Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Cybersecurity

Secure remote work: remote access, personal devices and home networks

Remote work was set up in a hurry, often with whatever was available, and it stayed. The result: remote accesses that were never revisited, personal computers that open corporate documents, and home networks no one controls. This page explains what to secure first and how to do it without making the work miserable.

Setting up a home remote-work station with cabling, screen and webcam

Securing remote work does not mean locking everything down. It means knowing who is signing in, from which device, to which data, and being able to cut that access in a few minutes. A lost laptop or a stolen password then stops being an emergency, because access is revoked centrally and the data does not sit on the device.

In brief

Secure remote work in three points

Securing remote work does not mean locking everything down. It means knowing who is signing in, from which device, to which data, and being able to cut that access in a few minutes when needed.

What it is

Identity verified at every sign-in, devices that are known and up to date, access to data that follows the person rather than the machine, and the ability to revoke that access remotely.

Who it is for

Small businesses whose employees work from home, on the road or in hybrid mode, and organizations that use personal devices in the absence of a full corporate fleet.

What it changes

A lost laptop or a stolen password stops being an emergency, because access is revoked centrally and the data does not sit on the device.

The context

Why remote work opened doors we never closed again

When remote work took hold, the priority was that things worked the next morning. A remote access to a server was opened, employees were allowed to use their home computer, files were shared with whatever was on hand. None of it was designed to last three years.

Those shortcuts are still there in many organizations. A remote access published on the Internet without a second factor is scanned constantly by bots. A personal computer does not have the same antivirus, the same updates or the same disk encryption as a corporate workstation, and it is shared with the family. A home network often includes a router provided years ago, with its factory password.

The good news is that the fix does not require replacing everything. It requires shifting the control point: instead of trying to secure every home, you secure the identity, the device and the access to the data.

Remote support technician with headset and laptop helping an employee working from home

What we put in place

What we set up for secure remote work

Six measures cover most of the situations we see in small businesses. They are rolled out progressively, starting with the ones that ask nothing of the employees.

Identity verified at every sign-in

What it is. Multi-factor authentication on email, files and applications, with access rules based on country, device and the risk of the sign-in.

What it does. A stolen password no longer opens anything, and a sign-in from an unusual country is blocked outright.

Known and monitored devices

What it is. Each corporate workstation is enrolled in central management: updates, disk encryption, endpoint detection and compliance status are checked continuously.

What it does. You know at all times which devices are reaching your data and which ones should no longer do so.

A clear rule for personal devices

What it is. A written policy stating what an employee can do from their personal computer or phone, backed by technical settings that separate corporate data from the rest of the device.

What it does. An employee’s departure lets you wipe the corporate part without touching their family photos, and without argument.

Remote access without a door on the Internet

What it is. Access published directly on the Internet is replaced by an access that requires verified identity, and exposed admin ports are closed.

What it does. The automated scans that look for a badly protected remote access find nothing to try any more.

Data in the right place

What it is. Working files live in a shared, backed-up corporate space, not on a laptop desktop nor in a personal cloud service.

What it does. A stolen laptop becomes a hardware replacement, not a lost set of files or a confidentiality incident.

Home network brought up to standard

What it is. A simple check of the home router for key stations: admin password changed, firmware up to date, a separate guest network for the home’s connected devices.

What it does. The work computer no longer shares the same network as the game console and the home cameras.

To be fixed

The remote-work shortcuts we find most often

Here is what we most often find when we take on a new client. None of these are rare, and none of them require a large budget to fix.

  • A remote access published on the Internet, protected by a single password
  • The same password used for the Windows session, email and accounting software
  • Corporate documents stored in an employee’s personal cloud account
  • A personal computer opening corporate email, with no up-to-date antivirus and no disk encryption
  • A former employee whose account is still active because no one followed up
  • A home router with its factory admin password, never updated
  • No way to know which devices actually connect to the company’s data
  • Files exchanged by email because secure sharing is considered too complicated

Who it is for

Who this work is for, and when

This project is usually triggered by a specific event. If you recognize yourself in one of these cases, this is the right moment.

  • An organization that shifted to remote work in a hurry and has not revisited its accesses since
  • A small business hiring remotely, sometimes outside Quebec, that has to provide access without shipping hardware
  • A professional firm or clinic bound by confidentiality obligations that cannot rely on good will
  • An organization where an employee lost a laptop or had a password stolen
  • A business asked by a client, insurer or customer to demonstrate its security practices
  • A hybrid team still using personal devices in the absence of a full fleet

Secure remote work is one part of our cybersecurity services: access, devices and identities managed together, alongside email protection and IT support. Delivered across Quebec from Trois-Rivières, in the Mauricie, in Montreal and around Quebec City. Further reading: VPN and remote access, mobile device management and Remote Desktop on Windows 11.

Questions and answers

Frequently asked questions about secure remote work

Do we need a VPN to work from home?
Not necessarily. A VPN is useful when applications or servers still live on site. If your email, files and applications are already in Microsoft 365, a VPN adds almost nothing to security and slows work down: what protects in that case is verified identity and a compliant device, not the tunnel. We look at your applications before deciding.
Can employees use their personal computer?
Yes, provided the corporate data is clearly separated from the rest of the device and this is written in a policy the employees have read. What does not work is letting a personal computer reach the data with no rule at all, then discovering when the person leaves that you have no way to remove that access.
What happens if an employee loses their laptop?
With central device management, the device is locked and wiped remotely, and the account’s access is revoked from the portal, right away. Without that management, you have to change passwords one by one, hoping the disk was encrypted. It is the difference between a thirty-minute call and a week of uncertainty.
Does remote work make us less compliant with Law 25?
Not by itself. The problem is not knowing where personal information sits or who can access it. Law 25 asks for reasonable security measures and the ability to identify and report a confidentiality incident. A well-run remote-work environment is what makes that demonstration possible, while a fleet of unmanaged personal devices makes it impossible.
How long does this take to set up?
Measures that require nothing from employees, such as closing exposed accesses and turning on conditional access rules, are set up quickly. Those that touch the devices are rolled out at the pace your team can absorb. We build the order with you rather than change everything the same week.
Will this slow my employees down?
A well-configured multi-factor authentication asks for a confirmation on an unusual sign-in, not on every session. What slows people down is an unneeded VPN, a password to change every month, or a file sharing setup so awkward that they fall back to email. We remove those frictions at the same time as we add the security.
Where do you start?
With an assessment. Our cybersecurity audit establishes which remote accesses exist, which devices touch your data and which accounts are still active. Managing arrivals and departures comes next, because that is where orphan accesses appear.

Take stock of your remote work

We look at your remote accesses, your devices and your active accounts, and give you a list of fixes ranked by urgency, with no commitment.