How To Guide
How to Set Up Secure Remote Access Policies
Balance employee flexibility with security.
Overview
Define who accesses what, from where, under what conditions.
Step 1: Policy
Define rules.
1
Access
- VPN or zero-trust required
- MFA for all connections
- Managed or approved devices only
- Session timeout after 30 minutes
2
Data
- No company data on personal storage
- Only approved cloud services
- Lock screen when away
Step 2: Technical
Enforce controls.
1
Implementation
- Always-on VPN for company devices
- Conditional access
- Geo-restrictions
- Log all sessions
2
Compliance
- MDM device verification
- OS, antivirus, encryption checks
- Remote wipe capability
Step 3: Governance
Maintain policy.
1
Ongoing
- Annual review
- Written acknowledgement
- Onboarding training
3
Home Office Security Requirements
- Require a dedicated workspace: Company data should not be visible to household members
- Home Wi-Fi must use WPA2 or WPA3 encryption with a strong password
- Recommend separating work devices from personal/IoT devices on home networks
- Provide guidance on physical security: Lock screen when away, secure printed documents
- Prohibit use of public Wi-Fi for company work without VPN
- Provide a checklist for employees to self-assess their home office security
4
Monitoring and Compliance
- Deploy endpoint monitoring on all remote devices to verify compliance
- Track VPN connection logs: Who connects, when, from where, for how long
- Monitor for impossible travel: Login from UK then login from another country within hours
- Alert on large data downloads during non-standard working hours
- Generate monthly compliance reports showing percentage of compliant devices
- Address non-compliance promptly with clear remediation steps
5
Incident Response for Remote Workers
- Define procedures for when a remote worker's device is lost or stolen
- Enable remote wipe capability and ensure it works before an incident
- Establish a clear reporting line: Who should remote workers call for security concerns?
- Include remote-specific scenarios in your incident response plan
- Test communication procedures: Can you reach all remote workers quickly?
- Consider the complication of time zones if you have distributed remote workers
Need Professional Help?
Our engineers provide expert assistance with setup, troubleshooting, and ongoing support for businesses and individuals across Cornwall.