A VPN Is Not Enough: 8 Remote-Work Security Controls That Close the Gaps

The security baseline for remote work now extends well beyond installing antivirus software and connecting to a VPN. A safer setup combines protected accounts, supported devices, verified communications, controlled access to company data and a recovery plan.
Traditional advice about updates, firewalls and backups remains useful, but account protection has advanced. The NCSC’s account guidance, reviewed in July 2026, recommends passkeys where available and otherwise calls for a unique password, two-step verification and a password manager. That is a more useful standard than relying on a short checklist of password characters.
1. Follow the company’s device and access rules
Use an employer-managed computer when one is provided. Its security settings, approved applications and monitoring tools may be centrally controlled, so replacing it with a personal laptop can remove protections that are invisible to the user. Do not disable management software, endpoint protection or browser controls to make the device more convenient.
If personal devices are permitted, confirm what the bring-your-own-device policy allows before downloading files or adding a work account. Keep work data inside the approved application, browser profile or managed workspace, and do not copy it into personal email, messaging services or cloud storage. For everyday work, use a standard device account rather than an administrator account; reserve elevated access for a task that genuinely requires it.
2. Lock the device and protect stored data
A remote laptop may be used in a shared home, carried to a coworking space or left briefly in a vehicle. Configure a short automatic-lock interval and require a PIN, password or supported biometric check when the device wakes. Lock it manually whenever you step away, even at home.
Current NCSC device guidance recommends controlling access to phones, tablets and computers, keeping their software supported, and checking that built-in antivirus and firewall protections remain enabled. Full-disk encryption adds protection if a powered-off laptop or removable drive is lost, but it does not protect an unlocked session; physical security and screen locking still matter.
3. Install updates and retain the built-in defenses
Enable automatic updates for the operating system, browser, work applications and security tools. An update may download without becoming active until the application or device restarts, so do not indefinitely postpone restart prompts. Remove software that is no longer needed, particularly if its publisher no longer supplies security fixes.
Modern operating systems normally include a firewall and malware protection. Confirm that both are active instead of assuming that purchasing another security package is automatically safer. If an employer supplies endpoint software, do not install a competing product without approval: overlapping tools can create operational problems, and the company may depend on its chosen agent for alerts and incident response.
4. Prefer passkeys; otherwise use unique passwords
Enable a passkey when a work service and company policy support it. Passkeys are tied to the legitimate service and are designed to resist the credential theft used in conventional phishing. Follow the employer’s recovery procedure as well, because access to the device holding a passkey can still be lost.
Where passwords remain necessary, generate a different one for every account and store it in an approved password manager. The important properties are length, unpredictability and uniqueness—not repeatedly changing a memorable password or adding a predictable symbol. Protect the password manager itself with its strongest available sign-in method and keep recovery codes somewhere approved and separate from the device.
5. Turn on the strongest available multifactor authentication
Multifactor authentication should protect email, collaboration tools, cloud storage, code repositories, remote access and any account with administrative privileges. Prefer the phishing-resistant method approved by the organization, such as a passkey or hardware security key. If those options are unavailable, an authenticator application is generally preferable to relying only on a password.
Never approve an unexpected login notification simply to make repeated prompts stop. Reject it, change the affected password if one exists, and report the event through the company’s security channel. An unsolicited approval request may mean that someone already has the first sign-in factor.
6. Verify unexpected requests outside the message
Remote work reduces the informal checks available in a shared office, making an urgent message from a supposed manager, supplier or IT technician harder to assess. Treat unexpected requests for credentials, MFA approval, payment, sensitive files or software installation as unverified. Do not use the phone number, link or reply address supplied in the suspicious message.
Confirm the request through a known channel, such as a saved company directory entry or an established conversation. Inspect the actual sender address and destination before opening a link, but remember that a familiar-looking display name is not proof of identity. Report suspicious messages using the organization’s designated process; deleting them without reporting can leave colleagues exposed to the same campaign.
7. Use the access path chosen for the work
A VPN is not a universal substitute for secure accounts and devices. Use the employer’s configured VPN when policy requires it for internal systems, and verify that it has connected before opening those systems. Do not install an unapproved consumer VPN on a managed computer or assume that every cloud application needs a separate tunnel.
On an unfamiliar network, avoid sensitive work until you can use a connection permitted by company policy, such as a trusted hotspot. Disable automatic joining of open Wi-Fi networks and stop sharing services you do not need. Even on a home network, keep the router’s firmware supported, replace default administrator credentials and use the strongest wireless security mode available to your devices.
8. Keep recoverable copies in approved locations
Store work in the organization’s approved repository rather than only on the laptop desktop. Synchronization can preserve accessibility, but it should not automatically be treated as a complete backup: unwanted encryption, deletion or overwriting may also synchronize. Workers should know which folders are protected and whom to contact when a file must be restored.
The NCSC’s data-security recommendations call for protecting information both in transit and at rest, using encrypted and authenticated protocols, maintaining multiple backups in different locations, isolating at least one recovery copy, and testing restoration. For an employee, the practical action is to use the company’s backup workflow rather than improvising with a personal USB drive or cloud account. For the organization, a backup is credible only when authorized staff can restore the required data without depending on the compromised device.
These controls work as a system. A VPN cannot rescue a phished account, antivirus cannot recover the only copy of an encrypted file, and a strong password cannot protect an unlocked laptop. The most useful remote-work check is therefore whether accounts, devices, communications, network access and recovery remain protected together.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.