Hybrid work is now simply how most businesses operate. The security model many are still using, however, assumes everyone sits behind one office firewall on company equipment. That assumption quietly stopped being true years ago.
The instinct is to respond with restriction: lock down devices, block services, add friction. That approach tends to fail, because people route around controls that stop them working. The better approach is to be clear about what actually changed, and protect that.
What actually changed
Three things moved.
The device left the building. It now sits on a home network alongside a smart TV, a games console, and whatever the kids installed.
The network stopped mattering. Your data lives in cloud services reachable from anywhere with a password. Being “on the office network” no longer proves anything about who someone is.
The casual check disappeared. Nobody can turn around and ask “did you really just email me asking to change the bank details?” Every request now arrives through a channel an attacker can imitate.
Notice that only the third one is a people problem, and it is the one most likely to cost you money.
Protect the identity, not the perimeter
If your data is reachable from anywhere, the login is the perimeter. That means MFA everywhere, no exceptions for convenience, and ideally conditional access rules that consider context: is this a known device, is this login coming from somewhere plausible, is this a sensitive action.
The goal is that a stolen password on its own is not enough to cost you anything.
Protect the device, lightly
You do not need heavy-handed management to get most of the benefit. Four things cover the majority of realistic risk:
- Disk encryption on, so a laptop left in a car is a lost asset rather than a data breach
- Automatic updates on, because unpatched software is the most common way in
- Reputable endpoint protection, kept current
- A screen lock with a short timeout
If the business owns the device, enforce these centrally. If staff use their own, be honest that your options are narrower, and think carefully about what data those devices should hold at all.
The BYOD conversation people avoid
Personal devices are the awkward middle ground. The pragmatic position for most small businesses is not to ban them, which is unenforceable, but to limit what they can do. Access through a browser rather than a fully synced local copy. No sensitive data stored locally. Clear expectations in writing.
The important part is deciding deliberately, rather than defaulting into it and discovering later that company data sits on a device you cannot wipe.
Home networks: less scary than they sound
Home routers are often old and poorly configured, and that is worth a nudge: change the default admin password, keep firmware updated, use WPA2 or WPA3. But do not over-invest here. Modern attacks overwhelmingly come through the browser and the inbox, not through someone’s router. Cover the basics and spend your attention elsewhere.
Rebuild the verification habit you lost
This is the highest-value cultural change, and it costs nothing.
Establish a rule that anything involving money or credentials gets verified through a second channel. A payment request by email gets a phone call to a known number, not the one in the signature. A password reset request in chat gets confirmed verbally.
Then, crucially, make it socially acceptable to do that. If checking with the boss feels like an accusation, people will skip it. It has to be normal and expected, including when the request appears to come from a director. Say so out loud, more than once.
The honest summary
Securing hybrid work is mostly about accepting that identity replaced the network as your boundary, keeping devices patched and encrypted, and rebuilding the informal verification that an office gave you for free. That is a modest amount of work with a large payoff, and none of it requires making your team’s day harder.
Want your remote setup reviewed and tightened without adding friction your team will resent? Get in touch.