Metaluxo
← Insights

Startups & SMEs

Remote Work Security Policy: What Changed After 2020

Remote work is permanent — your policy should be too.

In March 2020, you sent an email: “Work from home. Use your own laptop. Stay safe.” Five years later, that email is still your remote work security policy.

At Metaluxo we review IT policies for SMEs across the EU. The remote work policy is consistently the most outdated document we find. This post covers what a 2025 policy needs to address.


What changed

2020: Temporary. Most staff worked from home occasionally. The policy was an exception.

2025: Permanent. Many SMEs are fully remote or hybrid. The policy is the default, not the exception.

This changes the risk profile. In 2020, a compromised home laptop affected one person for a few weeks. In 2025, a compromised home laptop may be the primary access point to your entire cloud infrastructure.


The 2025 remote work security checklist

1. Device standards

Company devices: All work must be conducted on company-managed devices with endpoint detection, disk encryption, and remote wipe capability.

Personal devices: Only permitted if enrolled in mobile device management (MDM) and meeting minimum security standards.

No shared devices: Work accounts must not be used on devices shared with family members.

2. Home network requirements

  • WPA3 or WPA2 encryption required
  • Default router passwords changed
  • Router firmware kept up to date
  • Work devices on a separate network or VLAN where possible

You cannot enforce this technically for every employee, but you can require them to confirm compliance annually.

3. Physical security

  • Devices locked when unattended
  • Screens positioned away from windows and cameras
  • Confidential documents shredded, not discarded
  • No work in public spaces without privacy screens

4. Access control

  • VPN required for all internal system access
  • MFA on all work accounts
  • No password sharing, even with family
  • Automatic screen lock after 5 minutes of inactivity

5. Data handling

  • Customer data must not be downloaded to personal devices
  • Cloud storage (company-approved) is the only permitted file repository
  • USB drives are blocked or encrypted
  • Printing at home is prohibited for confidential documents

6. Incident reporting

  • Lost or stolen devices: report within 4 hours
  • Suspected compromise: report immediately
  • Family member accessed work device: report and reset credentials

The policy document

A 2025 remote work policy should be 2–3 pages and cover:

  1. Scope (who it applies to)
  2. Device requirements (company vs. personal)
  3. Network and physical security standards
  4. Access control requirements
  5. Data handling rules
  6. Incident reporting procedure
  7. Training requirements
  8. Consequences of non-compliance

Every employee should read and acknowledge the policy annually.


At Metaluxo we write remote work security policies for SMEs as part of our vCISO engagements. If your policy is still the email you sent in 2020, book a free 30-minute consultation and we will bring it up to date.

Common questions

Do we need to secure employees home networks?

You cannot control home networks, but you can require minimum standards: WPA3 encryption, router firmware updates, and a separate network for work devices where possible.

Can employees use personal laptops for work?

Only with endpoint management and encryption. A personal laptop without MDM or disk encryption is an unacceptable risk for most businesses handling customer data.

How do we handle data breaches on personal devices?

Your incident response plan must cover personal devices. The policy should require employees to report lost or compromised devices within 4 hours.

Related reading

Send us a message
Message us Book now