Skip to main content

Blog

A tidy home-office setup with a laptop, external monitor and a handwritten numbered checklist in a notebook

Remote Working: The Security Checklist Most SMEs Miss

Remote Working: The Security Checklist Most SMEs Miss

Most small businesses in Kent now have at least some staff working from home part of the time. Very few have updated their security setup to reflect that. The result is a business that works fine in the office but has significant gaps the moment someone logs in from a home network or a kitchen table.

This is the checklist I work through when a new client has a remote or hybrid team. Tick the ones you have covered. The gaps are your priority list.

Devices and endpoints

Are your staff using company-managed devices?

If staff are working on personal laptops or home PCs, you have no visibility of what else is on those devices, whether they are patched, or whether they have proper security software installed. Personal devices used for work should at minimum be enrolled in Microsoft Intune (or equivalent) so you can enforce basic security policies.

Ideally, work is done on company-owned, company-managed laptops. If that is not possible yet, set a clear policy about what personal device use is acceptable and what it requires.

Is endpoint protection installed and managed centrally?

A home worker laptop sitting on a residential broadband line with no managed antivirus is a soft target. Microsoft Defender is built into Windows 11 and is genuinely good, but it needs to be centrally monitored so you know if it detects something, rather than relying on the staff member to notice and tell you.

Authentication and access

Is MFA enforced for all remote access?

This is non-negotiable. Every account accessed remotely, starting with Microsoft 365 and including anything accessible via a web browser, must have multi-factor authentication enabled. A password alone is not sufficient protection when that password could be phished from a home network.

Are you using Conditional Access?

Microsoft 365 Business Premium includes Conditional Access policies. These let you require MFA only from untrusted locations, block access from high-risk countries, and prevent downloads to unmanaged devices. If you are on Business Premium and not using Conditional Access, you are paying for a security feature you are not using.

Is there a VPN for internal resources?

If any of your systems are not fully cloud-based (a server in the office, a network-attached storage device, an on-premise application), remote staff need a secure way to reach them. A properly configured VPN is the right answer. "Just open a port on the router" is not.

Data and file storage

Are files in the cloud, not on local drives?

If a home worker saves documents to their laptop local drive instead of OneDrive or SharePoint, those files are not backed up, not accessible to colleagues, and potentially on a personal device that you cannot recover if they leave. Enforce cloud storage. Turn on "known folder move" in OneDrive so the desktop, documents, and pictures folders sync automatically.

Is there a clear rule about USB drives and personal email?

Personal email accounts and USB drives are common routes for data leaving the business. Your remote working policy should address both explicitly. Most businesses should be restricting both via device management policy, not just relying on staff to exercise judgement.

Home network security

Have you advised staff on home router security?

You cannot mandate what home router a staff member uses, but you can advise: use WPA3 encryption if available, change the default router password, do not use the router default network name (which often reveals the make and model), and keep the router firmware updated.

A business-grade 4G/5G router supplied by the company is worth considering for staff who regularly handle sensitive data at home. It removes the variable of the home network entirely.

Monitoring and visibility

Do you know if a remote device has been compromised?

Without central management, the honest answer for most small businesses is no. A managed IT support contract that includes remote monitoring means you have visibility of device health, patch status, and security alerts across all devices, wherever they are.

Training and policy

Do staff know what is expected of them when working remotely?

A written remote working policy covers: which devices are permitted, where files must be saved, when VPN must be used, what to do if a device is lost or stolen, and who to contact if they notice something suspicious. Without it, staff make their own decisions, and those decisions are not always the right ones.

If you would like me to review your current remote working setup and identify the gaps, get in touch. Most reviews take a couple of hours and produce a clear action list.

Cyber security services

ClearPath IT Services provides remote working security reviews and managed IT support for small businesses across Kent, Medway and South East London.

ClearPath IT Services

Personal, reliable IT support for small businesses across Kent, Medway and South East London.

Clear IT. Sorted.

Get in Touch

Based in Kent, serving businesses across Medway, Dartford, Gravesend, Sidcup, Bexley and South East London.

Call: 0333 360 8308

Visit: 1a Saddington Street, Gravesend, DA12 1ED

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Contact me


© 2026 ClearPath IT Services Limited. All rights reserved. | Privacy Policy