Your Office Has a Firewall. Your Living Room Doesn’t.
Quick summary
The office perimeter got two decades of investment; the home office got a VPN license and a prayer. Four-plus years after the remote-work scramble, most hybrid companies are still running on 2020-era decisions nobody has revisited — while AI has industrialized the exact attacks that work best on remote workers. This guide gives IT leaders a five-area remote work security assessment: identity, device, network, data, and people.
Add up what your company has invested in securing the office over the past two decades. The firewall that gets refreshed every few years. The badge readers, the switch ACLs, the camera in the lobby. Now add up what you invested in securing the place where your controller actually approves wire transfers every Tuesday: a VPN license and a prayer.
That imbalance is the core remote work security problem, and it’s not a new one — it’s a 2020 one. When offices emptied out, IT teams did heroic work in about two weeks: stand up remote access, ship laptops, get people working. Those were emergency decisions, and they were the right calls at the time. The problem is what happened next: nothing. We’ve assessed environments where the entire “remote work policy” was still an email from March 2020, forwarded to new hires as onboarding documentation.
Four-plus years later, the temporary setup is the permanent architecture. And here’s the contrarian part: leaving it alone feels like the safe choice. Touching remote access risks breaking the thing everyone depends on. But “it works” and “it’s secure” are different claims — and the gap between them has been widening every year while attackers, now with AI doing the heavy lifting, have been specifically industrializing the techniques that work best against people who sit alone in living rooms.
This guide is the assessment we’d run on your environment: five areas, specific questions, and an honest look at what the “safe” choice of not revisiting 2020 is actually costing you.
The Myth of “We Have a VPN”
Ask a mid-sized company how they secure remote work and the most common answer is a product name: “we have a VPN.” It’s worth being precise about what that sentence actually claims. A VPN encrypts a tunnel between a device and your network. That’s transport security — protection against someone eavesdropping on the coffee-shop Wi-Fi. It says nothing about whether the device on the end of that tunnel is patched, whether the person typing is who they claim to be, or what they can reach once they’re inside.
In fact, the classic 2020-era configuration — full-tunnel VPN terminating into a flat internal network — can make you less safe than a well-configured cloud-first setup. Here’s why: the VPN concentrates all of your trust at one gate. One phished credential, and the attacker isn’t probing your perimeter anymore — they’re inside it, on a network where the file server, the ERP system, and the domain controller are all a lateral move away. We’ve reviewed environments where a contractor’s VPN login, protected by nothing but a password, had network-level reach to systems the contractor had never heard of. The firewall you spent two decades tuning never got a vote, because the attacker came in through the front door with a valid key.
VPNs also age badly at hybrid scale. They were designed for a minority of users connecting occasionally, not the whole company connecting always. When performance degrades — stuttering calls, crawling transfers — users don’t file tickets. They route around the control: files move to personal drives, work happens outside the tunnel, and your monitoring quietly loses visibility into the traffic it was built to watch.
The industry’s answer is to move trust from the network to the identity and the device: verify who is asking and the health of the machine they’re asking from, then grant access to the specific application — not the whole network. You’ll hear this called zero trust, and the label matters less than the direction: is your architecture moving toward per-request verification, or still betting everything on the tunnel? If you’re weighing that shift, our zero trust implementation guide covers how to sequence it without a rip-and-replace.
The Five Areas of a Remote Work Security Assessment
When we assess a hybrid environment, we score it across five areas. Not tools — areas: a shelf full of products can still leave all five exposed. Here’s the framework, with the questions that decide each score.
1. Identity: is MFA actually everywhere?
Most companies answer “we have MFA” the way they answer “we have a VPN” — true for one system, assumed for the rest. The assessment question is harsher: name a system a remote employee can reach with only a password. Email usually has MFA. But the VPN itself? The payroll portal? The admin interface on the firewall? Legacy protocols that quietly bypass modern authentication? We’ve assessed environments with immaculate MFA on Microsoft 365 and a VPN gateway that accepted a username and password from anywhere on earth. Beyond coverage, look at conditional access: can you require a healthy, known device for sensitive apps and block sign-ins from impossible locations? Identity is the new perimeter — it deserves the scrutiny the old one got.
2. Device: the managed fleet versus the actual fleet
Your asset inventory says 180 managed laptops. The actual population of devices that touched company data last month includes those laptops, plus personal desktops with cached Outlook sessions, a spouse’s shared iMac, and whatever a contractor brought. The gap between those two lists is your real exposure. For the devices you do manage: can you see patch status while they’re off-network for weeks at a time? Is disk encryption verified — not assumed — on machines that live in houses that get burgled and cars that get broken into? For the devices you don’t manage, the honest question is whether “BYOD” is a policy you designed or a reality you inherited. This is a fleet-visibility problem at its core, and the same gaps we cover in our guide to endpoint management security gaps get dramatically worse when the endpoints go home.
3. Network: the perimeter you don’t control
Every remote employee added a network segment to your architecture — one with a consumer router running firmware from whenever the ISP installed it, default admin credentials, and a teenager’s gaming PC on the same subnet as the laptop that opens your financials. You can’t manage those routers, but you can decide how much you trust them. That’s the real split-tunnel versus full-tunnel question: full tunnel buys inspection at the cost of performance (and user workarounds); split tunnel buys performance at the cost of visibility. The modern direction is to stop hauling traffic back to the office at all and enforce policy in the cloud, close to the user — the SASE model. You don’t need the acronym; you need a deliberate answer to “what do we inspect, where, and what do we accept that we can’t?”
4. Data: where the files actually end up
Here’s an uncomfortable exercise: pick five remote employees and trace where your data actually lives on their machines. In our experience you’ll find company files in personal cloud-drive folders, a Downloads folder holding two years of exported reports, and spreadsheets emailed to personal accounts “to print at home.” None of it malicious — all of it invisible. The assessment questions: can you see sensitive data leaving sanctioned locations? Do offboarded employees take a Downloads folder full of customer lists with them? Does your retention policy mean anything on a device you can’t wipe?
5. People: verification culture at a distance
In the office, a strange request got a natural sanity check — you leaned over a desk and asked, “did you really send this?” Distance removed that check and nothing replaced it. The assessment question here isn’t whether your people are smart; it’s whether a remote employee who receives an urgent, plausible payment request knows exactly how to verify it, feels safe delaying it, and has a known-good channel to do so. If verification depends on individual judgment instead of a defined procedure, your control is luck. Which brings us to why this area jumped up the priority list.
AI Didn’t Invent These Attacks. It Industrialized Them.
Every security-awareness deck from the last decade taught the same tell: look for bad grammar and generic greetings. AI-written phishing killed that advice. The messages now arrive in fluent, contextual English, referencing real projects and real colleagues, generated at a scale where every employee can get a personalized lure. If your phishing defense still leans on employees spotting typos, it leans on a tell that no longer exists — our phishing prevention guide goes deeper on what layered defense looks like when the lures are this good.
Voice cloning raises the stakes specifically for remote teams. A few seconds of audio — a conference talk, a webinar, a voicemail greeting — is enough to synthesize a convincing voice. Now replay the classic scam: a call that sounds exactly like your CFO asking an accounts-payable clerk to process an urgent payment. In an office, that clerk might catch the CFO in the hallway. At home, the phone call is the relationship. Remote workers get hit hardest by voice-clone fraud for a structural reason: they have no ambient, informal way to verify, so the attack removes the only channel they’d use to check it.
And then there’s the threat nobody phished you for: shadow AI. Staff on unmanaged home devices pasting customer data, contract language, and source code into consumer chatbots — unlogged, unmonitored, and outside every control you own. On a managed device you can at least see and steer this. On the personal desktop that “just checks email,” you can’t even count it.
The countermeasures are refreshingly unglamorous:
- Verification callbacks over a known channel. Any request to move money, change banking details, or share credentials gets verified by calling the requester back on a number from the directory — never one from the message itself. No exceptions for urgency; urgency is the tell now.
- Code words for payment requests. A shared phrase between finance and executives that no email, deepfake, or cloned voice would know. It costs nothing and defeats the most expensive attack in the playbook.
- An AI usage policy that covers personal devices. Not a ban — a clear statement of what data can and can’t go into which tools, paired with a sanctioned option so employees aren’t choosing between productivity and policy.
The Hidden Costs of the “Safe” Choice
The case for leaving the 2020 setup alone is always “there are louder projects.” So let’s price what the status quo actually holds.
An unmanaged laptop with cached credentials is an unlocked office. That personal machine with a saved VPN profile and a browser full of remembered passwords is functionally a key to your environment, sitting in a house you’ve never seen, on a network you don’t control. You wouldn’t leave a branch office unlocked overnight because locking it was inconvenient. Fleet-wide, that’s what unmanaged remote access is.
Incident response is roughly three times harder when the device is in a living room two states away. In an office, containment is fast: isolate the port, image the drive, interview the user at their desk. When the machine is remote and personally owned, every step slows down — you can’t physically seize it, off-network isolation depends on tooling you may not have deployed, and forensics happens over a residential connection or a shipping label, with chain-of-custody complications when the evidence belongs to your employee. Dwell time grows exactly when containment matters most.
The paperwork has caught up even if your architecture hasn’t. Cyber-insurance questionnaires now ask pointedly about MFA coverage, EDR on remote endpoints, and offboarding controls — and a wrong answer discovered after a claim is a denied claim. Auditors under HIPAA, SOC 2, and similar frameworks stopped treating home offices as out of scope years ago. The 2020 setup doesn’t just carry breach risk; it carries the risk of failing the questionnaire that was supposed to backstop the breach.
Run Your Own Remote Work Security Assessment
You don’t need a consultant to get an honest first read — you need the discipline to score your environment as it is, not as the policy binder describes it. Here’s the sequence we’d suggest:
- Build the real device list. Pull sign-in logs for the last 30 days and enumerate every device that touched company data. Compare it to your managed inventory. The delta is your starting exposure.
- Hunt for the password-only paths. Inventory every system reachable from the internet and flag anything a remote user can access without MFA — including the VPN itself and anything using legacy authentication.
- Trace the data. Take a handful of remote employees and follow where files actually live: sync folders, downloads, personal drives. Judge the pattern, not the people.
- Test the people layer. Ask three employees how they’d verify an urgent payment request from an executive. If you get three different answers, you’ve found the gap before an attacker does.
- Score all five areas and let the lowest score set your roadmap. Remote work security fails at the weakest area, not the average.
To make that concrete, we’ve packaged the full assessment into a scored worksheet — the same five areas, thirty-four questions, with an AI-era threats section and maturity bands that tell you where to start. Download it below, score honestly, and you’ll have a defensible picture in about half an hour. And if the score surprises you, that’s not a failure — it’s the first accurate measurement of decisions that were never supposed to last four years.
Downloadable Resources
Remote Work Security Self-Assessment
A scored 34-question self-assessment across the five areas that decide remote work security — identity, device, network, data, and people — plus an AI-era threats section covering voice-clone verification, payment code words, and shadow AI. Per-section tallies and maturity bands show exactly where your 2020-era setup is exposed and what to fix first.
Frequently Asked Questions
No. A VPN encrypts the connection between a device and your network — it protects data in transit, nothing more. It doesn’t verify that the device is patched or encrypted, that the person typing is legitimate, or limit what they can reach once connected. A full-tunnel VPN into a flat network can actually concentrate risk: one phished credential puts an attacker inside your perimeter with broad lateral reach. Treat the VPN as one transport control inside a larger remote work security posture that covers identity, device health, network, data, and verification practices.
Start by finding out what “BYOD” actually means in your environment — most companies discover far more personal devices touching company data than policy anticipated. Then apply tiers: fully managed devices get full access; personal devices get access only through controls you can enforce without owning the machine, such as conditional access requiring a compliant browser session, mobile application management that containerizes company data, and blocking downloads to unmanaged endpoints. The key principle is that access level should follow device trust level. A personal desktop you can’t see, patch, or wipe should never hold the same access as a managed laptop.
A voice cloning scam uses AI to synthesize a convincing replica of a real person’s voice — often an executive — from a few seconds of publicly available audio, then uses it in a phone call to authorize a fraudulent payment or extract credentials. Remote teams are hit hardest because they lack the informal, in-person verification an office provides. The defenses are procedural: require callback verification on a known directory number for any financial or credential request, establish a code word between finance and executives that no cloned voice would know, and make it explicitly safe for employees to delay an “urgent” request while they verify it.
Full tunnel routes all of a remote user’s traffic through the corporate network, giving you inspection and monitoring at the cost of performance and bandwidth — and when performance suffers, users find workarounds that bypass the tunnel entirely. Split tunnel sends only corporate-bound traffic through the VPN while the rest goes straight to the internet, which performs better but leaves that direct traffic invisible to your security stack. Neither is “correct” — the right answer depends on what you need to inspect and what you can accept losing visibility into. Increasingly, organizations sidestep the tradeoff by enforcing policy in the cloud close to the user rather than hauling traffic back to a data center.
Shadow AI is employees using consumer AI tools — chatbots, transcription services, code assistants — without IT’s knowledge or approval, often pasting in company data as part of their prompts. It’s a remote work risk specifically because home and personal devices sit outside your logging and controls: on a managed office machine you can monitor or block these tools, but on an unmanaged personal desktop you can’t even measure the exposure. The fix is a realistic AI usage policy that covers personal devices, defines what data classes can go into which tools, and provides a sanctioned AI option so staff aren’t forced to choose between productivity and compliance.
A current policy should cover five areas: identity (MFA on every remotely accessible system, conditional access rules), devices (what managed and personal devices may access, minimum patching and encryption requirements), network (VPN or cloud-access expectations, home router baseline guidance), data (where company files may live, personal cloud storage rules, offboarding data return), and people (verification procedures for payment and credential requests, an AI usage policy that includes personal devices). Just as important: a review date. Most remote work policies in circulation were written during the 2020 scramble and were never designed to govern a permanent hybrid workforce.
Still Running on 2020's Remote Work Decisions?
Plow Networks helps mid-sized organizations assess and modernize remote work security across identity, devices, networks, data, and people — turning an emergency-era setup into a deliberate architecture.
Explore more on: