The Security Perimeter That Disappeared
Enterprise cybersecurity for most of the past three decades was built around the concept of a perimeter: the corporate network was inside the perimeter and trusted; the internet was outside and untrusted. Controls — firewalls, managed devices, network monitoring, access controls — were deployed at the perimeter boundary, and employees who worked within the corporate office were inside the protected zone by default. Remote work dissolved this perimeter. The employee working from their home office is outside the corporate network, on a home network the IT department didn’t configure, using a combination of corporate and personal devices, and accessing corporate systems over the public internet.
The security risks that remote work creates aren’t primarily about the employee doing something irresponsible — they’re structural, arising from the security architecture that home environments represent compared to corporate ones. Understanding these structural risks allows remote workers to address them specifically, rather than relying on corporate security awareness training that was designed for in-office environments.
The Home Network as the First Risk
The home router that most remote workers use to connect to corporate systems is configured by the ISP for convenience rather than security, may not have received firmware updates in years, and is shared with every other device in the household — including IoT devices with poor security track records (covered in the Cyber Security section of Vol. 2). The corporate network you’re accessing through this router has security controls; the router itself typically doesn’t.
The minimum home network security improvements for remote workers: change the router admin password from the default (covered in Vol. 1), ensure Wi-Fi encryption is WPA2 or WPA3, keep router firmware updated, and use the IoT device isolation that guest network segmentation provides. If the corporate VPN requires connection through the home router, these measures protect the path between your device and the VPN gateway.
Device Separation: The Business Case for a Dedicated Work Machine
The remote worker who does personal browsing, gaming, and family use on the same machine that accesses corporate systems is creating risk that wouldn’t exist if these uses were separated. Personal use introduces the risk of malware (from game downloads, cracked software, less careful browsing habits) onto a device that also holds or accesses corporate credentials, files, and systems. The malware that compromises a gaming download that runs on the corporate laptop may exfiltrate the corporate credentials that exist on the same machine.
The security ideal: a separate device for personal use and the corporate laptop used exclusively for work. This isn’t always practical, but when the corporate device is employer-provided and the employer has restrictions on personal use, it’s also employer policy. For self-employed remote workers who provide their own equipment, the business case for a separate work machine is the data separation and liability reduction it provides alongside the security benefit.
Video Call Security: The Risk in Plain Sight
Video calls from home offices create a specific information security risk that’s often invisible: what’s visible in the background, audible in the conversation, and present on shared screens. Background environments (documents, whiteboards, name badges, organizational charts) visible in video calls have been used by social engineers to gather information about targets. Confidential conversations held in home offices where other household members are present may be overheard. Shared screens that include more than the intended content reveal information to all participants.
The practical precautions: use virtual backgrounds for external calls when the home office contains anything that shouldn’t be visible to external parties, be aware of what’s audible before speaking about sensitive topics in a space shared with others, and review what’s visible on screen before sharing (close unnecessary applications, check the taskbar for application names that reveal unintended context). These aren’t paranoid measures — they’re appropriate professional precautions for calls with external participants.
The Shadow IT That Remote Work Creates
Remote workers who can’t access corporate tools easily often find alternatives — using personal Dropbox to share files that can’t easily be sent through corporate channels, using WhatsApp for quick coordination that the corporate messaging system handles awkwardly, using personal email to receive work files when the corporate email is inaccessible. This ‘shadow IT’ creates data handling risks that IT departments are often unaware of and that create compliance exposure.
The solution isn’t primarily about policy enforcement — it’s about making the official tools work well enough for remote workers that the workarounds aren’t necessary. When remote workers are using personal cloud storage because the corporate SharePoint is too slow to access from home, the right response is fixing the SharePoint performance, not issuing another policy reminder about approved tools. IT teams that understand what workarounds remote workers are actually using can address the underlying friction rather than just the symptom.
