plan: who to call, what to do first, who tells customers

Point 2 is the cheapest win available. Most SMEs are already paying for controls they have not switched on.

Frequently asked questions

Is MFA enough on its own?

It is the highest-value single control, but MFA fatigue and adversary-in-the-middle phishing are real. Phishing-resistant methods (passkeys, FIDO2 security keys) close most of that gap.

Should we monitor remote employees?

Security monitoring of company systems, yes. Productivity surveillance is a different thing — legally fraught in Europe, likely to require works council consultation, and corrosive to trust. Keep the two clearly separate.

What about staff working from other countries?

It raises tax, employment and data protection questions well beyond security. Have a stated policy on where people may work from, and make sure HR and finance own it jointly with IT.

Further reading

Security and governance

Discuss your security and governance requirements.

MENTARA can help structure technology implementation and delivery requirements without claiming legal or regulated advisory services.

Discuss the requirement
Weekly briefing

Enterprise technology intelligence, delivered weekly.

AI, cyber security, cloud, enterprise software and technology workforce guidance.

New guides and comparisons, no more than weekly.