Remote working stayed. Has your security kept up?
For a lot of SMEs, remote working was never really planned. It was assembled in a hurry back in 2020, out of whatever laptops, routers, and video call subscriptions got people through the week, and it mostly stayed that way once things settled down. The laptop that went home five years ago might still be the one someone's using now. The home broadband router is whatever the internet provider sent out, unopened box and all. A personal phone probably has the company email app on it, alongside everything else in that person's life.
None of that is unusual, and none of it is really anyone's fault, but five years is a long time for a stopgap to go unreviewed, and how people work has moved on again since 2020 in ways that quietly change the risk. Meetings get recorded and transcribed by AI note-takers as a matter of course now. Personal devices carry more of the business than most owners realise and the tools built to keep a scattered team securely connected, VPNs especially, were largely designed for a world where a handful of people worked from home occasionally, not one where most of the team might not see the office in a given month.
Your video calls have picked up a new risk, and it isn't the wifi
The National Cyber Security Centre updated its guidance on securing home and remote working this year, and it's worth a read even if your team has been on Teams or Zoom for half a decade. The basics are still the basics: a strong, unique password on the meeting account, two-step verification (2SV) turned on, and a waiting room or lobby so uninvited guests can't just wander into a call. NCSC's guidance for home and remote working covers all of this in plain terms.
What's newer is the AI note-taker sitting in on the call. A growing number of meetings now have an AI assistant quietly recording, transcribing, and summarising everything that's said, sometimes added by the host, sometimes by a guest who brought their own. That's not a problem in itself, but it raises a question most businesses haven't actually answered: who can see that transcript afterwards, where does it get stored, and would you be comfortable if a client-sensitive conversation ended up searchable in someone's notes app six months later.
The VPN you set up in 2020 might not be doing what you think
Most SMEs that went remote in 2020 did it with a VPN (a virtual private network), which creates a secure tunnel between someone's home connection and the office network. It's a reasonable tool and plenty of businesses still run one perfectly well. However, VPNs were built for a model where remote access was the exception, and they tend to assume that once someone's connected, they're trusted for everything on the network behind it. That doesn't fit as neatly when most of the team is remote most of the time, which is part of why some IT providers are now moving clients toward a "zero trust" approach instead: checking who someone is and what they're allowed to touch every time they try to access something, rather than trusting the whole network once they're in. Neither approach is automatically right or wrong. It depends on your setup, and it's a genuinely good question to put to whoever manages your IT: is our remote access still the right shape for how the team actually works now?
We've written before about the router sitting at the edge of that whole setup, twice this year in fact, so we won't repeat it here. If you haven't seen either post, they're worth five minutes. This one's about everything on the other side of it: the calls, the laptops, and the people connecting in.
What's worth checking this month
Turn on 2SV for every meeting account your team uses, and switch on waiting rooms for anything client-facing or confidential.
Find out whether your video calls use an AI note-taker, and if so, who can see the transcripts and how long they're kept.
List the personal devices being used for work. Check whether the business could remote-wipe any of them if one was lost or stolen tomorrow.
Ask your IT provider whether your VPN still fits how the team works, or whether a different approach is worth considering.
Put a date in the diary, once a year is plenty, to review the whole remote working setup rather than just the security tools bolted onto it.
If it's been a while since anyone looked at how your team connects in from home, a remote working review is usually a straightforward half-day exercise, and it's something we do regularly for clients. If that would help, drop us a line at info@bitsgroup.co.uk or call 020 3011 1190.
