How to Secure Your Remote Workers' Laptops
Most small-business security was designed around a building. The firewall sits at the edge of the office, the machines sit inside it, and the network is the boundary. The moment a laptop leaves with an employee, essentially none of that applies — it's on a home network you don't control, alongside devices you've never seen.
The good news is that the fixes are mostly cheap and mostly one-time. The list below is in order of how much risk each item removes, not how hard it is, so if you only get through the first three you've still done the majority of the work.
1. Full-disk encryption
Start here, because it's free, it's already built into the operating system, and it converts your worst-case scenario from a data breach into a hardware loss.
Without it, a stolen laptop is a stolen filing cabinet — the password protects the login screen, not the disk, and pulling the drive out sidesteps it entirely. With it, the thief has a laptop-shaped paperweight. On Windows this is BitLocker; on Mac it's FileVault. Turn it on and store the recovery key somewhere that isn't the laptop.
2. Multi-factor authentication on everything that matters
A remote worker's credentials are more exposed than an office worker's, and stolen credentials are how most small-business compromises actually start. Multi-factor turns a working password into a non-working one.
Prioritise email first — it's the account that can reset every other account. Then anything financial, then anything holding customer data. If you can, prefer an authenticator app over SMS codes, which can be intercepted by someone who convinces a mobile carrier to move a number.
3. Automatic updates, actually verified
Office machines get patched because someone notices them. A remote laptop can sit months behind and nobody finds out until it matters. Most exploited vulnerabilities have had a patch available for a long time.
Turn on automatic updates for the operating system and the browser, and — the part people skip — have a way to confirm they're actually applying. "Automatic updates are enabled" and "this machine is up to date" are different claims, and a laptop that's been asleep for six weeks satisfies the first but not the second.
4. Separate work from personal
The single riskiest arrangement in small-business remote work is one laptop shared between an employee and their household. Family members install things. Kids click things. Personal browsing has a different risk profile from work browsing, and on a shared machine it's your data sitting behind it.
A company-owned machine used only for work is the clean answer. Where budget won't stretch, a separate user account with a separate password is a meaningful improvement over nothing — it's not isolation, but it stops the most casual routes.
5. Know where the data actually lives
Ask a straightforward question about each remote worker: if their laptop died right now, what would be lost? If the answer isn't "nothing," you have a backup problem wearing a security costume.
Work saved to a local desktop is invisible to whatever backup runs in the office. Cloud storage that syncs automatically solves this for most small businesses, with the caveat from our backup guide: sync is not backup, because it replicates deletions and ransomware just as faithfully as it replicates your work.
6. The home network — and being realistic about it
You don't control your employees' home networks and largely can't. But two things are worth asking for, because they're cheap and they close real gaps: change the router's default admin password, and update its firmware. Default credentials for every consumer router model are published online.
Beyond that, treat every network the laptop touches as hostile and secure the laptop rather than the network. That's the right mental model anyway once people work from coffee shops and airports.
7. Have an offboarding process before you need one
When someone leaves, their laptop leaves the building with them, sometimes on bad terms. Decide now: how do you get the hardware back, how quickly can you disable their accounts, and can you wipe the machine remotely if it doesn't come back?
The remote-work version of offboarding is harder than the office version, where you at least know the machine stayed. We covered the setup half of this in the new employee IT checklist; the exit half matters more and gets written down less.
The realistic minimum
If you do four things: encrypt the disks, turn on multi-factor for email, confirm updates are actually landing, and make sure work data isn't only on the laptop. That's most of the risk, and none of it requires new software.
Worth remembering that remote workers are also the likeliest target for the impersonation attacks that are now routine — someone working alone can't turn to a colleague and ask "did you send this?". Our spot-the-phish quiz is a genuinely useful ten minutes for a distributed team, and the free IT audit covers the wider picture. If you'd rather have this set up and kept that way, that's part of managed IT support.
Rather have someone handle it? This is part of our managed it support service across Middlesex, Somerset and Mercer County.
Need a hand?
We handle this for New Jersey businesses and homes
Whether it's a one-off problem or ongoing support, we're happy to take a look — and to tell you honestly if you don't need us.