Hybrid working brings real benefits — and real risks. Home networks, personal devices and coffee shop Wi-Fi all expand the surface attackers can target. Here’s a checklist that keeps things simple.
Devices
- Every laptop is company-managed (enrolled in Intune or similar), not just “password protected”
- Full-disk encryption is on for every device (BitLocker / FileVault)
- Endpoint protection is installed and reporting centrally
- Lost or stolen devices can be locked and wiped remotely
- Personal devices are kept away from company data (or properly secured if BYOD is genuinely a policy)
Access
- MFA is enforced on email and every system holding sensitive data
- Remote access goes through a managed VPN or zero-trust gateway — not port-forwarded remote desktop
- Leavers lose access on their last day, every time
- Admin accounts are separate from day-to-day accounts
Data
- Files live in OneDrive/SharePoint, not on local desktops or personal Dropbox accounts
- Sharing defaults are sensible (no “anyone with the link” organisation-wide)
- Backups cover Microsoft 365 as well as servers
- Sensitive data has clear rules for where it can and can’t go
People
- New starters get a security induction in week one
- Everyone knows how to report a suspicious email — and nobody is blamed for false alarms
- Home Wi-Fi basics are covered: unique router password, WPA2/WPA3, no default admin login
If you tick fewer than half of these, don’t panic — that’s normal, and every item is fixable. Start with MFA and encryption, because they block the most common attacks, then work down the list.
Need a hand? Our managed IT plans cover every item above as standard. Or book a free consultation and we’ll tell you your top three priorities.
Need help putting this into practice?
Our engineers are happy to talk through your setup — no obligation, no jargon.
Get a Free Consultation