Remote Work
Working From Home Without Putting Work Data at Risk: A Practical Personal Setup Check
A practical, non-technical home-working checklist for protecting accounts, devices, networks, and sensitive work information.
Use approved devices and accounts
Start with the organisation’s approved device, operating system, storage, collaboration tools, and account settings. These may include encryption, managed updates, backups, and security monitoring that are not present on a personal laptop. Do not forward work files to a personal email address, copy them into an unapproved note app, or use a personal cloud drive simply because it feels convenient. Convenience can create an uncontrolled copy of sensitive information.
If a work device is unavailable or unsuitable, ask IT or your manager for an approved alternative before improvising. Explain the task and deadline, not more data than necessary. Requirements may differ for contractors, regulated information, or cross-border work, so a colleague’s workaround is not proof that it is permitted. Security guidance should be documented and accessible, especially for new remote staff.
Before starting, confirm the device inventory tag, supported operating-system version, endpoint protection, and approved work account. If a personal device is permitted, separate work data as policy requires. Do not solve a missing access problem by forwarding files to a private account.
Protect sign-in credentials
Use a long, unique password for every work account and enable multi-factor authentication when it is offered or required. A password manager approved by your organisation can make unique passwords practical. Never share passwords, authentication codes, recovery codes, or security keys, including with someone claiming to be IT. Legitimate support teams should have a verified way to help without asking for your secret.
Treat unexpected sign-in prompts and password-reset messages as possible phishing. Check the sender, address, and destination carefully, and use a known bookmark or official app instead of a link in a message. If you entered information into a suspicious page, report it immediately through the organisation’s security route. Fast reporting lets the team revoke sessions or reset credentials before a small mistake becomes a larger incident.
Use a password manager approved by your employer, unique passwords, and phishing-resistant multi-factor authentication where available. When a login prompt arrives unexpectedly, open the known service directly instead of following the message link, then report suspicious prompts through the security channel.
Keep your device physically safe
Lock the screen whenever you step away, even at home. Keep work devices in a secure place, avoid leaving them visible in a car or shared space, and be careful with screens during travel or video calls. Use a privacy screen or reposition your desk if housemates, visitors, or people in a public place can see sensitive material. Physical access can expose data as effectively as a weak password.
Separate work from personal use where policy requires it. Children, guests, and family members should not use a managed work device or borrow it for quick tasks. Store paper records securely and use the organisation’s approved destruction method when they are no longer needed. If a device, badge, paper file, or storage drive is lost or stolen, report it promptly even if you think it was locked.
Lock the screen every time you step away, keep paper records out of view, and avoid discussing confidential work where others can hear. In shared housing or travel, use a privacy screen and secure storage. Lost equipment can create reporting duties under local and contractual rules.
Use networks deliberately
Secure your home router with a strong administrator password, current firmware, and modern Wi-Fi encryption. Avoid using a shared public network for sensitive work unless your organisation has provided a secure, approved method such as a managed connection or VPN. A network name that sounds familiar is not evidence that it is safe. Follow the configuration instructions provided by your employer rather than downloading an unofficial tool.
Do not disable security controls to solve a connectivity problem. Contact the approved support route and describe the error, device, and urgency. If you must work from a different location, consider who can see your screen, overhear calls, or access the network. Some organisations restrict where particular data can be accessed because of contractual, regulatory, or cross-border requirements; check before changing your normal setup.
Treat public Wi-Fi as untrusted. Prefer a trusted network or approved mobile hotspot, use the organisation’s required secure connection, and disable automatic sharing. A cafe connection is not an excuse to bypass security controls; delay sensitive work until a safer connection is available.
Handle data with care
Collect, download, and share only the information needed for the task. Check recipients before sending email or granting access, particularly when names autocomplete. Use approved sharing links with the narrowest practical permission and expiry. Avoid putting sensitive details into meeting titles, screenshots, or public chat messages. Classifications and rules vary, so follow your organisation’s data-handling policy where it is stricter than general advice.
Be cautious with generative AI tools, browser extensions, transcription services, and free file converters. They may process or retain content outside approved systems. Do not paste confidential work material, personal data, client information, source code, or credentials into a tool unless your organisation has explicitly approved that use. Ask the data owner or security team when the policy is unclear; guessing can create a reportable incident.
Use the approved classification and sharing labels before downloading, printing, or sending data. Check recipients and access expiry, particularly for customer data, health information, payment details, and source code. Cross-border transfers can have separate legal and contractual restrictions.
Know how to report a concern
Report suspicious messages, accidental disclosure, lost equipment, unusual account activity, or malware warnings through the official security contact as soon as possible. Include the facts: what happened, when, which account or device is involved, and what actions you already took. Do not attempt to hide an error or investigate beyond your role. Early, factual reporting gives specialists the best chance to limit harm.
An incident report is not a legal conclusion and should not include unnecessary personal information. Follow local emergency procedures if there is a physical threat. Your organisation may have additional obligations to customers, regulators, or affected people, so let the authorised response team decide notifications. A calm, practiced setup check reduces risk, but it cannot eliminate it; reporting and learning are part of secure remote work.
Report a lost device, misdirected email, suspected phishing attempt, or exposed file immediately, even if you are unsure harm occurred. Preserve what you can without investigating alone. Follow the incident process and urgent local safety instructions; fast reporting supports required containment and notification.