Secure Communications

Secure Remote Working

A single stolen password should not be enough to reach every system you run. We build remote access on identity and device checks, so a compromised login gets an attacker very little.

What this protects

One password should not open everything

Traditional remote access trusts anyone who clears the front gate. That is a risk sitting on every laptop that leaves the office.

Stolen credentials

Passwords are phished, reused and traded. Identity checks mean a stolen password is no longer enough on its own.

Unmanaged devices

Home and personal machines carry their own risks. Device checks keep an unhealthy laptop away from business systems.

Insurance and framework answers

Insurers and frameworks ask directly about multi-factor authentication and access control. This is where those answers come from.

Why VPN-only access has had its day

Traditional remote access works like this: connect to the VPN and you are inside. Once inside, you can reach almost everything, because the network trusts anyone who got past the front gate. One stolen password or one unpatched laptop, and the attacker is not merely in. They are in with your permissions, which is the part that costs you.

Zero trust turns that on its head. Every connection is judged on its own merits: who you are, what device you are using, whether that device is healthy, and what you are actually trying to reach. Access is granted per application, per user and per session, not once and forever.

What this looks like in practice

Multi-factor authentication

Something you know plus something you have. Finding your password stops being sufficient on its own.

Device compliance checks

A device that is unpatched, unprotected or outside your management platform does not get in, however correct the password.

Least privilege access

People reach the applications they need and nothing else, rather than the whole flat network.

Session controls

Access is reviewed and rechecked, so a laptop left on a train is not a permanent open door.

Safer working anywhere

The same protections at home, in a cafe or in a hotel room as in the office, because the checks travel with the user.

Clear policy

Written rules your staff can follow, plus training that explains why any of it matters.

Signs your remote access needs a rethink

  • A single shared VPN password, or one account per office rather than per person
  • No second factor, or a second factor that is only a text message
  • Remote users landing directly on the flat internal network with no separation
  • Devices you do not manage connecting to systems holding business data
  • No record of who connected, when, from where and to what
  • A VPN appliance still running firmware from several years ago

Questions we get asked about Secure Remote Working

Not necessarily. Many businesses keep a VPN for a narrow purpose and add identity and device checks around their applications. What changes is that access stops being all-or-nothing.

Done properly it is quick. Users sign in with their usual work account and a second factor, then reach their apps. The friction is concentrated into one step rather than spread across every task.

They get limited, browser-based access to specific applications, and they do not store business data on that device. The rules follow the risk.

Increasingly, yes. Cyber insurance questionnaires and frameworks such as Cyber Essentials ask directly about multi-factor authentication and access control, and this is where those answers come from.

For a typical business, a phased rollout over a few weeks. We start with the highest-risk access and work outward, rather than switching everything off on a Friday afternoon.

Not sure whether you need secure remote working?

Book a free 60-minute health check. We will tell you what you actually need, including when the answer is nothing.