Remote work has changed where business happens, but many security policies still assume employees sit behind an office firewall. A remote employee may have strong credentials, MFA, and a company-managed laptop, yet still connect through an untrusted network, an outdated router, or a shared connection the security team can’t assess. That doesn’t make remote work unsafe by default — identity checks are only one part of the picture. Businesses also need to understand the network path employees use to reach company systems.
The Office Firewall No Longer Follows the Employee
In a traditional office, traffic passed through company-managed equipment and IT could monitor much of the network directly. Remote work removes that consistency: one employee works from a home office, another from a hotel, another from a shared workspace, often switching routers and providers within the same week. A personal laptop may have missed updates, or a device might join a familiar-looking wireless network automatically without anyone noticing. A policy suited to a London office may also create delays for someone travelling between markets — the challenge is protecting access without making ordinary work so hard that employees look for shortcuts.
MFA Proves Identity, Not the Connection
MFA makes a stolen password less useful by requiring a second factor, but it answers one specific question: is this likely the legitimate account owner? It doesn’t ask whether the device is secure, whether the network could expose sensitive activity, or whether the sign-in location makes sense. A criminal who steals a password may still pass MFA through social engineering, and a compromised device can cause problems even after authentication. Modern security models treat MFA as one layer, not a complete solution.
The Network Underneath Still Matters
Network controls add context identity checks can’t: where traffic is coming from, whether the route is trusted, and whether access patterns have changed — through secure gateways, device certificates, or DNS filtering.
A VPN can be part of that approach, encrypting the connection between a device and the VPN provider’s server — useful on unfamiliar networks, though it doesn’t replace MFA or endpoint protection. The goal isn’t to treat every home network as hostile, but to avoid assuming every connection deserves equal trust: a finance employee accessing payment systems should face stronger controls than someone reading an internal newsletter.
Protect the Riskiest Work, Then Test It
Policies work better when based on business activity, not vague ideas about remote work. Identify the tasks that would cause the greatest damage if misused — changing payment details, exporting records, approving invoices — and give those stronger safeguards: a managed device, a verified location, or a secure route. Lower-risk work can stay easy to access.
Before enforcing any new policy, test it with real users across different locations and devices, completing everyday tasks like signing in or accessing a financial system. Watch whether the process confuses people and whether the help desk can tell if an alert is genuine. A VPN free trial can be useful here, letting a team compare connection performance across networks before a broader rollout, since a tool that constantly interrupts work will eventually get bypassed.
When People Bypass a Control, Learn Why
Employees don’t always ignore procedures out of carelessness. A slow login, unclear warning, or blocked task can push people toward personal email or unapproved file-sharing tools — workarounds that move activity outside what the security team can monitor. If several teams need the same exception, the rule may be too broad. The goal is friction proportionate to risk, not friction removed entirely.
Build a Security Model People Can Actually Use
Remote-work security works best when businesses stop looking for one perfect control. MFA protects identity, endpoint security checks the device, network controls add context, and monitoring helps the company respond when behaviour changes — no single layer can carry the entire burden.
The most effective programme is one employees can actually follow on a busy day, from a home office or hotel room, built through testing and regular review. MFA remains essential, but it’s the beginning of a secure remote-access strategy, not the end of one — the network still matters, because every approved user depends on the connection underneath it.
Blog received via e-mail
























