What it is
Identity verified at every sign-in, devices that are known and up to date, access to data that follows the person rather than the machine, and the ability to revoke that access remotely.
Cybersecurity
Remote work was set up in a hurry, often with whatever was available, and it stayed. The result: remote accesses that were never revisited, personal computers that open corporate documents, and home networks no one controls. This page explains what to secure first and how to do it without making the work miserable.
Securing remote work does not mean locking everything down. It means knowing who is signing in, from which device, to which data, and being able to cut that access in a few minutes. A lost laptop or a stolen password then stops being an emergency, because access is revoked centrally and the data does not sit on the device.
In brief
Securing remote work does not mean locking everything down. It means knowing who is signing in, from which device, to which data, and being able to cut that access in a few minutes when needed.
Identity verified at every sign-in, devices that are known and up to date, access to data that follows the person rather than the machine, and the ability to revoke that access remotely.
Small businesses whose employees work from home, on the road or in hybrid mode, and organizations that use personal devices in the absence of a full corporate fleet.
A lost laptop or a stolen password stops being an emergency, because access is revoked centrally and the data does not sit on the device.
The context
When remote work took hold, the priority was that things worked the next morning. A remote access to a server was opened, employees were allowed to use their home computer, files were shared with whatever was on hand. None of it was designed to last three years.
Those shortcuts are still there in many organizations. A remote access published on the Internet without a second factor is scanned constantly by bots. A personal computer does not have the same antivirus, the same updates or the same disk encryption as a corporate workstation, and it is shared with the family. A home network often includes a router provided years ago, with its factory password.
The good news is that the fix does not require replacing everything. It requires shifting the control point: instead of trying to secure every home, you secure the identity, the device and the access to the data.
What we put in place
Six measures cover most of the situations we see in small businesses. They are rolled out progressively, starting with the ones that ask nothing of the employees.
What it is. Multi-factor authentication on email, files and applications, with access rules based on country, device and the risk of the sign-in.
What it does. A stolen password no longer opens anything, and a sign-in from an unusual country is blocked outright.
What it is. Each corporate workstation is enrolled in central management: updates, disk encryption, endpoint detection and compliance status are checked continuously.
What it does. You know at all times which devices are reaching your data and which ones should no longer do so.
What it is. A written policy stating what an employee can do from their personal computer or phone, backed by technical settings that separate corporate data from the rest of the device.
What it does. An employee’s departure lets you wipe the corporate part without touching their family photos, and without argument.
What it is. Access published directly on the Internet is replaced by an access that requires verified identity, and exposed admin ports are closed.
What it does. The automated scans that look for a badly protected remote access find nothing to try any more.
What it is. Working files live in a shared, backed-up corporate space, not on a laptop desktop nor in a personal cloud service.
What it does. A stolen laptop becomes a hardware replacement, not a lost set of files or a confidentiality incident.
What it is. A simple check of the home router for key stations: admin password changed, firmware up to date, a separate guest network for the home’s connected devices.
What it does. The work computer no longer shares the same network as the game console and the home cameras.
To be fixed
Here is what we most often find when we take on a new client. None of these are rare, and none of them require a large budget to fix.
Who it is for
This project is usually triggered by a specific event. If you recognize yourself in one of these cases, this is the right moment.
Secure remote work is one part of our cybersecurity services: access, devices and identities managed together, alongside email protection and IT support. Delivered across Quebec from Trois-Rivières, in the Mauricie, in Montreal and around Quebec City. Further reading: VPN and remote access, mobile device management and Remote Desktop on Windows 11.
Questions and answers
We look at your remote accesses, your devices and your active accounts, and give you a list of fixes ranked by urgency, with no commitment.
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.