Resource
Remote and hybrid work IT setup
Hybrid working removed the assumption most business networks were built on: that being in the office meant something. Once staff work from anywhere on devices you cannot reach, identity and device management stop being optional refinements and become the whole security model.
What changes
Six shifts, each of which invalidates something that worked when everyone was in one building.
| Element | In the office |
|---|---|
| Security boundaryIdentity and device health | The network |
| Device controlManagement software or nothing | Physical access when needed |
| Data locationWherever the person saved it | On the file server |
| SupportRemote tooling and clear documentation | Walk to the desk |
| ConnectivityWhatever the home has | One managed connection |
| OffboardingRemote wipe and courier | Collect the laptop in person |
What to put in place
Six things that make hybrid work sustainable rather than tolerated.
- Device management enforcing encryption and a compliant configuration before company data is reachable
- Multi factor authentication on everything, since the network no longer provides any assurance
- Files in a managed cloud location rather than on individual laptops
- Conditional access rules based on risk signals rather than on location alone
- A clear standard for what personal devices may and may not access
- Remote wipe capability tested before you need it
The personal device question
Most businesses allow some personal device use, usually email on a phone, and most have never decided that deliberately.
The workable position is to distinguish between accessing and storing. Reading email in a managed application on a personal phone, with the ability to wipe just that application, is reasonable. Syncing the company file store to a personal laptop nobody manages is not.
Write the standard down and apply it consistently. The failure mode is not the policy being strict or lenient, it is the policy being unstated and therefore different for every person.
Common questions
Answered before you ask.
Should we buy laptops or let staff use their own?
Company owned devices are considerably simpler to secure, support and recover, and the cost difference is smaller than it looks once you account for the support burden of supporting hardware you do not control. Where personal devices are used, restrict them to managed applications rather than full access and be explicit about which is which.
How do we support someone with poor home internet?
Establish whether it is the connection or the wireless inside the home, because it is frequently the latter and a better router solves it. Where the connection is genuinely inadequate, options include a cellular backup, a stipend toward an upgrade, or agreeing that particular role requires office attendance. All three are legitimate.
Is a VPN still necessary?
Only for reaching systems that remain on the internal network. If your applications are cloud based and protected by strong identity controls, a VPN adds friction without adding much security. Where one is still needed it should require multi factor authentication and check device compliance rather than granting flat network access once connected.
Related
Read next.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
MFA and password management rollout
How to deploy it without a revolt.
Cloud services and migration
Azure, hybrid environments and planned server retirement.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.