
A VPN encrypts your internet traffic so your ISP, your landlord, or the coffee shop WiFi cannot see what you are doing.
A VPN encrypts your internet traffic so your ISP, your landlord, or the coffee shop WiFi cannot see what you are doing.
When to use:
Which VPN: If your company does not provide one, use Mullvad (€5/mo, audited no-logs) or ProtonVPN (free tier available).
If your company gives you a laptop, use it only for work. Do not browse social media, shop online, or let your kids use it.
Do not use the same password for work and personal accounts. A password manager like Bitwarden or 1Password lets you have separate vaults:
Work Vault: Company email, VPN, HR system, Slack
Personal Vault: Personal email, banking, shopping, social media
Your router came with "admin/admin" or "admin/password." Change it.
Router (usually 192.168.1.1 or 192.168.0.1):
- Change default admin password
- Update router firmware
- Disable WPS (WiFi Protected Setup — it is insecure)
- Use WPA3 encryption (or WPA2 if WPA3 unavailable)
- Change SSID (network name) to something that does not identify you
Set up a separate WiFi network for smart home devices (thermostat, lights, refrigerator). These devices have poor security. If they are compromised, the attacker cannot reach your work laptop.
Remote workers often delay updates because they are in the middle of something. Do not.
| What | Why | Frequency |
|---|---|---|
| Operating system | Patches critical vulnerabilities | Automatic |
| Browser | Most common attack vector | Automatic |
| VPN client | Security fixes | Automatic |
| Antivirus | Signature updates | Automatic |
| Router firmware | Network-level security | Monthly check |
| All installed apps | Vulnerabilities found constantly | Enable auto-update |
Enable automatic updates everywhere. The 5 minutes of inconvenience is better than a ransomware attack.
Enable MFA on:
Preference order:
Passkeys (Face ID, fingerprint, Windows Hello) are phishing-resistant and more convenient than passwords.
Every time you stand up, lock your screen. It takes one second.
| Device | Shortcut |
|---|---|
| Mac | Control + Command + Q or corner hot corner |
| Windows | Windows + L |
| Linux | Super + L |
Enable auto-lock:
If you work in public places, a privacy screen filter makes your screen unreadable from any angle other than directly in front.
Remote workers get more phishing emails because attackers know you rely heavily on email.
If an email asks you to do something financial or sensitive, verify it through a different channel. Call the person. Send a Slack message. Do not reply to the email.
If your laptop is lost or stolen, encryption prevents anyone from reading your data.
| Device | How to Enable |
|---|---|
| Mac | System Settings → Privacy & Security → FileVault (Turn On) |
| Windows | Settings → Privacy & Security → Device Encryption (or BitLocker) |
| Linux | LUKS during installation |
| Phone | iPhone: Settings → Face ID & Passcode → Data Scrambling. Android: Settings → Security → Encrypt phone. |
Use full disk encryption. There is no downside on modern hardware.
Remote work security is mostly common sense — lock your screen, use strong passwords, be suspicious of unexpected emails, keep everything updated. The biggest risk is not sophisticated hacking — it is small, avoidable mistakes.
The 10 tips above cover 90% of remote work security risks. Implement them today.
No approved comments are visible yet. New community replies may wait for moderation.