Remote & Hybrid Work Security: A Guide
Remote and hybrid work are now permanent features of public sector life — and every home office, personal device, and remote connection extends your network beyond the walls you control. Here is KYND's guide to securing remote and hybrid work.
What are the risks of remote and hybrid work?
When staff work outside the office, organizational data flows through home Wi-Fi networks, personal (“bring your own”) devices, public hotspots, and cloud collaboration tools. Each is outside the protections of the office network, creating common exposures: unpatched home routers, shared family computers, unencrypted laptops, and remote access services reachable from the internet.
Why does remote work increase exposure?
Traffic no longer passes through the office firewall and monitoring, so compromises are harder to detect. Personal devices may lack updates, encryption, and endpoint protection, and staff working alone can't lean over to a colleague to sanity-check a suspicious request — making social engineering more effective at a distance.
Why should public entities pay attention?
Many public entities adopted remote access quickly during the pandemic, sometimes by exposing legacy systems that were never designed for it. Staff now routinely handle resident data, court records, and payment systems from home, and exposed remote access services such as VPNs (virtual private networks) and RDP (remote desktop protocol) remain leading entry points for ransomware.
What if we don't secure remote work?
A single compromised home device or unprotected remote login could give an attacker the same access a trusted employee has, becoming the entry point for ransomware or data theft. Records kept on personal devices can also complicate public records compliance and breach-scope assessment.
Which frameworks should we align to?
NIST Cybersecurity Framework (CSF) 2.0 addresses remote work largely through the Protect function — identity, access control, and data security. In CIS Controls v8, the most relevant are Control 6 (Access Control Management), Control 4 (Secure Configuration), and Control 12 (Network Infrastructure Management).
Process defenses: set expectations in policy
Adopt a remote work policy defining which devices and services are approved, how sensitive data may be stored and shared, and how quickly lost or stolen devices must be reported. Train staff on home network basics — updating routers, strong Wi-Fi passwords — and on avoiding public Wi-Fi for sensitive work.
Technical controls that reduce remote work risks
Require MFA (multi-factor authentication) on VPN, email, and cloud accounts, and prefer organization-managed devices with full-disk encryption, automatic updates, endpoint protection, and screen locks. Keep RDP off the public internet, and ensure remote endpoints are covered by the same monitoring as office machines.
Checklist
When building or reviewing your remote and hybrid work security, consider the following:
- Is MFA enforced on all remote access, including VPN, email, and cloud services?
- Do remote staff use managed devices, or personal devices meeting enforced security standards?
- Are laptops encrypted, set to auto-lock, and covered by endpoint protection and updates?
- Is a remote work policy in place covering approved devices, data handling, and public Wi-Fi use?
- Do staff know how to report a lost or stolen device immediately, and is the process tested?
- Is remote desktop protocol (RDP) blocked from the public internet or gated behind VPN with MFA?