Remote work has not created new threats. It has shifted the terrain. The protections you patiently built in your offices, the firewall, the controlled network, the colleagues who notice what is going on, do not follow the employee who works from home, from a train, or from a client’s waiting room.

The good news: the measures that close this gap are few, and largely within reach of an SME. Some are even already present on your devices, simply switched off.

What changes as soon as you leave the office?

Only three things, but they matter.

The network is no longer yours. At the office, you know who is connected and what filters the traffic. At an employee’s home, traffic passes through a router you do not manage, shared with game consoles, televisions, and sometimes flatmates.

The device is not always yours either. In many French-speaking Swiss SMEs, remote work took hold with whatever equipment people had on hand. A family computer, a personal phone onto which the business mailbox was added.

Visual oversight disappears. No one notices any more that a screen has been left open, that a laptop was left on a café table, or that an employee is following the unusual instructions in a fake e-mail. This absence of outside eyes is underestimated: it is nonetheless one of the reasons why CEO fraud attempts work better when the targeted person is working alone.

Is public Wi-Fi really dangerous?

The classic fear of hotel Wi-Fi largely belongs to the past. Almost all professional sites and services now use HTTPS, a protocol that encrypts content between your device and the service: the person at the next table does not read your e-mails, even on an open network.

The risk has shifted to two other, more discreet, points.

The fake access point. Anyone can create a network named “Hotel_Guest” or “Free_Station_Wifi”. A network’s name proves nothing. Once connected, the attacker controls what your device sees: they can display a login portal asking for a business address and password, or push an error message inviting you to install a “certificate” or an update.

Vigilance while on the move. On the move, people read quickly, on a small screen, between two appointments. This is exactly the context in which a phishing e-mail works best.

Typical scenario: the hotel portal

An employee at a seminar connects to the hotel network. A page appears: "Session expired, please log in again with your business address." Habit with captive portals does the rest. The business mailbox password ends up with a third party. No legitimate Wi-Fi portal needs your business password.

The countermeasure comes down to two reflexes. Prefer the phone’s tethering when possible, it is simple, fast, and under your control. And only enter a business login on a site you opened yourself, never from a page that appeared on its own.

Disk encryption: the most cost-effective measure

If there is only one point to take away from this article, it is this one.

An unencrypted laptop protects nothing at all. The session password can be removed within minutes with a bootable USB key, or by simply removing the drive to plug it in elsewhere. Everything the machine contained becomes readable: contracts, quotes, client lists, archived e-mails, passwords saved in the browser.

With an encrypted drive, the same theft becomes a hardware problem. The data is unreadable without the password, and the damage is limited to the price of the device.

You probably already have it, without knowing it

On Mac, the feature is called FileVault. On Windows Professional, BitLocker. On recent phones, encryption activates as soon as an unlock code exists. No purchase, no noticeable performance loss. The only point to watch: keep the recovery key somewhere other than the device, in the company's password manager or in a physical safe.

Check device by device, including older machines and those belonging to people who are rarely at the office. That is precisely where you find the ones that were forgotten.

Should personal devices be accepted at work?

This is the question that makes SMEs most uncomfortable, because the ideal answer (equipment provided to everyone) is not always affordable. Better to state the problem frankly.

When an employee works from their personal machine, the company controls neither the system updates, nor the software installed, nor the other uses of the device. You also cannot wipe it remotely, or impose anything on it without their consent.

Here is what remains realistic.

SituationRealistic approach
Personal device, occasional accessEverything via browser, no local copy of files, mandatory two-factor authentication
Personal device, regular useSeparate a dedicated work profile, require an up-to-date system and an encrypted drive, put in writing what is allowed
Sensitive data or administrator accessCompany-provided equipment, no exceptions
Personal phone with business mailboxUnlock code, automatic updates, ability to revoke remote access

A word on the last point: in most professional tools (Microsoft 365, Google Workspace, and their equivalents), you can revoke a device’s sessions from the admin console. This does not wipe the phone, but it does cut off access. Know where this button is before you need it.

Finally, put in writing what is permitted. One page is enough. In the event of an employee’s departure or an incident, the absence of a written rule is what costs the most.

The screen, the session, and prying eyes

Automatic session lock is the simplest measure of all, and one of the least applied. Set it to a few minutes of inactivity, on computers as well as phones. A laptop left open in a coworking space, a waiting room, or a train is accessible to anyone passing by.

And the screen itself speaks. On a train, the person next to you reads a salary table or a client name without any particular effort. This is not cybersecurity in the strict sense, but the leak is very real. A privacy filter costs little and solves the problem for people who often work while travelling.

Data that exists only on a laptop

This is the most frequent oversight of nomadic work. The server backup runs every night, no one worries. Except that the report in progress, the site photos, and the sales tracking file exist only on a laptop, in a local folder, and have never been copied anywhere.

A disk failure, a theft, or a spilled coffee is then enough to wipe out weeks of work. Two responses work, and they combine well. Make sure work files sit from the outset in a synchronised and backed-up space, rather than on the machine’s desktop. And check that this space is genuinely covered by a real backup, which is not automatic: synchronisation is not a backup, as explained in our article on the 3-2-1 rule.

What remote access requirements should you enforce at minimum?

If your employees need to reach a server, a file share, or an application hosted on your premises, three requirements are non-negotiable.

No internal service exposed directly on the internet. A publicly accessible remote desktop is scanned and attacked constantly by bots. Access must go through an encrypted tunnel (VPN) or a gateway designed for that purpose.

Two-factor authentication on all remote access, including the VPN itself. A password stolen through phishing then becomes insufficient on its own.

Named individual accounts, and immediate revocation on departure. The shared “office” account whose password is still known by three former employees is a classic, and it is undetectable in the logs.

Check what is visible from the internet

Many remote access points were opened in a hurry, in 2020, and no one has closed them since. They still work, without two-factor authentication, with the original accounts. Take stock of what is reachable from the outside before asking whether the rest is properly configured. The public exposure tool gives a first overview.

A general rule will not be enough

These measures form a solid foundation, and they rule out the vast majority of automated incidents. They do not, however, say much about your own particular situation.

Remote work multiplies configurations. A six-person accounting firm where everyone works on a single hosted piece of software does not have the same weak points as an engineering office that moves multi-gigabyte plans around, nor as a medical practice whose data cannot leave the premises. And within a single company, usages diverge: a salesperson working from their phone, an accountant pulling files onto their laptop, management checking e-mails from a family tablet.

That is the limit of a checklist, even a well-applied one. The real gaps become visible when you look at how people actually work, where files travel, which access points still exist, and who uses them. Things no one volunteers in a questionnaire, often because no one perceives them as a problem.

Start with the foundation. The cyber check-up situates your level within a few minutes, and the other priority measures are grouped in the Best practices pillar, notably the 10 essential measures. Only then should you have what really matters at your company checked.