Remote-work baseline
- First controls: MFA on email, cloud and remote access; supported devices; named accounts and prompt offboarding.
- BYOD choice: Decide which data and apps personal devices may reach, and how business access is removed.
- Contractor rule: Give time-limited, scoped access with an internal owner.
- Buy only for a gap: VPN, private access and remote desktop solve different problems.
Last updated: September 24, 2026
Remote work does not require a new VPN by default. It requires clear rules for who can reach which work systems from which devices, plus a way to revoke that access. NIST SP 800-46r2 treats remote access as a system: client devices, access technology and the resources behind it all need protection. CISA's SMB guidance calls for MFA on email, file storage, remote access and privileged accounts.
Define the permitted access paths
| Work pattern | Start with | Add a product only if |
|---|---|---|
| Cloud apps on managed laptops | SSO/MFA, device updates, disk encryption and account revocation | Existing identity/device tools cannot enforce required access rules |
| Private office application | Named access, MFA, patched host and logging | A managed VPN or private-app gateway is needed to reach it |
| Remote control of an office PC | Named host, strong authentication and session review | The app cannot be delivered securely through a cloud or private-app route |
| Personal device | Restricted app/data scope and a documented exit path | You can manage the business data boundary without taking over the personal device |
| Contractor | Sponsor, least privilege, expiry date and offboarding | A dedicated access platform is necessary for repeatable control |
A consumer VPN mainly changes where internet traffic exits. It does not by itself create company-managed access, identity policy or protection for an infected device. The business VPN guide and LogMeIn Pro review cover distinct purchase cases.
A workable BYOD policy
Choose which apps are allowed on personal devices and which are restricted to managed equipment. State whether local downloads, copy/paste and offline files are allowed. Tell staff what IT can and cannot see or erase, and how work access will be removed when they leave. If your current tools cannot separate business from personal data, narrow BYOD access rather than pretending you can fully secure an unmanaged laptop.
For company laptops, verify operating-system updates, disk encryption, screen lock, endpoint protection and a recovery contact. For any device, require MFA and use the strongest phishing-resistant option that the system and team can operate. Keep emergency recovery codes under business control, not only on one employee's phone.
First 30, 60 and 90 days
| Window | Action | Verification |
|---|---|---|
| Days 1–30 | Inventory remote users, apps, devices and administrator paths; enforce MFA on highest-risk accounts | Access list and MFA exceptions reviewed by an owner |
| Days 31–60 | Set device/BYOD rules; remove dormant vendor access; test one leaver | Leaver loses app, remote and local host access |
| Days 61–90 | Practice lost-device and compromised-account scenarios; review logs and support workload | Time-stamped exercise, alert owner and corrective actions |
Do not use a headline breach percentage to set your policy. Use your own inventory and actual exceptions. For payment approvals away from the office, add a callback using a previously known number; see the BEC verification guide.
When existing subscriptions may suffice
Microsoft 365 Business Premium, Google Workspace editions and managed device tools have different included identity and device features. Check the exact edition and configured policy before purchasing a new remote-access service. If the unmet need is one private application, compare scoped private access. If it is a remote desktop, count the host computers. If it is just account compromise, improve MFA and recovery first. The security toolbox guide helps organize these decisions.
Choose the first action
Run the free assessment and use its local report to name the owner and verification method for your highest-priority remote-work gap. The result is planning guidance, not a security guarantee.
Sources checked September 24, 2026: NIST SP 800-46r2, CISA SMB MFA guidance, and NIST SP 1300. This page is source-based guidance, not a tested deployment.