The debate on remote vs in-office work has touched on a number of business aspects. Whether it’s productivity and effectiveness or security and management challenges, many organisations choose a hybrid working model to maintain business continuity and meet their employees’ needs, at least to some extent.
However, the perks of remote and flexible working are too appealing for workers to be won over with “endless coffee and snacks” in the office. In times of Great Resignation and labour shortages, some companies offer flexible working to keep the ball rolling.
One of the main challenges of this working model is keeping customers’ data safe and secure, especially if the workers are using their own devices to do the job, which most often is the case.
Security, but at what cost?
In a hybrid model, companies can give their own devices to new hires and risk not getting them back when employees resign, creating unexpected operational costs. Still, companies prefer corporate devices as they are made to be used only for work and to keep data safe.
However, the hybrid model raises concerns around these devices being transported to and from the office multiple times per week, when they can be stolen or damaged.
This also leads to losses for the company, and the only solution for both sides is to enable agents to use personal devices at home and keep corporate devices in the office.
Allowing employees to use personal devices for work involves a certain amount of risk since the devices are unknown to the network and might not be secure enough.
Commenting on this concern, Andrew McNeile, Chief Customer Officer at Thinscale, said: “The key issue is that you are always introducing unknowns into your network when employees access corporate resources off-site.
The question is; how do you turn something that is unknown in something known and controlled? Organisations will introduce a VPN, an antivirus or a VDI to provide a basic level of protection for people connecting from home.
“The danger however is that these types of solutions don’t protect the endpoint, the actual device, itself. And this is often the weakest and most vulnerable part of the IT infrastructure.”
Even when a VPN or an antivirus is installed, there are still threats to data circulating through employees’ personal devices.
McNeile explains: “There are 3 main categories of threats to the endpoint. The first is keylogging and screen-scraping software which track the inputs on a keyboard or records what’s happening on a monitor to gather passwords and payment details.
“The second is data leakage, both intentional and unintentional. What happens if an employee copies and pastes customer data for example? And finally, malware and viruses introduced via USBs or other paraphernalia, which can not only compromise the device but the data as well.”
BYOD for all
Organisations also have to think of those employees who are not willing to switch up devices to separate their work life from their personal life.




