Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Working From Home Securely: A Practical Guide for Small Businesses

In short

Remote and hybrid working opens up new security gaps, but the fixes are affordable and mostly common sense. This article covers the essentials: securing devices, turning on multi-factor authentication, using a VPN on public Wi-Fi, sharing files safely, and locking down home routers, so your team can work anywhere without putting the business at risk.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Remote work is normal now, and so are the risks

Hybrid and home working have become part of everyday life for UK small businesses. It’s flexible, it’s popular with staff, and for many roles it works brilliantly. But it also quietly moves your business data out of the office, onto home networks, personal devices and public Wi-Fi that you don’t control.

The good news: keeping remote work secure doesn’t need a big budget or a technical team. Most of it is a handful of sensible habits and a few settings turned on. Here’s what actually matters.

Secure the devices first

Every laptop and phone that touches your business email or files is a doorway into your business. Lock those doors.

  • Keep everything updated. Turn on automatic updates for the operating system and apps. Most attacks exploit known flaws that a simple update would have fixed.
  • Use antivirus. The protection built into modern Windows and Mac is a solid baseline, as long as it’s switched on.
  • Encrypt the disk. Turn on BitLocker (Windows) or FileVault (Mac). If a laptop is lost or stolen, encryption means the data on it stays unreadable.
  • Set a proper screen lock. A PIN or password that kicks in automatically, so an unattended device in a cafe isn’t wide open.

Wherever possible, provide company-managed devices rather than relying on personal laptops. It’s easier to support, easier to secure, and keeps work and personal life separate.

Turn on multi-factor authentication everywhere

If you take one thing from this article, take this. Multi-factor authentication (MFA) asks for a second proof of identity, usually a code or a tap on your phone, on top of your password.

It matters because passwords leak constantly. With MFA switched on, a stolen password on its own is useless to an attacker. It’s free on virtually every business platform and, according to the NCSC, it’s one of the most effective steps a small business can take.

Turn it on for email, Microsoft 365, your accounting software, your file storage, everything. For a deeper look at getting logins right, see our guide to the best password manager for small business.

Passwords leak constantly. With MFA switched on, a stolen password on its own is useless to an attacker.

Use a VPN on public Wi-Fi

Public Wi-Fi in cafes, hotels, trains and shared offices is convenient and inherently untrustworthy. You don’t know who else is on the network or what they can see.

A VPN (Virtual Private Network) encrypts your connection, so even on a dodgy network, your traffic can’t be read by others nearby. For mobile and hybrid staff it’s a simple, sensible habit.

We use and recommend Proton VPN for this. It’s from a privacy-focused Swiss provider, it’s easy for non-technical staff to use, and there’s a genuinely usable free tier to trial before you commit. On a secured home network a VPN matters less than good MFA and updates, but the moment someone works from a public hotspot, switch it on.

Share files the safe way

Remote teams live and die by file sharing, and this is where data quietly leaks. The risky habits are emailing sensitive attachments around and copying files onto personal USB sticks or personal cloud accounts.

Do this instead:

  • Use a proper business cloud service with access controls, rather than scattering copies everywhere.
  • Share links, not copies, so there’s one version and you can revoke access later.
  • Set links to expire and limit them to specific people where the content is sensitive.
  • Protect the storage account with MFA, so a leaked password doesn’t expose everything.

For sensitive documents, an end-to-end encrypted service like Proton Drive adds an extra layer, meaning even the provider can’t read your files.

Don’t overlook home Wi-Fi

Your staff’s home routers are part of your security now, whether you like it or not. The two common weak spots are easy to fix:

  • The default admin password. Many routers ship with a well-known default that never gets changed. Ask remote staff to set a new, strong admin password.
  • Old firmware. Routers need updates like anything else. A quick check for firmware updates closes off known flaws.

While they’re in there, make sure Wi-Fi encryption is set to WPA2 or WPA3. It’s a ten-minute job that removes an easy way in.

Watch out for phishing, wherever people are

Remote workers are more exposed to phishing. They can’t lean over to a colleague and ask “does this email look right to you?”, and scammers know it. Remind staff to slow down on unexpected requests, especially anything about payments, invoices or password resets, and to verify by phone if in doubt. A quick, blame-free “check with me first” culture beats any technical filter.

Bringing it together

None of this is exotic. Secure the devices, turn on MFA, use a VPN on public Wi-Fi, share files properly, and tidy up home routers. Do those consistently and you’ve closed the gaps that catch most small businesses out.

The hard part is doing it across a whole team, consistently, without it slipping. That’s where having it managed for you helps: devices kept updated, MFA enforced, and staff supported wherever they work. If you’d like a hand getting remote work locked down, explore our cyber security services or get in touch for a plain-English review of how your team works today.

Frequently asked questions

Is it safe to let staff use their own personal laptops for work?

It can be, but it's risky by default. Personal devices are often shared with family, patchy on updates and mixed in with personal files. If you allow it, insist on the basics: up-to-date software, antivirus, a strong screen lock, disk encryption and no work data saved locally. A managed work device is safer and simpler to support.

What's the single most important thing to turn on?

Multi-factor authentication (MFA) on every business account, especially email and Microsoft 365. It means a stolen password alone isn't enough to get in. It's free on almost every platform and blocks the overwhelming majority of account takeover attempts. If you do nothing else this week, do this.

Do my staff really need a VPN at home?

At home on their own secured Wi-Fi, a VPN is less essential than good MFA and updates. Where a VPN genuinely matters is on public Wi-Fi, in cafes, hotels, trains and shared workspaces, where a VPN encrypts the connection so others on the network can't snoop. It's a sensible habit for any mobile worker.

How should people share files securely when working remotely?

Use a proper business cloud service with access controls, not email attachments or random USB sticks. Share links rather than copies, set them to expire, and only give access to people who need it. Turn on MFA for the storage account too, so a leaked password doesn't expose your files.

What about home Wi-Fi, is that a weak point?

It can be. The main risks are the router's default admin password never being changed and old firmware. Ask remote staff to change the router admin password, use WPA2 or WPA3 encryption, and install router updates. It takes ten minutes and closes an easy way in.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.