03333 44 6500 Mon–Fri 8am–6pm
Client Portal
Cybersecurity

The Complete Guide to Secure Remote Working for UK Small Businesses

Remote and hybrid working is now permanent for most teams. This guide covers VPNs, device management, phishing risks and the policies you need to keep remote staff secure - without making their lives difficult.

CH
CloudHost Team
22 Mar 2026 · 9 min read

Remote and hybrid working has shifted from an emergency measure to a permanent feature of how UK small businesses operate. That's a positive development for flexibility and staff retention - but it has significantly expanded the attack surface that businesses need to protect.

When your team works from offices, coffee shops, home networks, and hotel Wi-Fi, the traditional model of securing a physical office perimeter doesn't work. This guide covers what a genuinely secure remote working setup looks like for a small business in 2026.

The Core Problem: You Can't Control the Network

In an office, you control the network. Your firewall sits at the perimeter, your devices connect to a managed switch, and you can see what's on the network. When staff work remotely, they're connecting from networks you don't control - home broadband, public Wi-Fi, shared workspaces - any of which could be compromised or insecure.

The response to this isn't to try to extend your office network everywhere. It's to assume the network is untrusted and protect the device and identity instead. This is the core principle behind the "zero trust" security model that most security frameworks now recommend.

Essential 1: Multi-Factor Authentication (MFA)

If you implement nothing else from this guide, implement MFA. It is the single highest-impact security control for remote working.

MFA requires a second form of verification - typically a code from an authenticator app - in addition to a password. Even if an attacker obtains a user's password through phishing or a data breach, they cannot access the account without the second factor.

MFA should be enabled on:

  • Microsoft 365 / Google Workspace accounts (every user, no exceptions)
  • Any cloud applications your business uses (CRM, accounting software, project management)
  • Remote desktop access (RDP, VPN login)
  • Domain admin accounts

CloudHost recommendation: Use an authenticator app (Microsoft Authenticator, Google Authenticator) rather than SMS-based MFA wherever possible. SMS codes can be intercepted through SIM-swapping attacks; authenticator apps cannot.

Essential 2: Device Management (MDM/Intune)

You need to know - and have some control over - the devices your staff use to access company data. This is what Mobile Device Management (MDM) provides.

For businesses using Microsoft 365, Microsoft Intune is included in Business Premium and provides:

  • Visibility of all enrolled devices and their compliance status
  • Enforcement of encryption (BitLocker on Windows, FileVault on Mac)
  • Remote wipe capability if a device is lost or stolen
  • Policy enforcement - requiring PIN/password, blocking jailbroken devices, enforcing OS updates
  • Conditional access - blocking access to company data from non-compliant devices

If you allow personal devices for work (BYOD), Intune can apply policies to the work apps without touching personal data - a sensible balance between security and privacy.

Essential 3: VPN or Zero Trust Network Access

For businesses with on-premises servers or systems that staff need to access remotely, a VPN (Virtual Private Network) creates an encrypted tunnel between the remote device and your office network.

Traditional VPNs work well but have limitations - they typically give broad network access once connected, which means a compromised device on a VPN can move laterally through your network. More modern approaches include:

  • Split-tunnel VPNs - only route specific traffic (to on-premises systems) through the VPN, not all internet traffic
  • Zero Trust Network Access (ZTNA) - provides access only to specific applications, not the whole network, with continuous verification of device health and identity

For businesses that have largely moved to Microsoft 365 and cloud applications, a traditional VPN may not be necessary at all - Intune-managed devices with Conditional Access and MFA can provide strong security without the complexity.

Essential 4: Email Security and Anti-Phishing

Phishing - deceptive emails designed to steal credentials or deliver malware - is responsible for the majority of successful cyberattacks on UK small businesses. Remote working makes this worse, because staff are less likely to turn around and ask a colleague "did you send this email?" when they're working from home.

Key email security measures include:

  • Microsoft Defender for Office 365 (included in M365 Business Premium) - scans links and attachments in real time, blocks known malicious content
  • DMARC, DKIM, and SPF records - DNS records that make it harder for attackers to send emails that appear to come from your domain
  • Safe Links - rewrites URLs in emails so that even if a user clicks a malicious link, it's checked at time of click, not just at time of delivery
  • Staff awareness training - regular simulated phishing exercises that train staff to recognise and report suspicious emails

Essential 5: A Remote Working Policy

Technology alone isn't enough. Staff need to know what's expected of them when working remotely. A remote working policy doesn't have to be lengthy - but it should cover:

  • Which devices are approved for work (company-managed only, or permitted personal devices?)
  • Requirements for home Wi-Fi (WPA2/3 encryption, router password changed from default)
  • Prohibition on using public Wi-Fi for sensitive work without a VPN
  • Screen locking requirements
  • How to report a lost or stolen device
  • How to report a suspected phishing email or security incident

The policy should be communicated to all staff and reviewed annually. CloudHost can provide a template remote working policy as part of our managed IT service - tailored to your specific setup.

What About Personal Devices?

The question of BYOD (Bring Your Own Device) is one of the most common we encounter with businesses across Nottingham, Derby and Leicester. The honest answer: personal devices are manageable, but they increase complexity and risk.

If you allow personal devices, at minimum:

  • Require MFA on all accounts accessed from personal devices
  • Use Intune App Protection Policies to separate work apps/data from personal data
  • Define clear acceptable use and data handling requirements
  • Have a process for de-authorising a device when a staff member leaves

Pulling It All Together

A secure remote working setup for a UK small business doesn't require enterprise-grade complexity or budget. The combination of Microsoft 365 Business Premium, properly configured MFA, and a clear policy covers the vast majority of the risk.

The businesses that get this wrong aren't cutting corners on budget - they're cutting corners on configuration. Turning on MFA but not enforcing it. Deploying Intune but not requiring compliance before granting data access. Having a VPN but not requiring it for remote desktop access.

If you'd like CloudHost to review your current remote working setup and identify gaps, book a free IT review. We cover businesses across the East Midlands and can usually turn around an assessment within a week.

Next Step

Is Your Remote Working Setup Secure?

CloudHost helps businesses across the East Midlands build secure, productive remote working environments - from device management and VPNs to phishing protection and security policies.

Or call: 03333 44 6500 · Mon–Fri 8am–6pm