Home networks, personal devices, and public Wi-Fi are three things your office firewall can't protect against. But that doesn't mean you're helpless — it just means you need a different approach.
Remote work is here to stay. Whether you've got a full-time remote team, a few people who work from home on Fridays, or one key employee who travels constantly — your business data is leaving the building every single day. And most small businesses haven't kept up with what that actually means for their security.
I want to be clear about something up front: this isn't about punishing remote workers or making their lives harder. The goal is exactly the opposite. The best security solutions are the ones people actually use — the ones that work in the background without adding friction to someone's day. When security is inconvenient, people find workarounds, and workarounds are where breaches happen.
So let's talk honestly about the real risks, and then talk about the fixes that actually work. After 30+ years of helping small businesses manage these problems, we've seen what breaks and what holds up. Here's what you need to know.
When your employee sits down at their kitchen table and opens their work laptop, they're connecting through a home network that you have zero visibility into and zero control over. That network might be perfectly fine. Or it might be a Comcast router running firmware from 2019 with the default admin password still set to "admin."
Here's why that matters: your corporate firewall — assuming you have a real one (and if you're not sure, read this first) — protects traffic inside your office. It does nothing for a laptop connecting from someone's living room. If that home network has been compromised, traffic flowing through it can be intercepted. Malware from a family member's computer can spread to your employee's machine. And the router itself can be used as a jumping-off point by attackers who've already gotten in.
To make things more interesting, most home networks have a mix of devices on them: smart TVs, baby monitors, Ring doorbells, gaming consoles, kids' tablets, and maybe a work laptop all sharing the same network. IoT devices — the smart home gadgets — are notoriously insecure. They're cheap to make and rarely get updated. If an attacker compromises a smart thermostat, they're now on the same network as your employee's work machine.
You can't control what's in someone's house. But you can control what happens to your business data while it's there.
Ask yourself how many of your employees check their work email on their personal phone. Or access the shared drive from their home computer because it's more convenient. Or use their personal laptop when their work one is in the shop.
In most small businesses, the answer is "a lot." And that's understandable — you can't always issue dedicated hardware to everyone, and you want people to be reachable. But personal devices create a real problem.
A work-managed device has your IT policies applied to it. It has endpoint protection installed. You can remotely wipe it if it gets lost or stolen. You know what software is on it. You can enforce screen locks and encryption.
A personal device has none of that. It might have the same antivirus that came with it three years ago. It might have apps installed that are riddled with security holes. It definitely doesn't have your endpoint protection on it. And if that employee leaves your company tomorrow, you have no way to remotely wipe your business data off their personal phone.
We've seen this go wrong in a few different ways. An employee's personal laptop gets infected with malware, and because they were accessing the company file share from it, the malware finds its way onto your server. An employee gets phished on their personal email, and because they use the same password for work, the attacker gets into your systems too. Or an employee leaves on bad terms, and they still have six months of company files sitting on their home computer with no way for you to get them back.
Public Wi-Fi is the one most people have heard about, but it's still worth covering because it's genuinely misunderstood. The risk isn't just that someone's eavesdropping on your connection — it's that on a public network, you can't verify what network you're actually on.
Setting up a fake Wi-Fi hotspot is trivially easy. An attacker sits in the same coffee shop, sets up a hotspot called "Starbucks_WiFi" (or something close to it), and waits for people to connect. Once you're on their network, they can see your unencrypted traffic, redirect you to fake login pages, and intercept credentials. This is called an "evil twin" attack, and it doesn't require any particular sophistication to pull off.
Even on a legitimate public network, you're sharing bandwidth with strangers. Someone on the same network running network scanning tools can probe connected devices for vulnerabilities. It's not as common as it used to be now that most sites use HTTPS, but it's still a real risk — especially for applications that don't encrypt their traffic properly.
The fix for public Wi-Fi is a VPN — but not just any VPN. Consumer VPN services you see advertised aren't the right answer for business. More on that in a minute.
Here's the underlying problem that connects all three risks above: when employees work remotely without the right setup, you have no visibility into what's happening. You don't know if a device has been compromised. You don't know if someone is connecting from an unusual location. You don't know if your business data is sitting on an unencrypted personal drive.
In the office, your firewall logs traffic, your network monitoring catches unusual behavior, and your IT team can see what's connected to the network. Remote work punches holes in all of that. Attackers know this. It's why credential theft targeting remote workers has increased dramatically — remote access portals are one of the most common entry points for ransomware.
The good news is that the tools to fix this visibility gap are not expensive or complicated. They just have to be set up correctly and used consistently.
Here's what we actually recommend for small businesses with remote workers. None of this is exotic or expensive. All of it makes a real difference.
If a remote employee's password gets stolen — through phishing, through a data breach on another site, through any of a dozen other ways — MFA is what stops that from becoming your problem. With MFA enabled, a stolen password alone isn't enough to log in. The attacker also needs the second factor, which they almost certainly don't have.
MFA is the single highest-impact security change most small businesses can make. Enable it on Microsoft 365, on your VPN, on any remote access tool, on your cloud services. All of it. We've written a whole piece on this if you want the full rundown, but just know that this is step one and it's not optional.
We know this isn't always possible. But if an employee is regularly working from home, a company-managed laptop is worth the investment. You control the security configuration, you can deploy endpoint protection, you can remotely wipe it if it goes missing, and you know what software is on it. This closes an enormous number of the personal device risks in one move.
If you truly can't issue company devices to everyone, the next best thing is a mobile device management (MDM) policy for phones accessing company email. MDM lets you apply security policies and remotely wipe company data from personal phones without touching personal content. It's a reasonable middle ground.
A business VPN creates an encrypted tunnel from the remote device back to your network. All traffic flows through that tunnel, which means it's protected from eavesdropping on whatever local network the employee is using. It also means all traffic goes through your firewall and DNS filtering, so your security tools can actually see it.
Consumer VPN services (the ones you see advertised everywhere) are designed for personal privacy, not business security. They route your traffic through the vendor's servers in ways that don't integrate with your IT infrastructure. What you want is a business-grade VPN that routes remote traffic back through your own network. Solutions like pfSense or OpenVPN on your own hardware give you this — and the per-user cost is basically nothing once it's set up.
This is a simple ask that makes a real difference: tell remote employees to create a separate guest Wi-Fi network at home and connect work devices to it. Most modern home routers support multiple SSIDs (network names). By putting work devices on a separate network from the smart TV and the kids' tablets, you limit the blast radius if any of those IoT devices get compromised.
You can also recommend that employees keep their home router firmware updated and change the default admin password if they haven't. That advice is free and takes five minutes.
DNS filtering blocks malicious websites at the network level — before they even load. In the office, this runs on your firewall or network. For remote workers, you can push a DNS filtering client to company devices that works wherever they connect. It adds almost no friction to the user experience but blocks a huge percentage of malware delivery and phishing sites. It's one of the best-value security tools we recommend, and it works just as well in someone's kitchen as it does in your conference room.
This is the boring one, but it matters. Your employees need to know what they're allowed and not allowed to do with company data on personal devices and on remote connections. Put it in writing: no storing company files in personal cloud storage, no accessing work systems from unmanaged devices without approval, no using public Wi-Fi without VPN. Not because you're policing your people, but because when they know the rules, they can follow them — and when something goes wrong, you have a documented baseline to work from.
If you're not sure how your business stacks up, here's a quick gut-check. For each of these, be honest with yourself:
If you said no to more than two of those, you've got some gaps worth addressing. None of these fixes are expensive or time-consuming to put in place. They're all basic hygiene for a business with any remote workers at all.
And one more thing: check in on your security posture regularly. The threat landscape changes. What was good enough two years ago might not be today. If you'd like help taking a look at where your remote work security stands, that's exactly the kind of assessment we do — and we'll give you straight answers, not a sales pitch. You might also want to check out our free Cybersecurity Essentials guide or the IT Buyer's Guide while you're here.