Skip to main content

Cybersecurity for Employees Working From Home

More employees are working from home than ever before due to the COVID-19 pandemic. Increased remote work may offer benefits and increased flexibility, but it can also bring unwelcome cybersecurity risks. Consider these precautions to help minimize these risks:

Employers

Use Virtual Private Networks (VPN), not Remote Desktop Protocols (RDP).

One critical security best practice is to make sure that employees use Virtual Private Networks (VPN), not Remote Desktop Protocols (RDP), when accessing the company’s network via home Wi-Fi. With a VPN, it’s possible to encrypt data to better protect passwords, credit card numbers and other sensitive information.  A VPN can also provide a level of anonymity through capabilities such as masking of location data, website history and IP addresses. 

Employers should avoid using the RDP on their network because it is not a secure solution.

Implement Multi-factor Authentication (MFA).

Multi-factor Authentication (MFA), which requires authorized users to provide more than one method of validating their identity, adds additional cyber protection. For example, employees could be prompted to enter a code that they access through an app on their phone, in addition to their user name and password, when logging into the company’s network.

The authentication factors typically correlate to a device (e.g., an authenticator app on a smartphone), biometrics (e.g., a fingerprint) or information (e.g., a PIN). For more information on the best way to implement MFA at your company, reach out to your technology staff and/or managed service provider.

Ensure remote work practices comply with internal and external policies, laws and regulations.

It is important for companies to understand their regulatory environment and ensure that remote work complies with internal and external policies, laws and regulations. It is possible that some roles within a company will not be suited to remote work. In that case, companies should communicate clearly their remote work policies to employees, including expectations for productivity and permissibility.

For example, some teleconferencing software may not be HIPAA compliant for use by a medical provider because the software does not encrypt personal health information (PHI). Identify and address risks, such as those associated with storing business information in personal cloud storage or printing on home printers.

Ensure systems, software, technologies and devices are updated and kept current with the latest security patches.

If computers and other systems and devices are going to be used in a home environment, employers should track that equipment and provide a means of updating software security patches. The National Institute for Standards and Technology (NIST) provides a National Vulnerability Database that offers information on vulnerabilities from many vendors. For more information about patch management and some best practices to consider, reference the NIST Guide to Enterprise Patch Management Technologies.

Employees

Prevent unauthorized users on company resources (e.g., laptops, mobile devices).

Employees should not allow others access to company resources, including family members. Whenever possible, employees should use a private location if they are on a call or in a meeting that involves sensitive information, such as anything HIPAA-related.

Use only company-authorized devices for remote work.

It may seem convenient for employees to print work documents on home printers or send emails to personal devices, but these actions may put the company at risk and violate company policies. Personal devices may not have the same level of security and privacy protections as company devices. If your company has a “Bring Your Own Device” policy, be sure that employees comply with it when using personal devices at home. This includes home printers and personal email accounts. Advise employees to be aware of “shortcuts,” such as taking photos of company documents with a personal phone as an alternative to scanning them, as these shortcuts may introduce privacy and security risks.

Dispose of company documents properly.

Employees should reference your company’s records retention and management policies, as well as information management policies, to ensure compliance. If employees must dispose of hard copies of company documents, they should either shred them or securely retain them for proper disposal when they return to the office. Protect physical documents that must be retained as best as possible.

Related Resources

Cyber Risk Management - Getting Started - Establishing a Security Baseline

This article discusses the importance of management commitment as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related Resources

Cyber Risk Management Self-Evaluation Guide

This evaluation is designed to help you self evaluate and identify your gaps and strengths in your company's ability to protect against a data or data service compromise, cyber theft or cyber attack.

Lock resting on keyboard, representing cyber security.

Related Resources

Cyber Security Training for Employees

A large number of information security incidents are directly attributable to inadequate data technology user training. This bulletin discusses providing employees and contractors with appropriate training to recognize cyber threats.