Remote Working Checklist: What to Consider Before Your Employees Work from Home

Remote Working Checklist: What to Consider Before Your Employees Work from Home

By |

Estimated reading time: 9 minutes

Remote working can be a brilliant way to give employees greater flexibility, improve productivity and keep your business running smoothly wherever people are based. But successful homeworking needs more than handing someone a laptop and making sure they have an internet connection.

When an employee works from home, their laptop, internet connection, user account and access to company systems effectively become an extension of your business IT environment. That means remote working needs to be considered from both an employee and an IT perspective.

For small and medium-sized businesses, the aim should be to make remote working practical, secure and consistent. Employees need to be able to access the systems and information required to do their jobs without introducing unnecessary security risks or making it harder for customers and colleagues to reach them.

The following checklist covers the main areas businesses should consider before employees work remotely, from equipment and connectivity through to Microsoft 365, cyber security, telephony and business continuity.

1. Start with the Homeworking Setup

A suitable homeworking environment helps employees work comfortably, safely and productively. Employers should consider their health and safety responsibilities for people working from home, including appropriate workstation assessments for regular display screen users.

This does not necessarily mean recreating the office in every employee's home, but staff should have a suitable place to work and the equipment needed to perform their role effectively.

Consider whether the employee has:

  • A suitable desk or work surface.
  • An appropriate and adjustable chair.
  • A separate monitor where this would make regular work more comfortable.
  • A keyboard, mouse or laptop stand where required.
  • Suitable lighting without excessive glare.
  • A reasonably quiet and private place to work.
  • An appropriate headset if they regularly make calls or attend online meetings.

Employees who regularly work from home should also understand how to report problems with their workstation or equipment.

It is worth agreeing from the outset what equipment the business will provide, what employees are responsible for and who they should contact when something isn't working properly.

2. Check Connectivity and Broadband

Even a perfectly configured laptop isn't particularly useful if the employee cannot maintain a reliable connection.

The requirements will vary according to the person's role. Someone primarily working with email and cloud documents may have relatively modest requirements, while employees regularly using video conferencing, cloud applications, large files or remote desktop systems will depend much more heavily on a stable connection.

Wi-Fi coverage within the home matters too. A fast broadband service doesn't necessarily mean there will be a reliable wireless connection in the room where somebody actually works.

Before relying on home connectivity, check whether video and voice calls are stable, whether business applications perform acceptably and whether employees can reach everything they need without complicated workarounds.

For employees performing particularly important roles, it is also worth considering what happens when their home internet connection fails. A mobile connection may provide a temporary fallback, but the appropriate solution depends on the work they need to perform.

3. Decide Whether Employees Need a VPN

One of the most common questions businesses ask when setting up remote working is: "Do our employees need a VPN?"

The answer depends on how your systems are configured.

A VPN can be useful when employees need secure access to office-based servers, legacy applications, internal systems or file shares that are not otherwise safely available over the internet. It creates an encrypted connection between the employee's device and the business network.

However, not every remote worker needs a traditional VPN.

For example, an employee who needs to use an application hosted on a server inside the office may require one. Someone whose work takes place entirely within Microsoft 365 and other cloud applications may not, provided appropriate identity, device and access controls have been configured.

Modern cloud environments can often use technologies such as multi-factor authentication, Conditional Access and managed devices to control who can access company information and under what circumstances.

The important question therefore isn't simply "Do we have a VPN?" It is: How can employees securely access the systems they need without exposing systems they don't?

Whatever remote access method you use should be maintained, monitored and simple enough that employees don't feel the need to create insecure workarounds.

If you're unsure which approach is appropriate, our guide to connecting remote staff securely to your office network explains when a VPN is needed and when cloud-based alternatives may be more suitable.

4. Make Microsoft 365 Part of Your Remote Working Strategy

For many SMEs, Microsoft 365 has become a central part of remote and hybrid working. Email may sit within Exchange Online, documents within SharePoint or OneDrive, and day-to-day communication within Microsoft Teams.

That can make remote working considerably easier because employees are no longer necessarily dependent on being physically connected to the office network.

But moving information into Microsoft 365 doesn't automatically make a business secure.

User accounts still need protecting, permissions need managing and devices need to be appropriately controlled. Features such as multi-factor authentication can make it significantly harder for somebody with a stolen password to access an employee's account.

Depending on your Microsoft 365 licensing and requirements, Conditional Access and device management can provide further control over how company information is accessed.

For example, a business may decide that sensitive systems can only be accessed by authorised users using compliant, managed devices rather than allowing unrestricted access from any computer.

This is why Microsoft 365 should be treated as part of your wider IT and security strategy rather than simply as a collection of cloud applications.

5. Secure Devices Before They Leave the Office

A remote worker's laptop remains part of your business environment even when it is sitting on their kitchen table.

Ideally, employees should use properly configured and managed company devices. This gives the business considerably more control over security, software, updates and what happens if equipment is lost or stolen.

Business devices should normally have appropriate endpoint protection, automatic security updates, encryption, screen locking and controlled administrator permissions.

Where appropriate, management tools can also provide visibility over device health and allow action to be taken if a device is lost or compromised.

This becomes particularly important when employees work remotely for long periods because their devices may rarely return to the office.

6. Be Careful with Personal Devices and BYOD

Allowing employees to use their own laptops, phones or tablets can appear convenient, particularly when remote working is introduced quickly. However, Bring Your Own Device (BYOD) arrangements create additional questions.

How do you know whether the device is patched? Does anybody else in the household use it? Is company information stored locally? Is the device encrypted? What happens to business information when the employee leaves?

Personal devices can also blur the distinction between business and personal data.

Where possible, providing a managed business device gives the organisation much greater control. Where BYOD is necessary, there should be a clear policy defining which devices can access company systems, what security requirements apply and how business information is protected.

7. Protect Accounts, Passwords and Company Data

Remote working makes identity security particularly important.

If an attacker can successfully sign in as an employee, they may be able to access email, files, finance systems and customer information from anywhere without ever needing physical access to your office.

Multi-factor authentication should therefore be enabled on important business systems wherever possible.

Permissions also matter. Employees should only have access to the systems and information required for their roles. Administrator accounts should be carefully controlled, and access should be reviewed when somebody changes role or leaves the organisation.

Company information should also be stored in approved business systems rather than being copied into personal cloud accounts, USB drives or other unmanaged locations.

Employees should understand how information can be safely shared and, importantly, what to do when they receive an unexpected login prompt, suspicious email or unusual request.

If you're not sure how well these protections are currently configured, our guide to checking whether your business IT systems are secure covers the key areas worth reviewing.

8. Don't Forget the Human Side of Cyber Security

Technology can reduce risk, but employees still need to recognise when something doesn't look right.

Remote workers may receive phishing emails, fake Microsoft 365 login pages, unexpected MFA prompts, fraudulent payment requests or messages pretending to come from senior colleagues.

When people are outside the office, it can also be harder to lean across a desk and ask somebody else whether an email looks suspicious.

Staff should therefore know how to report suspicious activity and feel comfortable doing so quickly.

Regular security awareness training can help employees recognise common attacks, while simulated phishing exercises can provide useful practical experience.

For businesses handling particularly sensitive information, such as accountancy practices, there may be additional controls worth considering. Our guide to IT support and security for accountants looks at these areas in more detail.

9. Make Sure Customers Can Still Reach Your Team

Telephony is easily overlooked when businesses plan remote working.

Employees may be able to access their email and files perfectly from home, but what happens when a customer calls their normal office number?

A modern cloud telephone system can allow employees to make and receive business calls wherever they are working. Calls can be routed to individuals or teams, while features such as call queues, voicemail and out-of-hours messages can continue to operate without employees being physically present in the office.

Softphone applications and services such as Microsoft Teams Phone can also allow employees to use business numbers from their computer or mobile device rather than giving customers their personal mobile numbers.

The objective should be that, from a customer's perspective, it doesn't particularly matter whether the person answering their call is in the office or working remotely.

Call quality should also form part of your connectivity testing, and businesses with call recording or other compliance requirements should ensure those controls continue to operate for remote users.

10. Make Sure Remote Working Doesn't Undermine Your Backups

Backups are another area where remote working can expose weaknesses.

If an employee saves important documents solely to the local storage on their laptop, are those files actually included in your backup arrangements?

Employees should understand where business documents are supposed to be stored. Using managed business locations such as SharePoint, OneDrive or approved file systems can help prevent important information becoming scattered across individual devices.

Backups should themselves be monitored and tested. Being able to see that a backup job completed isn't the same as knowing the business can successfully recover its information.

This becomes part of the wider question of how your organisation would continue operating after a significant IT problem. Our guide to building a disaster recovery plan for a small business explains how backups, recovery priorities and business continuity fit together.

11. Plan What Happens When Something Goes Wrong

Remote working arrangements shouldn't assume that every laptop, internet connection and cloud service will work perfectly forever.

Think about some simple scenarios. What happens if an employee's laptop fails on Monday morning? What happens if their broadband goes down? What happens if a laptop containing business information is stolen?

Similarly, what happens if an employee believes their Microsoft 365 account has been compromised, or if the office system remote workers depend upon becomes unavailable?

Employees should know who to contact and what they should do first. Your IT provider should also be able to support remote users without requiring every problem to be solved by bringing equipment back to the office.

For more serious incidents, these procedures should connect with your wider disaster recovery and business continuity plan rather than existing as a completely separate process.

12. Set Clear Remote Working Policies and Expectations

Remote working works best when everyone understands what is expected.

Policies don't need to become enormous documents full of technical terminology. They should answer the practical questions employees are likely to encounter.

That includes which systems should be used for meetings and file sharing, how confidential information should be handled at home, whether documents can be printed, how IT problems should be reported and what to do if equipment is lost or stolen.

The business should also establish sensible expectations around availability and communication.

Remote working shouldn't result in employees feeling that they need to be permanently online simply because they aren't physically visible in the office.

13. Have a Process for When Somebody Leaves

Offboarding needs additional thought when employees work remotely because company equipment and access may be distributed outside the office.

When somebody leaves the organisation, their access should be removed promptly and systematically.

That can include disabling accounts, revoking active sessions, removing VPN or remote-access permissions and transferring ownership of important business information.

Company laptops, phones and other equipment should also be recovered and securely processed before being allocated to another employee.

Having an up-to-date asset register makes this considerably easier because the business can identify what equipment an employee has rather than trying to reconstruct that information after they have left.

14. Support Wellbeing and Team Connection

Remote working isn't only an IT project. It affects communication, management and employee wellbeing too.

Some employees thrive when working from home, while others may feel isolated or find it difficult to separate their working day from their personal time.

Regular one-to-one conversations, sensible workloads and clear communication can help managers identify problems before they become more serious.

Meetings should have a purpose rather than being used simply to prove everybody is working, while employees should know how to ask for support when they need it.

The most successful remote-working arrangements combine reliable technology with sensible management practices.

Remote Working Checklist for Employers

Once the foundations are understood, a shorter checklist becomes useful. Before employees regularly work from home, check that you have:

  • Completed appropriate homeworking and workstation assessments.
  • Provided suitable laptops, monitors, keyboards, mice and headsets where required.
  • Checked broadband, Wi-Fi and call quality.
  • Decided whether employees require a VPN or whether secure cloud access is more appropriate.
  • Enabled multi-factor authentication on important systems.
  • Provided managed business devices wherever practical.
  • Configured appropriate patching, encryption and endpoint protection.
  • Defined where business files and information should be stored.
  • Reviewed user permissions and access to company systems.
  • Provided suitable business telephony for remote employees.
  • Documented what happens if equipment is lost, stolen or compromised.
  • Provided appropriate cyber security awareness training.
  • Established a clear employee offboarding process.
  • Considered backup connectivity and equipment arrangements for important roles.
  • Connected remote-working procedures with your wider disaster recovery plan.
  • Agreed communication, availability and support arrangements.

Remote working arrangements should also be reviewed periodically. Businesses change, employees change roles and technology evolves, so a setup that worked two years ago may no longer be the most appropriate approach today.

Frequently Asked Questions About Remote Working IT

Do employees need a VPN to work from home?

Not necessarily. A VPN may be appropriate when employees need to securely access systems or applications hosted inside the company network. Businesses primarily using Microsoft 365 and other cloud applications may be able to use modern identity and device controls instead. The correct approach depends on where your systems are hosted and how employees need to access them.

Is Microsoft 365 secure for remote working?

Microsoft 365 provides a range of security capabilities suitable for remote working, but they need to be configured appropriately. Multi-factor authentication, permissions, device management, security policies and monitoring all contribute to the security of the environment.

Should employees use their own laptops when working from home?

Where practical, company-managed devices are generally preferable because the business has greater control over security, updates, encryption, software and business information. If employees use personal devices, the organisation should have a clear BYOD policy and appropriate technical controls.

How can a business secure employees working remotely?

Remote-working security normally involves several layers rather than a single product. Managed devices, multi-factor authentication, secure remote access, endpoint protection, patching, appropriate permissions, secure file storage and staff awareness should work together to reduce risk.

Can employees answer their office phone when working from home?

Yes. Cloud telephony, VoIP and services such as Microsoft Teams Phone can allow employees to make and receive business calls remotely while continuing to use company telephone numbers, extensions, call queues and voicemail.

What equipment should an employer provide for remote working?

The appropriate equipment depends on the employee's role and working arrangements. It may include a managed laptop, monitor, keyboard, mouse, headset and other equipment needed to create a suitable workstation. Businesses should also consider connectivity, security and how equipment will be supported and maintained.

Make Remote Working Part of Your IT Strategy

Remote working can be a real advantage for a business, but it works best when it has been designed rather than simply allowed to evolve.

The objective is to give employees the flexibility they need while maintaining control over company systems, information and communications.

For some businesses, that may mean improving an existing Microsoft 365 environment. Others may need better device management, more secure remote access, improved cyber security or a cloud telephone system that allows employees to work from anywhere.

And as working arrangements evolve, these technologies should form part of the wider IT strategy rather than being managed as individual fixes.

If managing remote devices, Microsoft 365, security and day-to-day support is becoming too much to handle internally, our guide to outsourcing IT support without hiring a full-time IT manager explains another option for growing businesses.

Not Sure Whether Your Remote Working Setup Is Secure?

Remote working often evolves gradually. A few laptops are taken home, Microsoft 365 is introduced, an old application still needs a VPN and office calls start being diverted to mobiles.

Individually, each decision may make sense. Over time, however, businesses can end up with a mixture of technology that works but isn't necessarily as secure, manageable or reliable as it should be.

Telanova can review how your employees currently work remotely and help identify where improvements could be made. From Microsoft 365 and managed devices to secure remote access, cyber security, backups and business telephony, we can help you build a remote-working environment that works for your employees as well as your business.

Our Bracknell-based team supports businesses throughout the local area, including Bracknell, Wokingham, Reading and Ascot.

If you're unsure whether your current remote-working environment is secure, reliable or suitable for long-term use, speak to Telanova on 01344 989 530 to discuss your setup.