Remote Work Without the Headaches: Practical Security Habits for SME Teams
There are many key benefits to remote working. It helps your team stay flexible, productive, and gives employees greater freedom over where and how they work. But it’s not without its trade-offs, with the number one concern being cybersecurity.
As more people work outside the traditional office environment, organizations need to think really carefully about how they protect company data, devices and systems from an increasingly sophisticated range of threats, and this can create a bit of a headache when it comes to keeping SME security consistent.
When everyone is in one place, working under the same roof, security policies and processes are generally easy to manage. Sure, it’s not fool proof, but ultimately, because everyone is working within the same controlled environment, it’s easier to keep an eye on things and make sure the right measures are in place.
But when your team is working remotely, that changes. Suddenly, everything is spread out, with employees responsible for their own devices and day-to-day security habits. So how exactly can you keep your business protected?
The key is to introduce practical security practices for your SME team to follow. These aren’t complicated or burdensome rules, these are straightforward, simple habits that will not only protect your business from common cyber threats, but help to make your team far more confident in spotting and avoiding common pitfalls.
Without any further ado, then, let’s run through them.
Make a VPN Standard Policy
One of the main problems of remote working is that your employees aren’t always going to be working from the same place. That is to say, sometimes they might be out and about, working from a coffee shop – they might even be working while on vacation abroad.
That introduces a seismic change in your security perimeter that you won’t be able to avoid – what happens if an employee connects to a public network and unknowingly exposes sensitive company information?
The answer is a company VPN that your team can switch to whenever they’re on unfamiliar networks. To give an example of how something like this works, imagine one of your employees connects to the Wi-Fi at a busy cafe. To keep themselves safe, they ask themselves, ‘what’s my IP?’, and use an online checker to see what their connection is exposing – but this only identifies a problem.
The point is, if their IP is public and the network is unreliable, knowing the address isn’t going to make the connection any safer. At best, they now know that their connection is exposed; at worst, they get a false sense of security.
With a VPN, however, the employee doesn’t have to rely on their IP address as a proxy for security. Their traffic is routed through an encrypted connection to the VPN server, and the services they access see the VPN’s public IP rather than the one actually assigned to their current network. In other words, they don’t need to worry about whether the cafe’s network is exposing their usual IP – the VPN gives them a more consistent, protected connection wherever they happen to be working.
Make MFA Non-Negotiable
Even if your employee is using a VPN and their connection is safe, that doesn’t stop their account from being compromised. On the contrary, even with all the best security practices in the world, an employee’s data can still be breached if they’ve failed in the most basic line of security.
We’re talking, of course, about passwords. According to a recent study, 78% of people use the same password across multiple accounts, which makes your company especially vulnerable if just one of your employees fits that pattern.
The answer for this one comes in the form of MFA. Whichever way you look at it, passwords are a weak point in your company’s security posture, and even a strong password can be compromised through phishing or a data breach.
Multi-factor authentication, however, adds another checkpoint so a stolen password alone can’t be enough to get someone in. This not only makes it significantly harder for an attacker to access an account, but it also means a reused password can still be a strong one, and that goes a long way when considering just how sophisticated the methods of stealing passwords have become in recent years.
Make Updates Automatic
One last security habit we should talk about is updates – and more specifically, how quickly you install those updates. Because remote workers can’t benefit from the same level of hands-on IT oversight as someone sitting in the office, this makes something as mundane as a software update surprisingly important.
If a laptop is running an outdated browser, for instance, your team could effectively be working with a vulnerability that’s already been discovered and, potentially, already exploited elsewhere. The practical habit, then, is simple: don’t make employees responsible for remembering to update everything themselves.
If you have company-managed devices – which you really should – you should be turning on automatic updates wherever possible, making sure company devices are configured to install security patches as soon as they become live.
It’s one of those measures that works best when nobody has to think about it: you’re not leaving anything up to chance and you’re not relying on your team to remember something that really isn’t their job to manage. There are plenty of other measures you can put in place – endpoint protection, device encryption, security training – but this measure and the other habits mentioned are certainly key, simple solutions that are making big differences in the remote working landscape today.



