RSS Amplifier

CyberInsights · Jul 19, 2025

Remote Work: A Security Risk?

0
Sign in to vote or save

CyberInsights · CyberInsights

Introduction

Remote and hybrid work have become the norm since the COVID-19 pandemic. Even though some companies are encouraging a return to the office, many employees continue to work from home, drawn by the flexibility and improved work-life balance it offers.

For businesses, the benefits are clear. Operating costs can be reduced, and employee satisfaction often improves. However these advantages come with significant risks that are often overlooked.

Working from home introduces serious challenges around cybersecurity and data protection. In August 2020 INTERPOL reported huge increases in cyberattacks between January - April 2020 against large organisations, highlighting difficulties in the transition from office based work, to home based work.

This article explores the key risks associated with remote work and outlines practical steps that both companies and employees can take to stay secure and effective while working from home.

Cybersecurity Threats

What are the risks that organisations face with work-from-home policies?

To start with, home networks are usually much less secure than corporate environments. Employees working remotely often rely on consumer-grade routers without enterprise-level firewalls or monitoring. This makes them easier targets for attackers.

Another issue is the use of personal devices without proper endpoint detection. Without managed antivirus software, automatic updates, or encryption, these devices can be weak points for malware, data leaks, or unauthorised access.

Phishing and vishing attacks have also increased significantly. Remote workers are more likely to fall for fraudulent emails or phone calls, especially when isolated from their teams or overwhelmed with IT issues. These attacks don’t need technical sophistication, they rely on social engineering and psychological pressure.

There is also some evidence, though still debated, that remote work can lead to increased dishonesty and risk-taking. Employees who feel disconnected from their organisation may be more likely to ignore policies, mishandle sensitive data, or even sell it. Research published in the National Library of Medicine links remote work with increased mental health issues and moral disengagement, both of which are associated with unethical behaviour.

One of the most striking real-world examples came in July 2020, when 69 high profile Twitter accounts were hacked as part of a cryptocurrency scam. The attackers used social engineering, not malware or exploits, to target Twitter employees working remotely. They impersonated IT staff and took advantage of ongoing VPN issues, which had become common after Twitter’s shift to remote work during the pandemic.

According to the Department of Justice, the attackers created a fake VPN login page and tricked employees into entering their credentials. When multi-factor authentication was triggered, the attackers prompted employees to approve the login in real time (a tactic known as MFA fatigue. Some employees fell for it.

The breach did not occur because of advanced hacking techniques. It succeeded because of operational vulnerabilities linked to remote work:

  • No Chief Information Security Officer (CISO) was in place at the time.

  • Twitter failed to implement compensating controls after transitioning to remote work.

  • VPN issues were common and expected, which made fake IT support calls seems credible.

  • Employees were not properly trained to spot or respond to vishing attacks.

The DOJ concluded that the attack was a “cautionary tale” about how easily even unsophisticated attackers can bypass systems when security awareness is low and leadership oversight is lacking, both of which are more likely in fully remote environments.

What Companies Can Do

Remote work is not going away, but the security risks that come with it can be managed. Companies must take a proactive approach to security:

  1. Implement Stronger Access Controls

    • Use role-based access to ensure that employees only have the permissions that they need.

    • Enforce least privilege principles, especially for those with access to sensitive systems.

    • Regularly audit access rights and revoke unused or outdated permissions.

  2. Harden Authentication Methods

    • Use multi-factor authentication (MFA), but educate employees on avoiding MFA fatigue.

    • Consider phishing-resistant MFA methods like hardware tokens or biometric authentication.

    • Monitor for unusual MFA patterns (e.g. repeated approvals within short timeframes).

  3. Provide Regular Security Training

    • Train employees to recognise phishing and vishing attempts (not just through PowerPoint slides but through interactive simulations). It is incredibly important to get employees involved and interested.

    • Teach staff to report suspicious activity, even if they aren’t sure.

    • Emphasise the risks of oversharing internal problems (like VPN issues) in public forums or insecure channels.

  4. Improve Incident Reporting Culture

    • Make it easy and safe for employees to report suspected social engineering attempts without fear of being blamed.

    • Include clear escalation paths.

    • Reward quick reporting, its often the fastest way to stop a breach in progress. Employees are likely to respond well to a reward based culture.

  5. Strengthen Technical Infrastructure

    • Enforce endpoint protection on all devices that connect to corporate systems.

    • Ensure regular patching, disk encryption, and remote wipe capabilities.

    • Segment sensitive environments so that a breach in one area doesn’t compromise everything.

  6. Appoint and Empower Security Leadership

    • Make sure that your organisation has a dedicated CISO or equivalent role with the authority to drive change.

    • Avoid “check-the-box” compliance. Security must be operational, not just regulatory.

  7. Simulate Real World Environments

    • Run regular phishing and vishing drills with measurable outcomes.

    • Conduct tabletop exercises for the executive team so they’re prepared for response coordination in case of an incident.

  8. Communicate Securely and Consistently

    • Establish standard protocols for how the IT department contacts staff (e.g. never ask for credentials over the phone).

    • Publish a clear internal policy about how to verify IT requests or report suspicious contact.

Conclusion

The shift to remote work has created a more flexible and cost effective way of operating, but it has also introduced serious and sometimes overlooked cybersecurity risks. Weak home networks, unmanaged devices, social engineering, and a lack of physical oversight can all open the door to attacks.

Organisations must respond by taking home work security as seriously as they would any other core business risk. That means improving access controls, investing in employee awareness, strengthening infrastructure, and ensuring leadership is fully engaged.

Cybersecurity in remote environments is not just an IT problem, it’s a company wide challenge that requires cultural, procedural, and technical changes. The organisations that recognise this and act on it will be far better positioned to protect their people and their data.

Authors Note

Although this was a very interesting topic to write about I feel that I barely scratched the surface. If you found this article interesting please let me know. I’d be happy to write more pieces that dig deeper into the challenges of remote work and cybersecurity.

This piece reflects my own views and opinions and should not be taken as definitive fact.

If you found this article interesting please consider subscribing or sharing it with others. Thank you for reading, your support means a lot.

No posts

Read the original on getcyberinsights.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.