Back to Blog
Best Practices

Physical Device Security in a Remote Work World

Plaza Cyber Security TeamJanuary 30, 20264 min read
An open laptop on a desk in a home office
An open laptop on a desk in a home office

The shift to remote and hybrid work has fundamentally changed the security perimeter. Devices that once remained within the controlled environment of an office now travel to homes, coffee shops, airports, and co-working spaces. Protecting these devices from physical threats and insecure network environments is critical for maintaining organizational security in the modern workplace.

Full Disk Encryption Is Non-Negotiable

Every device that stores or accesses organizational data must use full disk encryption. If a laptop is lost or stolen, encryption ensures that the data on the drive is inaccessible without the correct credentials. Without encryption, anyone with physical access to the device can remove the hard drive and read its contents directly, bypassing all operating system access controls.

Modern operating systems include built-in encryption tools. BitLocker on Windows and FileVault on macOS provide transparent full disk encryption that operates with minimal performance impact. Ensure that encryption is enforced through centralized policy management and that recovery keys are stored securely in a central repository so that IT teams can assist with legitimate recovery scenarios.

Extend encryption to removable media as well. USB drives, external hard drives, and memory cards that are used to transport organizational data should be encrypted. Better yet, implement policies that restrict or prohibit the use of removable storage devices, directing users to approved cloud storage services instead.

Screen Locks and Access Controls

Configure all devices to lock automatically after a short period of inactivity. Five minutes is a reasonable maximum for laptops, and two minutes for mobile devices. Require strong authentication to unlock, using biometrics where available combined with a PIN or password as a fallback.

Disable features that display sensitive information on locked screens, such as email previews and message notifications. On mobile devices, configure lock screen settings to show minimal information. These small details prevent casual observation of sensitive data by people near the device.

Device Tracking and Remote Management

Enroll all organizational devices in a mobile device management or unified endpoint management platform. These tools provide the ability to locate lost devices, remotely lock them, and as a last resort, remotely wipe all data. Ensure that remote wipe capabilities are tested regularly so that they function when needed.

Enable location services on organizational devices to support tracking of lost or stolen equipment. Configure devices to report their location at regular intervals so that the last known position is available even if the device is subsequently powered off or disconnected from the network.

The Dangers of Public Wi-Fi

Public wireless networks at hotels, airports, coffee shops, and conferences present significant security risks. Attackers can set up rogue access points that impersonate legitimate networks, intercepting all traffic that passes through them. Even on genuine public networks, traffic is often unencrypted and visible to other users on the same network.

Require all remote workers to use a corporate VPN when connecting from any untrusted network. The VPN encrypts all traffic between the device and the corporate network, preventing interception regardless of the security of the underlying wireless connection. Configure the VPN client to connect automatically when the device is on a non-trusted network.

For situations where VPN access is unavailable, use a mobile hotspot from a cellular device rather than connecting to public Wi-Fi. Cellular connections provide a significantly more secure alternative for handling sensitive data when away from trusted networks.

Physical Theft Prevention

Train employees on basic physical security practices for mobile devices. Never leave laptops unattended in public spaces, even briefly. Use cable locks to secure laptops at desks in shared workspaces or hotel rooms. Store devices out of sight in vehicles rather than leaving them visible on seats. At home, keep work devices in a secure location, especially in shared living situations.

When traveling, carry laptops in bags that do not obviously contain computer equipment to reduce the likelihood of targeted theft. Be aware of shoulder surfing in public spaces, where nearby individuals may observe screens or keyboard input. Use privacy screens on laptops to limit the viewing angle and prevent casual observation of sensitive information.

BYOD Policies

Organizations that allow employees to use personal devices for work must implement clear bring-your-own-device policies. Define minimum security requirements including operating system version, encryption status, screen lock configuration, and antivirus presence. Use mobile device management tools that can create a separate, encrypted container for organizational data on personal devices, allowing remote wipe of corporate data without affecting personal content.

Physical device security in a remote work environment requires a combination of technology, policy, and user education. By addressing encryption, access controls, network security, and physical awareness, organizations can protect their data regardless of where their employees work.

#physical-security#remote-work#devices#encryption