Cybersecurity

Remote Work Security Checklist for Small Businesses: Devices, Wi-Fi, VPN and Cloud Access

Use this practical remote work security checklist to protect small-business devices, home networks, VPN connections, cloud applications, employee accounts and business data.

Published 4 Oct 2026 · Digital Reality Studio
Remote Work Security Checklist for Small Businesses: Devices, Wi-Fi, VPN and Cloud Access

Remote work security starts with a repeatable checklist

Remote and hybrid work can extend a small business beyond its office network, but it also creates more places where accounts, devices and business data can be exposed. An employee may connect from a home office, hotel, shared workspace or mobile hotspot. The business may rely on cloud email, file storage, customer relationship management systems and remote support tools rather than a traditional internal network.

The goal is not to make remote work impossible. The goal is to define a minimum security standard, apply it consistently and make it easy for employees to report problems. NIST describes a remote-work device as an extension of the organization’s environment, which means laptops, phones and tablets need regular updates, appropriate access controls and ongoing maintenance. Read the NIST telework security overview for the underlying security principles.

Use the checklist below as an implementation workflow. Start with the controls that protect identity and business data, then improve device management, home-network security, remote access and response procedures.

1. Define your remote-work security standard

Before selecting tools, write down what employees, contractors and vendors must do when working away from the office. A short policy is more useful than an unwritten expectation.

  • List approved work devices. Identify whether employees may use company-managed laptops, personal computers, tablets or smartphones. Treat personal-device access as a separate risk decision rather than assuming that every device is equivalent.
  • Classify sensitive information. Mark the systems and data that require stronger controls, such as payroll, customer records, payment information, health information, intellectual property, administrator consoles and business backups.
  • Document approved access methods. Specify which cloud applications, VPN services, remote-support tools and file-sharing platforms employees may use. Prohibit unsanctioned storage of business files in personal accounts.
  • Set minimum device requirements. Require supported operating-system versions, automatic security updates where practical, screen locking, malware protection, disk encryption for laptops and MFA for business accounts.
  • Assign responsibility. Identify who approves access, who manages devices, who handles lost equipment and who receives security reports outside normal business hours.
  • Include contractors and vendors. Remote access should be limited to the systems and time period required for the work. Avoid shared accounts because individual accounts make access review and investigation possible.

The Federal Trade Commission’s small-business cybersecurity guidance recommends written practices, employee training, MFA, updates, backups and procedures for lost or stolen equipment.

2. Secure every remote-work device

A business laptop may contain cached email, browser sessions, downloaded documents, authentication tokens and locally stored credentials. A lost or compromised device can therefore expose more than the files visible on its desktop.

  • Use supported operating systems and applications. Remove devices that no longer receive security updates, or isolate them from sensitive systems until they can be replaced.
  • Turn on automatic updates. Enable operating-system, browser, productivity-suite and security-software updates when automatic installation is appropriate. Establish a process for updates that require testing or a restart.
  • Enable full-disk encryption. Use the encryption feature provided by the operating system or device-management platform. Protect recovery keys in an administrative system rather than storing them in an employee’s laptop bag or local text file.
  • Require screen locking. Configure a short inactivity timeout and require a strong PIN, password or biometric unlock method. Employees should manually lock the screen whenever they leave a device unattended.
  • Use standard user accounts. Employees should not perform normal work from local administrator accounts. Reserve administrative privileges for approved maintenance tasks.
  • Enable endpoint protection. Use centrally managed antivirus or endpoint detection and response where the business can support it. Confirm that protection is active and that alerts reach someone who can investigate.
  • Restrict removable media. Decide whether USB storage is allowed. If it is necessary, require encrypted devices and scan files before they are opened or transferred.
  • Control software installation. Provide an approved application list or an installation request process. Unapproved browser extensions, remote-control tools and file-sharing utilities can create avoidable access paths.
  • Secure mobile devices. Require a screen lock, current software, automatic device locking and the ability to remotely revoke business access or wipe business data when the device is lost.
  • Keep work and personal use separate where possible. Do not allow family members to use a company laptop. For BYOD, use an approved management or application-isolation approach rather than relying only on an employee promise.

For a deeper implementation baseline, link this checklist to the Endpoint Security Baseline for Small Businesses.

3. Harden home and temporary networks

Home Wi-Fi is part of the remote-work environment. Employees do not need to become network engineers, but they should follow a small number of consistent rules.

  • Change default router credentials. Replace the router’s administrator username or password if the manufacturer permits it. Do not reuse the Wi-Fi password as the router-administration password.
  • Use WPA2 or WPA3. Select the strongest wireless encryption supported by the router and current devices. Avoid obsolete or open wireless security modes.
  • Update router firmware. Enable automatic firmware updates if available, or create a recurring reminder to check the manufacturer’s support page.
  • Disable unnecessary remote administration. Router management should not be exposed to the public internet unless there is a documented, protected reason to do so.
  • Use a separate guest network. Keep visitors, smart-home equipment and personal devices away from the network used by business-managed equipment when the router supports network separation.
  • Use a unique Wi-Fi passphrase. Do not publish it publicly or reuse it for business accounts. Change it when access has been widely shared or when the household’s security situation changes.
  • Be cautious with public Wi-Fi. Public networks should not be treated as trusted. When employees must use one, they should use an approved VPN for business traffic, avoid sensitive work when a safer connection is available and verify the network name with the venue.
  • Prefer a managed mobile hotspot when appropriate. A company-managed hotspot can reduce dependence on unknown public networks, but it still requires an updated device, strong authentication and appropriate data-plan controls.

The FTC recommends changing default router credentials, disabling remote management, using WPA2 or WPA3 and separating guest or public Wi-Fi from the business network. Its secure remote access guidance also covers public Wi-Fi and VPN use.

4. Make identity the main security boundary

Remote access depends heavily on identity. A secure laptop does not compensate for a stolen password, an unprotected mailbox or an overprivileged cloud account.

  • Require MFA for email, file storage, VPNs, remote-support tools, financial systems and administrator accounts. Enforce it centrally rather than leaving enrollment optional.
  • Prefer phishing-resistant authentication. Passkeys and FIDO2 security keys provide stronger protection against credential phishing than passwords alone. Use the strongest method supported by each critical system.
  • Use a business password manager. Require unique passwords for every service and keep shared credentials in controlled vaults with named access wherever possible.
  • Separate administrator accounts. Owners, IT providers and power users should have standard accounts for everyday work and separate administrative accounts for privileged actions.
  • Review inactive and departed-user accounts. Disable accounts promptly during offboarding. Revoke sessions, reset tokens where supported and remove access from groups, shared drives, VPNs and third-party applications.
  • Limit sign-in risk. If your identity provider supports it, use device-compliance checks, sign-in risk policies, location or network signals and step-up authentication for sensitive actions.
  • Protect account recovery. Recovery email addresses, phone numbers, backup codes and administrator recovery methods should be documented and protected like primary credentials.

See the related guide on phishing-resistant MFA for small businesses. CISA specifically recommends enabling MFA across systems such as email, file storage and remote access; consult its MFA guidance for small businesses.

5. Configure VPN and remote-access tools carefully

A VPN can provide a protected connection to business resources, but deploying a VPN does not automatically secure the endpoint, identity or application behind it. Choose the access method that matches the resource being protected.

  • Use an approved business VPN for internal resources. Do not allow employees to select arbitrary VPN applications for connecting to company systems.
  • Require MFA on the VPN. A VPN account protected only by a password is a high-value target.
  • Limit access by role. Employees should reach the systems required for their jobs, not the entire internal network by default.
  • Keep the VPN gateway updated. Assign ownership for firmware, operating-system updates, certificates, configuration backups and vulnerability notifications.
  • Restrict administrative access. Separate VPN administration from ordinary user access, protect the administrator account with phishing-resistant MFA where possible and review administrative logs.
  • Set session and idle timeouts. Balance usability with the sensitivity of the system. Require reauthentication for high-risk actions.
  • Do not expose remote desktop directly to the internet. Use a protected access layer, MFA and network restrictions. The FTC warns that remote-access protocols such as RDP and VNC can provide attackers with a path to systems when they are not properly secured.
  • Control remote-support software. Approve specific tools, require user consent where appropriate, restrict unattended access and remove temporary support accounts after the task is complete.
  • Log remote connections. Record successful and failed sign-ins, administrative actions, device identity and session activity when the platform supports it. Alerts should be sent for unusual activity.

For cloud applications, direct application access with strong identity controls may be more appropriate than placing every service behind a broad network VPN. The important principle is least privilege: authenticate the user, evaluate the device and grant only the access required.

6. Protect cloud files and business applications

Cloud services are often the primary workplace for small businesses. Their security depends on configuration, identity governance and sharing discipline.

  • Use business-managed tenants. Store company documents in business accounts rather than personal email, consumer storage or former employees’ accounts.
  • Review sharing settings. Prefer named-user sharing over public links. Set expiration dates for external links when supported and remove access when a project ends.
  • Separate confidential folders. Do not place payroll, legal, financial or customer data in a broadly shared folder merely for convenience.
  • Review third-party app permissions. Remove OAuth applications that are unused, excessive or owned by unknown developers. Pay particular attention to apps that can read mail, files or contacts.
  • Monitor external collaboration. Review guests, external domains, anonymous links and unusual download activity on a recurring schedule.
  • Protect synchronization. Decide which folders may sync to local devices. Use device controls to prevent sensitive data from being downloaded to unmanaged computers where feasible.
  • Back up important cloud data. Cloud availability is not the same as an independent backup. Confirm that critical files, configurations and records can be recovered after accidental deletion, account compromise or ransomware.
  • Maintain audit logs. Keep logs long enough to investigate suspicious sharing, sign-ins, deletions and administrator changes.

7. Create a lost-device and suspected-compromise procedure

Employees should not have to decide what to do after losing a laptop or clicking a suspicious link. Put the first actions in writing and make reporting easy.

  1. Report the lost device, suspicious message, unexpected MFA prompt or unusual computer behavior immediately.
  2. Identify the user, device, approximate time, location and systems involved.
  3. Revoke active sessions and disable or suspend the account when compromise is suspected.
  4. Use device-management tools to lock, locate or erase the device when appropriate.
  5. Rotate exposed passwords, recovery codes, API keys and other credentials.
  6. Preserve relevant email, identity, endpoint, VPN and cloud-service logs.
  7. Contact the organization’s IT provider, insurer, legal adviser or incident-response partner according to the business plan.
  8. Do not ask employees to investigate deeply, delete evidence or communicate with an attacker without authorization.

Connect this procedure to the Small Business Incident Response Plan. The FTC also recommends having a plan for saving data, continuing operations and notifying affected parties after a breach.

8. Train and verify the controls

Training should be short, repeated and tied to the tools employees actually use. Cover phishing, unexpected MFA prompts, fake technical-support calls, public Wi-Fi, file-sharing links, lost equipment and reporting procedures. NIST advises teleworkers to follow organizational policies, keep devices updated, secure home Wi-Fi and report suspicious activity rather than ignoring it.

Use a monthly or quarterly review cycle:

  • Check that all active users have MFA and no former users retain access.
  • Review device inventory, encryption status, update status and endpoint-protection alerts.
  • Review VPN, identity-provider and cloud audit logs for unusual sign-ins or sharing.
  • Test a lost-device report and confirm that access can be revoked quickly.
  • Verify that backups include critical cloud data and that at least one restoration test succeeds.
  • Review vendor and contractor access, including expiration dates and administrative permissions.
  • Update the remote-work policy after major technology, staffing or business-process changes.

Remote work security checklist

  • Written remote-work and BYOD policy approved.
  • Business-managed device inventory maintained.
  • Supported operating systems, automatic updates and endpoint protection enabled.
  • Full-disk encryption and screen locking enabled on laptops.
  • Home routers use changed administrator credentials and WPA2 or WPA3.
  • Router firmware is current and remote administration is disabled unless required.
  • Guest and smart-home devices are separated from work equipment where practical.
  • MFA is enforced for email, cloud storage, VPN, remote support and administrator accounts.
  • Phishing-resistant MFA is used for high-value accounts where supported.
  • VPN access is approved, patched, logged, MFA-protected and limited by role.
  • Internet-exposed RDP and VNC are prohibited or protected by a documented secure design.
  • Cloud sharing, OAuth applications and external collaborators are reviewed regularly.
  • Critical cloud data is backed up and recovery has been tested.
  • Lost-device and suspected-compromise reporting procedures are documented.
  • Employees receive recurring training and know exactly how to report an incident.

Final implementation advice

Small businesses do not need to deploy every advanced security product at once. Begin with the controls that reduce the largest practical risks: MFA, managed and encrypted devices, timely updates, secure Wi-Fi, restricted remote access, disciplined cloud sharing, independent backups and a clear incident-reporting process. Then add device compliance checks, stronger authentication, centralized logging and more detailed access reviews as the business grows.

The most effective remote-work security program is visible in daily operations. Employees know which devices and applications are approved, managers know who can access sensitive systems, administrators can revoke access quickly and the business can recover when something goes wrong.