Five years ago, remote work was the exception. Now it's Tuesday. According to Gallup's latest workplace data, 53% of employees in roles that can be done remotely work in a hybrid arrangement, and another 27% work fully remote. That's 8 in 10 knowledge workers who aren't sitting behind your office firewall every day. Your security model needs to account for that reality - not the one from 2019.
In Part 2, we covered identity as the new perimeter. This installment is about what happens once identity is verified - securing the devices, connections, and data flows that extend into every employee's personal environment.
The Home Network Problem
Your office has a managed firewall, network segmentation, intrusion detection, and DNS filtering. Your employee's home has a consumer-grade router from their ISP with the default admin password still set, firmware that hasn't been updated since installation, and a flat network shared with smart TVs, gaming consoles, Ring doorbells, and their kid's school laptop.
We're not going to pretend you can manage every employee's home network. You can't, and you shouldn't try. But you can control what happens on the device that connects to your data from that network, and you can control how that connection works.
Basic home network guidance for employees should cover three things: change the router admin password, enable automatic firmware updates if available, and create a separate Wi-Fi network for work devices if their router supports it (most modern routers do). These aren't corporate mandates - they're recommendations. But they meaningfully reduce risk with minimal effort.
VPN vs. Zero Trust: Understanding the Shift
Traditional remote access relied on VPNs. Connect to the VPN, get a tunnel into the corporate network, access everything as if you were in the office. VPNs worked when remote access was occasional and the corporate network was where all the resources lived. Neither of those things is true anymore.
The problems with VPN-centric remote access are well-documented at this point:
- All-or-nothing access. Once connected to the VPN, a user typically has access to the entire network. A compromised VPN connection means an attacker has access to the entire network too.
- Performance. All traffic gets routed through the corporate network, even traffic destined for cloud services. An employee in Park City accessing Microsoft 365 has their traffic routed through the Salt Lake office and then back out to Microsoft's cloud - adding latency to every interaction.
- Split tunneling risks. To solve the performance problem, many organizations enable split tunneling - only corporate-destined traffic goes through the VPN. But this means the employee's device is simultaneously connected to the corporate network and the open internet, creating a bridge that malware can traverse.
- Scalability. VPN concentrators have capacity limits. When everyone went remote in 2020, VPN infrastructure collapsed under the load for organizations that weren't prepared.
Zero trust network access (ZTNA) replaces the VPN model with something more surgical. Instead of granting network-level access, ZTNA grants application-level access. An employee authenticated and authorized to use the accounting system gets access to the accounting system - not the entire network. Every access request is evaluated independently based on identity, device posture, location, and risk level. No implicit trust. No network-level access. No lateral movement potential.
For businesses still running on-premises resources that require VPN access, the transition to zero trust is gradual, not a rip-and-replace. Cloud-native resources move to ZTNA first. On-premises resources that can't be migrated stay on VPN with tighter access controls. Over time, as workloads move to the cloud, the VPN footprint shrinks.
Endpoint Compliance: Trusting the Device
Authenticating the user is half the equation. The other half is verifying the device. A legitimate user on a compromised device is still a threat. Endpoint compliance checks verify that the device meets your security standards before granting access.
What we check for in our managed environments:
| Compliance Check | What We Verify | What Happens if Non-Compliant |
|---|---|---|
| OS version | Running a supported, patched version | Access restricted until updated |
| Endpoint protection | Huntress agent active and reporting | Access blocked, IT notified |
| Disk encryption | BitLocker (Windows) or FileVault (Mac) enabled | Access blocked until enabled |
| Firewall | Host firewall active | Access restricted |
| Patch status | Critical patches applied within SLA | Flagged, escalated after grace period |
| Management enrollment | Device enrolled in MDM/Intune | Access blocked for unmanaged devices |
These checks happen at every authentication event, not just the first one. A device that was compliant on Monday might not be compliant on Wednesday if a patch was released and not applied. Continuous compliance verification ensures that the trust granted to a device is warranted at the moment access is requested.
Cloud-First Security Architecture
Here's the mental shift that matters: stop thinking about securing a location and start thinking about securing data wherever it lives. When your file storage is SharePoint, your email is Exchange Online, your CRM is cloud-hosted, and your phone system is GoTo Connect - the office is just another location where people access cloud services. It's not special. It's not more trusted. It's one of many access points.
Cloud-first security means your security controls live in the cloud too:
- Identity controls in Entra ID - conditional access, MFA, risk-based authentication (covered in Part 2)
- Endpoint protection through Huntress - cloud-managed EDR that works regardless of network location
- DNS filtering through Cisco Umbrella - DNS-level protection that follows the device, not the network
- Backup through Datto SaaS Protection - cloud-to-cloud backup that doesn't depend on on-premises infrastructure
- Privilege management through AutoElevate - controlling admin rights on endpoints without a VPN connection to a domain controller
None of these controls care whether the device is in your office, at someone's home, or in a hotel room in San Francisco. They operate at the identity and endpoint level, not the network level. That's the architecture that supports modern work.
The Human Element
Remote workers face specific social engineering risks that office workers don't. They can't walk down the hall to verify a suspicious request. They're more likely to use personal devices for quick tasks. They're more susceptible to "urgent" requests that create pressure to act fast because they can't see that the CEO is sitting calmly in their office and didn't actually send that wire transfer request.
Training for remote workers should emphasize verification procedures. Any request involving money, credentials, or sensitive data should be verified through a separate communication channel. Got an email from the CFO asking you to change vendor payment details? Call the CFO. On the phone. Using the number you already have, not the one in the email. This isn't paranoia - this is the specific attack pattern that costs businesses the most money, and it succeeds because people don't verify.
Practical Steps
If you're managing a hybrid workforce and want to improve your security posture, here's a prioritized list:
- Deploy endpoint compliance checks through conditional access - this is the highest-impact single change
- Ensure endpoint protection (EDR) is deployed on every device that accesses company data, including home machines
- Move DNS filtering to a roaming model that protects devices regardless of network
- Evaluate your VPN usage - what's still going through VPN that could be accessed directly through cloud services with proper controls?
- Establish a verification procedure for financial and sensitive requests
- Provide home network security guidance to employees
In Part 4, we'll tackle what happens when things go wrong - building an incident response plan that your team can actually execute. Because no matter how good your preventive controls are, incidents happen. The question is whether you'll respond with a plan or with panic. Stay tuned.
