Remote Working Security Checklist
When staff work from home, a café or a client site, the office firewall no longer protects them. Security then depends on the device, the connection, the account and the person. This checklist covers the basics every business should confirm for anyone working away from the office.
Step 1: Devices
- Every device used for work is known to the business — including personal devices.
- Disk encryption is enabled (BitLocker on Windows, FileVault on Mac).
- Operating systems and applications receive updates automatically.
- Anti-malware protection is installed and active.
- Screens lock automatically after a short period.
- The business can remotely wipe or disable a lost work device.
A lost laptop without disk encryption is a data breach, not just a hardware loss. Encryption is the single most important control for portable devices.
Step 2: Connections
- Home routers have had their default administrator passwords changed.
- Home Wi-Fi uses WPA2 or WPA3 encryption.
- A business VPN is used where remote access to internal systems is required.
- Staff avoid sensitive work on open public Wi-Fi, or use a phone hotspot or VPN instead.
- Remote-desktop access is never exposed directly to the internet.
Step 3: Accounts and sign-in
- Multi-factor authentication is enabled on email and every business cloud service.
- Work accounts are not used on shared family devices, or are separated with their own profile.
- Passwords are unique per service, ideally in a password manager.
- Staff know how to spot sign-in prompts they did not initiate — and to refuse them.
Step 4: Data handling
- Business files are stored in approved locations (OneDrive, SharePoint or equivalent), not personal drives.
- Files are shared through links with permissions, not personal email attachments.
- Confidential documents printed at home are collected, stored and shredded appropriately.
- Personal cloud accounts and personal email are not used for business data.
Step 5: Physical security
- Screens are locked whenever the device is left unattended.
- Privacy is considered when working in public — screens angled away, calls kept discreet.
- Devices are never left visible in cars or unattended in public places.
- Household members do not use work devices or watch sensitive work.
Step 6: When something goes wrong
- Staff know who to contact — immediately — if a device is lost or stolen.
- Staff report suspected phishing or unusual account activity without fear of blame.
- The business can reset passwords and revoke sessions quickly.
- Incident contact details are available somewhere other than the affected device.
Make it a routine
Run through this checklist when someone starts working remotely, when they change devices, and at least once a year for everyone who works away from the office.
Plain-English Takeaway
Remote working is safe when the basics are covered: encrypted and updated devices, trusted connections, MFA-protected accounts, approved storage locations and a fast way to report problems. Check them per person, not just per policy.
Downloadable guide
Download the Remote Working Security Checklist
A one-page printable checklist covering devices, connections, accounts, data handling and incident reporting for remote staff.
Download PDFFree download. No email address required.
Related Knowledge Centre resources
Is Your Business VPN Properly Protected?
Questions to ask about how your business VPN is set up, monitored and maintained.
Coming SoonMicrosoft Passkey Readiness Guide
Check which users, devices, authentication policies and recovery procedures your business should review before Microsoft retires its own SMS and voice authentication.
View guideCyber Essentials Readiness Checklist
Work through the key controls to review before applying for Cyber Essentials.
View guideBusiness Backup Checklist
Confirm what is backed up, where it goes and who checks that it works.
Coming Soon