Top Security Practices for Remote Teams

Remote work did not remove the security perimeter. It moved the perimeter onto identities, personal devices, and the accounts people create without telling anyone.

Click rate measures your people. Reporting rate measures your defences; punitive simulations improve the first by damaging the second.

The failure looks like a single approved prompt

The incident that costs a distributed business rarely begins with a sophisticated intrusion. It begins with someone in an airport approving a multi-factor prompt they did not trigger, because prompts arrive several times a day and this one arrived while boarding.

That is the honest starting point. The controls that matter are the ones that keep working when a competent, tired person makes a reasonable mistake. A control that assumes otherwise is a policy rather than a control.

Identity is the perimeter, with a consequence people skip

Everyone accepts that identity is the new perimeter. Fewer teams follow the consequence through: if identity is the perimeter, access cannot be decided once, at sign-in, then trusted for the rest of the session.

The implication is conditional, contextual access (device health, location plausibility, sensitivity of the resource), and shorter, revocable sessions for anything touching money or personal data. That is the difference between a compromised credential granting a foothold and one granting the estate.

Multi-factor authentication is necessary and no longer sufficient

Three routes go around ordinary MFA without defeating it. Approval fatigue, where repeated prompts are eventually accepted without thought. Session token theft, where the attacker acquires the artefact issued after a successful authentication and never meets the factor. And the service desk, which exists to restore access to people who cannot authenticate and is therefore, by design, the documented bypass.

Two distinctions follow. Phishing-resistant factors bound to the device and the site defeat the first two in a way push approvals and codes do not. And the reset path deserves as much control design as the login path: a rigorous authentication scheme with a sympathetic, unverified help-desk reset has a published back door.

Movers, not joiners and leavers, is the control that quietly fails

Joiners get attention because someone is waiting to work. Leavers get attention because the risk is obvious. Movers get a conversation and a new group membership, and almost never the removal of the old one.

Over a few years this produces employees whose access reflects their career history rather than their job. Annual recertification is the standard answer and fails for a specific reason: the manager reviewing the list cannot tell what the entitlements do, and approving everything carries no consequence while blocking a colleague’s access does.

Recertification works better when it is scoped to a small number of high-consequence entitlements, described in business language, and defaulted to removal where the reviewer does not respond.

The endpoint question is really a data question

Asking how to secure remote devices leads to full device management, which is the right answer for company-owned hardware and a poor one for contractors, associates and personal machines. Enrolling a personal device gives the employer capabilities over personal data that create a consent problem in UK GDPR terms and, quite reasonably, meet resistance.

The workable framing is to control the data rather than the machine: application-level protection, containerised access to documents, blocked copy-out to unmanaged applications, and revocation without wiping the device. The trade-off is real (visibility is lower and forensic evidence after an incident thinner), and leadership should take that decision knowingly rather than discover it afterwards.

The counter-argument: awareness training is oversold

Phishing simulation programmes are usually measured on click rate, which is the wrong headline number: it measures how well your workforce performs on tests, improves quickly under pressure, and says little about resilience.

The number worth optimising is reporting rate, and specifically time-to-first-report, because the organisation’s ability to contain a real campaign depends entirely on someone raising a hand early. This matters because the two metrics can be pushed in opposite directions. Programmes that name, rank or discipline people who click reliably reduce clicks and simultaneously teach everyone that reporting a mistake is dangerous. The employee who clicked and says nothing for four hours is far more costly than the one who clicked and reported in four minutes.

Reframe it accordingly: make reporting a single, obvious action; thank people publicly for reports, including the false alarms; and never publish click leaderboards.

The risk nobody owns: sanctioned tools and unsanctioned tenants

Distributed teams solve their own problems, which is largely a virtue. The residue is applications signed up for with work email addresses, trials that became dependencies, and third-party integrations granted standing access to mailboxes and files through consent screens nobody read as a security decision.

Two mechanisms make this materially worse than ordinary shadow IT. The first is delegated authorisation: an application granted broad access to a mail account retains it silently after passwords change and after the employee leaves, because the grant is a separate object from the credential. The second is ownership: where a tenant was created on a personal account, the company’s data sits in an account the company has no legal control over.

Neither shows up in a penetration test, because neither is a vulnerability: both are legitimate grants. Reviewing them periodically is a natural companion to integration and architecture work, since both come down to knowing which systems are connected to what.

Plan for the day your identity provider is unavailable

Distributed businesses have a failure mode office-based ones do not: when the identity provider or collaboration platform is unavailable, the workforce cannot reach the incident plan, the contact list or each other, because all three live behind the thing that is down.

What is needed is small and rarely present: an out-of-band contact route independent of corporate identity; break-glass accounts held securely, excluded from routine policy and monitored so use is immediately visible; and a one-page incident card, reachable offline, naming who decides, who speaks to customers and who contacts insurers or the regulator.

Standards such as ISO 27001 and Cyber Essentials give structure to this and are worth using as scaffolding. They will not tell you whether recovery works. Only rehearsal does, and the rehearsal that teaches most is run without the tools you normally rely on. Governance and resilience work should end in a test, not a document.

Controls sized for how your people work

Link-IT builds cyber governance for distributed teams: identity, access, endpoint and recovery designed proportionately, and evidenced well enough to satisfy customers, insurers and investors.

Discuss your next stage