• Skip to primary navigation
  • Skip to main content

HRMorning

  • FREE RESOURCES
  • PREMIUM CONTENT
  • HR DEEP DIVES
  • PODCASTS
    • VOICES OF HR
    • WOMEN’S LEADERSHIP TODAY
  • LOGIN
  • SIGN UP FREE
  • Employment Law
  • Benefits
  • Recruiting
  • HR Technology
  • Payroll
  • Management
  • Women’s Leadership
  • More
    • Talent Management
    • Performance Management
    • Leadership & Strategy
    • Compensation
    • Policy & Procedures
    • Wellness
    • Staff Departure
    • HR Career & Self-Care
    • Health Care
    • Retirement Plans
  • HR Technology
  • Policy & Procedures

Why Cybersecurity in Remote Work Is Now an HR Priority

Roddy Bergeron
By: Roddy Bergeron, HR Expert Contributor
  • Share on

About the Author

Roddy Bergeron is the Cybersecurity Technical Fellow at Sherweb, the technology and service provider that equips nearly 8,000 MSPs with everything they need to run and scale their offerings. Bergeron's career has taken various paths including government auditing, nonprofit work, public/private partnerships with the State of Louisiana and helping to build an MSP by building their managed service, managed security, vCISO and compliance programs.

Show Less
Last Updated: June 30, 2025
8 minute engagement
Why Cybersecurity in Remote Work Is Now an HR Priority

For every company that has decided to bring its workforce back to the office (think: Amazon, Dell, JPMorgan and Zoom), another has doubled down on a hybrid or completely remote workplace model.

Companies in the latter group spend a lot of time considering what remote work will mean from a payroll and productivity perspective, but often overlook what it will require in terms of cybersecurity in remote work – and the critical role HR plays in managing it.

For them, onboarding, policy enforcement and employee device usage are no longer just operational concerns – they’re cybersecurity flashpoints. If HR doesn’t help shape how remote work policies are communicated, enforced and updated, they risk becoming the weakest link in the company’s security posture.

Consider, for instance, an employee who has decided to work from Costa Rica for the week. She’s connected to an open, unsecured Wi-Fi network. Unbeknownst to her, this simple act could expose her device – and by extension, the company’s entire network – to cyber threats. Such scenarios are not isolated incidents; in fact, 74% of data breaches involve a human element, often stemming from lapses like this.

This scenario exposes a critical gap in employees’ understanding of how their actions on company devices affect overall network security. HR can’t leave employees as the last line of defense against risks related to cybersecurity in remote work. Instead, HR must lead by embedding clear cybersecurity expectations into policies, training, and ongoing communications, partnering closely with managed service providers (MSPs) to ensure smooth transitions from traditional offices to remote and hybrid work models. This approach builds a culture where every employee knows their role in protecting the organization.

Even a single incident can reveal a major blind spot: Many employees don’t fully understand how their actions on company-connected devices can compromise broader systems. But they shouldn’t be expected to act as the final line of defense. HR leaders have a key role to play in building a culture of shared accountability, where cybersecurity in remote work isn’t treated as an IT issue alone. Partnering with managed service providers (MSPs) and IT teams, HR should help design and reinforce security protocols that reflect the realities of distributed workforces and reduce risk across the organization.

5 Ways to Strengthen Cybersecurity in Remote Work

Here’s an overview of five of the most important ways companies, their HR teams and MSPs can work together to secure evolving networks – ideally before going remote.

1. Introduce a Cybersecurity Plan Grounded in Real-World Threats

In the past, companies often adopted a reactive stance on cybersecurity in remote work,  addressing threats only after they materialized. However, with a dispersed workforce, the potential vulnerabilities companies are exposed to are too significant to deal with as they come, making a proactive approach necessary. Rather than “wait and see,” they should start with a comprehensive risk assessment to identify and address vulnerabilities inherent in home offices, co-working spaces and mobile setups.

While IT spearheads the technical aspects, HR should collaborate closely to:

  • Develop clear policies for cybersecurity in remote work
  • Ensure those policies are communicated effectively and followed by employees, and
  • Facilitate frequent and ongoing cybersecurity training to keep employees aware of evolving threats.

By embedding HR into the framework for cybersecurity in remote work, companies move beyond one-off training sessions and toward a sustained culture of accountability and cybersecurity awareness. As hybrid and remote work introduce security risks tied to behavior – like device sharing, poor password practices and unsecured networks – HR is critical to shaping expectations, enforcing protocols and building habits that protect company assets every day.

Planning for this shift should begin with a thorough risk assessment to identify vulnerabilities common to home offices, co-working spaces and mobile setups – from unintentional eavesdropping and unsecured devices to risky network access and browser-based workflows. Understanding these risks, and the potential business impact of a breach, allows organizations to put stronger protections and response procedures in place before an incident occurs.

2. Address AI-Driven Threats and Emerging Risks

Don’t overlook the growing threat posed by AI, automation and advanced reconnaissance. Even if your company isn’t using AI directly, you still need to be protected from it – and, ideally, by it.

AI has become a double-edged sword in cybersecurity. On one side, attackers are using it to scale their efforts, automate fraud and create social engineering tactics that are more personalized and harder to detect. On the other, defenders are racing to deploy AI tools that can strengthen threat detection, reduce response times and identify suspicious patterns that traditional systems might miss.

For HR, this means working with IT to ensure employees are aware of new, AI-powered risks, especially those that mimic legitimate messages or workflows. As the line between human and machine-generated threats continues to blur, awareness training needs to evolve just as quickly.

Cybercriminals are using AI tools, including ChatGPT-style bots, to generate highly personalized phishing messages that mimic the communication style of real employees – even CEOs. These scams often target HR and payroll teams directly. One common tactic: an email that appears to come from an employee, requesting a last-minute bank account update in the payroll system before the next pay cycle. You can imagine how quickly that can go wrong.

Another growing risk is the unintentional exposure of sensitive company information. Employees increasingly use public AI tools to summarize meetings, draft communications, or analyze internal reports – and in doing so, may unknowingly upload proprietary data. That content can then be referenced in unrelated prompts by external users, creating dangerous opportunities for data leakage.

Deepfake technology raises the stakes even further. With AI-driven voice cloning and increasingly realistic avatars, attackers can impersonate candidates, pass virtual interviews, and embed themselves inside your organization. These tactics are no longer theoretical – they’re happening now.

The same AI tools that create these risks, however, can help mitigate them. MSPs can support businesses by implementing continuous threat detection tools that monitor patterns and behaviors and deploy defensive AI to counter malicious activity in real time.

For HR, this means evolving how internal requests are validated. Secure, multi-channel verification processes should become standard practice – especially for payroll changes, access requests and hiring decisions. AI may be making fraud more convincing, but HR has the power to make it less effective.

3. Ensure Software Updates and Device Compliance

Don’t let your workforce skip critical security updates.

When employees are in the office, companies can schedule regular software updates, track which devices have been updated, and follow up in person if needed. But remote work reduces this control. Off-site employees are more likely to delay or forget updates, making their devices prime targets for cybercriminals who exploit outdated software vulnerabilities, one of the key challenges in cybersecurity in remote work.

Skipping updates increases the risk of malware infections and company-wide data breaches. Updates don’t just improve functionality – they include security patches that fix known vulnerabilities. Although updating software is a simple task, ignoring it can have major consequences.

Companies must create and enforce policies requiring employees to keep devices, applications and operating systems current. Regular reviews of device lifecycles are also critical, since unsupported devices no longer receive updates and become high-risk.

HR can play a vital role by ensuring that update compliance is embedded in Bring Your Own Device (BYOD) policies. Non-compliance should be addressed through regular audits or employee performance reviews, reinforcing that cybersecurity in remote work is a shared responsibility – not just IT’s job.

4. Establish a Backup Plan for Critical Data

All it takes is one compromised device for a cyberattacker to gain access to a company’s entire network – potentially resulting in millions of dollars in data loss.

Beyond cyberattacks, accidental deletions, hardware failures and other oversights can also cause significant data loss. That makes it critical for companies to safeguard their data and back it up more than once.

A widely adopted strategy is the 3-2-1 backup rule. This means:

  • Maintaining at least 3 copies of data
  • Stored on 2 different types of media
  • With 1 backup kept offsite 

Companies should ensure backups happen frequently and that these copies remain secure. There’s flexibility in how organizations apply this rule – what matters is that the process fits their needs and effectively protects against data loss.

For HR, supporting cybersecurity in remote work includes reinforcing policies around data protection and employee responsibility for safeguarding information, especially as remote devices become gateways to critical systems.

5. Involve Employees in Building a Security-First Culture

Don’t work around employees. Work with them, especially when it comes to cybersecurity in remote work.

Many companies try to prevent employee-created threats without involving employees in the process. At a minimum, teams should understand the threats the company faces so they can be the eyes and ears, reporting issues as soon as they arise.

Proactive awareness programs build a strong first line of defense. Every employee should be trained to:

  • Recognize phishing attempts
  • Understand basic secure network practices, such as disabling unnecessary device services and enabling firewalls, and
  • Follow clear policies on incident reporting, confidential information handling, software updates, and device usage – no matter where they work.

Holding employees accountable for learning and compliance drives program effectiveness. Some organizations measure this by running simulated phishing campaigns to test awareness and response.

Security awareness should be a tracked KPI – especially during onboarding and annual reviews. HR and IT must partner to ensure training sticks, measuring true readiness rather than box-ticking.

As hybrid and remote work expands, cybersecurity becomes increasingly critical. Companies need networks that withstand evolving risks, backed by the right tools and a workforce that’s both aware and engaged.

Security isn’t a perk of office life – it’s the cost of doing business anywhere. Remote or not, if you aren’t ready, the threat is already inside.

Filed under
  • HR Technology
  • Policy & Procedures
  • Share on

Get the HRMorning Newsletter

With HRMorning arriving in your inbox, you will never miss critical stories on labor laws, benefits, retention and onboarding strategies.

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Free Training & Resources

Webinars

Keep It Simple: How to Reduce Unnecessary Workplace Complexity

Provided by Paycom

White Papers

TriNet AI in HR eGuide 2026

White Papers

Your guide to navigating CFO benefits questions

Provided by Maven Clinic

EBOOK, White Papers

The Prevention Mandate: An Employer’s Framework for a Healthier Workforce

Provided by Personify Health

SPONSORED CONTENT

HR Technology

sponsored content
The Best AI Software for HR Automation

Courtesy of G-P

Talent Management

sponsored content
Powerful Employee Retention Strategies for 2025: How to Keep Your Best People

Courtesy of PEOPLEGURU

Benefits

Health Care

Wellness

sponsored content
Proven Results: 5 Ways Teladoc Health Chronic Condition Management Transforms HR Outcomes

Courtesy of TELADOC HEALTH

Further Reading

  • HR Technology
AI Risks: Is Your HR Department Aware and Prepared?

The digital landscape is evolving at a breakneck pace, with artificial intelligence (AI) poised to revolutionize various aspects of work. F...

  • HR Technology
How to Temper Employees’ Fear That AI Will Take Their Jobs | 2-Minute Video

Many employees fear that AI will eliminate their jobs. Or change their jobs. While change is very possible, elimination is less likely. ...

  • Policy & Procedures
Mitigate Risks at Company Holiday Parties: 9 Best Practices for HR

The holiday season is the perfect opportunity for companies to celebrate successes, strengthen bonds, and foster a sense of community among...

  • HR Technology
5 ways LMS software makes HR pros’ jobs easier 

HR pros find that learning management systems (LMS) software helps them develop their employees. And while LMS software comes with many ben...

  • HR Technology
  • Leadership & Strategy
The HR Credibility Gap: 7 Ways to Gain Trust with IT, Finance

HR’s influence at the top is growing, but outside the C-suite, trust is harder to earn. Research from Sapient Insights Group reveals a...

  • HR Technology
HR chatbots automate the boring administrative stuff so you can focus on empowering your team

Between juggling administrative tasks, employee inquiries and strategic company initiatives, HR is hard work. That’s why HR chatbots ...

Get the latest from HRMorning in your inbox PLUS immediately access 10 FREE HR guides.

I WANT MY FREE GUIDES
HR Morning Logo
  • Facebook
  • Linked In
  • ABOUT HRMORNING
  • ADVERTISE WITH US
  • WRITE FOR US
  • CONTACT
  • Employment Law
  • Benefits
  • Recruiting
  • Talent Management
  • Performance Management
  • HR Technology
  • Leadership & Strategy
  • Compensation
  • Policy & Procedures
  • Wellness
  • Staff Departure
  • HR Career & Self-Care
  • Health Care
  • Retirement Plans
  • DEI

HRMorning, part of the Rover Insights Network, provides the latest HR and employment law news for HR professionals in the trenches of small-to-medium-sized businesses. Rather than simply regurgitating the day's headlines, HRMorning delivers actionable insights, helping HR execs understand what HR trends mean to their business.

Powered By Rover Insights
Privacy Policy | Terms of Service
Copyright© 2026 Rover Insights
HRMorning Logo

WELCOME BACK!

Enter your username and password below to log in

Forget Your Username or Password?

Reset Password

Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.

Log In

Why do we need your credit card for a free trial?

We ask for your credit card to allow your subscription to continue should you decide to keep your membership beyond the free trial period.  This prevents any interruption of content access.

Your card will not be charged at any point during your 21 day free trial
and you may cancel at any time during your free trial.

During your free trial, you can cancel at any time with a single click on your “Account” page.  It’s that easy.