Remote work
Remote-work security checklist for UK owner-managers (2026)
Laptops go home on Fridays. Someone answers email from a café before a client visit. This is a short checklist for owners with 5 to 50 staff and no IT team: what must be true before anyone works away from the office.
Half your team works from the kitchen table some days. That is normal for UK firms with 5 to 50 people. It is also where good office habits quietly fall apart.
This checklist is for owner-managers, not IT specialists. Use it to decide what must be true before someone works away from the office, and what you can leave alone. It will not make you "fully secure". It will cut the common, boring failures: stolen passwords, invoices paid to the wrong account, and lost laptops with customer files on the desktop.
What counts as remote work here
- Staff working from home on company or personal devices
- Owners travelling with a laptop
- Contractors who only reach your systems from outside the office
- People moving between office Wi-Fi, home broadband, and public hotspots
If everyone works in one locked office on company desktops, you still want MFA and a password manager. You can skip most of the travel items.
The five non-negotiables
If you only do five things, do these. Everything else is detail.
- MFA on every account that can see company email or files. That means Microsoft 365 or Google Workspace, plus any finance tools. Prefer an authenticator app over text messages where you can. Our MFA for Microsoft 365 beginners guide walks you through it.
- A company password manager for everyone. No shared spreadsheet of passwords. No office login on a sticky note at home.
- Company files live in the company cloud. SharePoint, OneDrive, Google Drive, or your chosen system. Not only in a laptop Desktop folder. And remember that sync is not a backup, see Is OneDrive a backup?.
- Laptops are encrypted and lock themselves. BitLocker on Windows, FileVault on Mac, and a screen lock within a few minutes.
- No bank-detail changes from email alone. Call a known number to check. Write that rule down once and add it to onboarding. Our invoice fraud checklist has the wording.
A password manager is the step most small firms skip. It is also the one that makes MFA, leavers, and shared logins easier to manage. See our best password manager for UK small businesses guide to compare options.
Devices: company laptops or staff's own
Company laptops are easier to control. You can require encryption and security software, and wipe one if it is lost. Staff using their own devices is common in small firms. It is fine if you are honest about the trade-off.
- Prefer company laptops for anyone who handles customer personal data, payroll, or bank access.
- If staff use their own machines, require disk encryption, an automatic screen lock, a separate browser profile for work, and the company password manager. Do not let the browser save every work password.
- Use security software you can check from one admin screen. If you already pay for Microsoft 365 Business Premium, Microsoft Defender for Business is often enough. Free home antivirus with no admin view is not the same thing. See cheap endpoint protection for under 50 staff.
- Have a short lost-laptop plan: who to call, how to sign the device out of company accounts, and whether the disk was encrypted. Our lost or stolen laptop checklist covers day one.
Home Wi-Fi and public hotspots
Most UK home broadband is good enough for normal work. You do not need an always-on VPN for every member of staff on their own fibre. You do need a clear rule for cafés, hotels, trains, and unknown networks.
- Home. Change the router's default admin password. Use WPA2 or WPA3. Accept firmware updates when your provider prompts. A guest network for family devices is nice to have.
- Public Wi-Fi. Prefer a phone hotspot for banking, payroll, and admin portals. On café Wi-Fi, stick to sites that show the padlock and never install a "network helper" a hotspot asks for.
- VPN. Useful for travel, untrusted networks, and reaching a private office system. It is not a substitute for MFA, a password manager, or updates. Our do UK SMEs need a VPN? guide explains when yes and when no.
If you or your team travel often, a VPN is a sensible extra once the basics are done.
Accounts and access from anywhere
Remote work multiplies logins. Keep the damage small if one is stolen.
- Keep Microsoft or Google admin accounts separate from day-to-day email accounts. Put MFA on both. Store emergency admin details in the password manager, with two named people who know they exist.
- Ask your IT provider to switch off old sign-in methods that skip MFA, such as legacy "app passwords", where your plan allows.
- Give contractors their own login with an end date. Never share the owner's mailbox password "just for this project".
- Use shared mailboxes (info@, office@) rather than shared passwords. See why shared logins are a liability.
- Once a quarter, check who can approve invoices, change payees, or export customer lists. Remote teams drift into "everyone is an admin" by accident.
Files and "I'll just email myself the spreadsheet"
A classic remote-work mistake is a sensitive file sitting in personal email, WhatsApp, or on a USB stick in a coat pocket.
- Pick one official place for company files. Train people to open and edit there, not download copies to the Desktop.
- For client sharing, use links that expire and need a password, from your cloud suite. Avoid open links that never expire.
- Stop sending passwords over WhatsApp or text. Share the item from the password manager instead.
- If you still use paper or USB sticks for anything sensitive, label them, lock them away, and know what happens if one is lost.
People habits that matter more than another tool
A ten-minute remote-work briefing beats a 40-page policy nobody opens.
- Phishing works just as well on the sofa. Teach people to check links, distrust urgent payment changes, and use our first hour after a phishing click checklist if something feels wrong.
- The work laptop is not the family computer. Separate user accounts at minimum. Separate machines for finance roles if budget allows.
- On video calls in public, use headphones and lock the screen when walking away.
- When someone leaves, remote access ends the same day: account disabled, sessions signed out, laptop returned or wiped, password manager access removed.
Copy-paste checklist
Print this or drop it into your onboarding document.
- MFA on email, cloud storage, and finance tools for every person
- Company password manager rolled out and shared password lists retired
- Laptops encrypted with a screen lock, and lost-device steps written down
- Security software you can check from one admin screen
- Company files in the company cloud, not only on a local Desktop
- No bank-detail or payee changes approved from email alone
- A rule for public Wi-Fi: phone hotspot first, VPN where it earns its keep
- Contractors on their own named logins with an end date
- Leaver checklist signs out devices and accounts the same day
- One backup restore test this quarter, see our restore test guide
A sensible order if you are starting from scratch
- Week 1. MFA everywhere that matters. Password manager for the owners and managers.
- Week 2. Roll the password manager out to everyone. Retire shared passwords.
- Week 3. Encryption and security software on every work laptop. Run one lost-laptop drill.
- Week 4. Write the payment-checking rule and the file-location rule into onboarding.
Add a travel VPN and other extras only after those are done. If you already pay for Microsoft 365 Business Premium, start with what it includes before buying more. Buy less, finish more.
What this checklist is not
- Not Cyber Essentials certification. That has its own controls and assessment, see Cyber Essentials for beginners.
- Not a promise that remote staff are safe from ransomware or invoice fraud.
- Not legal advice on home-working contracts or data protection. If you handle a lot of personal data, take proper advice.
- Not a reason to buy several overlapping security products before MFA and a password manager are done.
FAQ
- Do remote staff need a VPN?
- Not always. Most UK home broadband is fine for normal work on cloud apps. A VPN earns its keep for travel, public Wi-Fi, and reaching a private office system. Get MFA and a password manager in place first.
- Can staff use their own laptops for work?
- It can work for a small firm. Require disk encryption, a screen lock, a separate work browser profile, and the company password manager. Prefer company laptops for anyone handling payroll, bank access, or lots of customer personal data.
- What is the single most important remote-work control?
- Multi-factor authentication (MFA) on email and cloud accounts. Most remote-work problems start with a stolen password. MFA stops many of those from turning into a break-in.
- Is this the same as Cyber Essentials?
- No. Cyber Essentials is a government-backed certification with its own controls and assessment. This checklist overlaps with it, but completing it does not make you certified.
Bottom line
Remote-work security for a UK SME is mostly about logins, laptops, and payment discipline. Get MFA, a password manager, encrypted laptops, and a no-email-bank-changes rule in place. Treat a VPN and extra tools as optional layers once the basics are routine.
Written for UK SME owners. More guides · How we make money