Remote workers protect data best by using approved devices and services, updating software promptly, enabling the strongest supported multifactor authentication, using unique credentials through an approved password manager, and treating unexpected links, attachments, login prompts, and data requests as untrusted. Keep work information out of personal email, consumer file sharing, and unapproved AI tools. Protect screens and conversations in shared spaces. If something feels wrong, disconnect only when policy directs, preserve evidence, and report quickly through the employer’s official incident channel rather than trying to investigate alone.
Start with the employer’s rules
Security responsibilities depend on the organization, data, role, and jurisdiction. Locate the remote-work, acceptable-use, device, data-classification, incident, and travel policies. Know the help-desk and security contacts before an event. Do not install security software, change configurations, or use a personal VPN on a managed device unless authorized.
Separate work and personal activity. Prefer managed accounts and devices. If bring-your-own-device work is permitted, follow the organization’s controls for updates, encryption, screen lock, storage, backup, remote wipe, and support. Family or housemates should not use a work device or know its credentials.
Protect identity and access
Use unique passwords stored in an approved password manager and enable MFA. CISA recommends stronger, phishing-resistant MFA where available. No MFA is magic: attackers can abuse push fatigue, fake prompts, sessions, or consent screens. Read every prompt, deny unexpected requests, and report them.
Use least privilege. Do not stay signed in as an administrator for routine work. Lock the screen when stepping away and return equipment or access promptly when a role changes. Never share an authentication code with a caller or “support agent.”
Handle data deliberately
Learn the organization’s data classes and approved storage, transfer, printing, retention, and deletion routes. Do not forward work to personal email for convenience. Check recipients and sharing permissions before sending. Limit downloaded copies and avoid public USB charging or unknown removable media. Store paper securely and shred it through an approved method.
Before entering work content into an AI assistant, transcription bot, browser extension, or meeting tool, confirm that the service and exact use are approved. Public tools can retain prompts or expose sensitive material. Approval for one system or data class does not imply approval for all.
Home, travel, and meeting privacy
Position screens away from windows and shared walkways or use an approved privacy filter. Use a headset for confidential calls and confirm who is present before sharing. Smart speakers, home cameras, and personal assistants can create unintended recording or exposure; follow policy and disable or relocate them where appropriate.
Avoid discussing sensitive work in cafés, airports, rides, or shared accommodation. Treat travel networks and physical access as higher risk. Use approved connectivity, keep devices with you, and report loss immediately. A VPN can protect network traffic in specific configurations but does not make phishing, malware, or oversharing safe.
How to apply this: 15-minute readiness checklist
Confirm: automatic updates are on; screen lock works; approved MFA is enabled; password manager is available; backups follow policy; work files are in approved storage; personal forwarding is absent; emergency contacts are saved; the home router uses current supported security; meeting privacy is adequate; and unapproved extensions or AI tools are removed through the proper process. Record unresolved items and ask IT rather than improvising.
Engagement: incident decision aid
| Signal | Immediate safe action | Report with |
|---|---|---|
| Unexpected MFA prompt | Deny; use official contact | Time/account/screenshot if safe |
| Suspicious link opened | Stop interaction; follow policy | Message, URL, actions taken |
| Device lost | Call security/help desk promptly | Device, time, last location |
| File shared wrongly | Do not conceal it | File, recipients, permissions |
| Ransomware signs | Follow incident instructions | Device and visible symptoms |
Fast, honest reporting can reduce harm. Do not delete logs or messages unless directed.
Human and privacy safeguards
Security monitoring should be lawful, proportionate, transparent, and limited to legitimate need. Workers should not use this article to surveil colleagues or household members. Accessibility needs can affect authentication and device controls; request an approved accessible alternative rather than weakening protection silently.
Stale-content cleanup
Remove “a VPN makes you safe,” universal antivirus recommendations, unsupported breach statistics, product affiliates, and advice to reconfigure employer systems. Add phishing-resistant MFA, approved AI use, physical privacy, rapid reporting, accessibility, and a reviewed date. Recheck CISA and NIST guidance annually.
FAQ
Is a VPN enough for remote-work security?
No. It may protect network traffic, but identity, device, phishing, permissions, data handling, and incident response still matter.
Can I use a personal computer for work?
Only if the employer permits it and required controls are followed. Prefer a managed device where provided.
What if I clicked a suspicious link?
Stop interacting, follow the organization’s incident instructions, and report what happened promptly. Do not hide it or conduct an unauthorized investigation.
Can I paste work into an AI tool?
Only when the exact tool, account, purpose, and data are approved under employer policy.
Internal links
/jobs/— verified remote roles/job-scam-checker/— assess suspicious recruiting messages/remote-resume-builder/— handle application data carefully/interview-preparation/— practice secure remote interviews
Sources
- NIST telework and BYOD security: https://csrc.nist.gov/pubs/sp/800/46/r2/final
- CISA multifactor authentication: https://www.cisa.gov/more-password
- CISA Secure Our World: https://www.cisa.gov/secure-our-world
- CISA ransomware guide: https://www.cisa.gov/stopransomware/ransomware-guide
- NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework

