Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

Remote Work Security Basics for a Company With No Internal IT

Cybersecurity
Last updated: August 14, 2026

A remote work security policy for a small business without IT staff comes down to five things, MFA everywhere, a password manager, minimum device requirements, secured home Wi-Fi, and a plain list of who to call when something looks wrong.

None of those five things require hiring anyone. That’s the part owners get wrong most often. They hear “security policy” and picture a security officer, a line item they can’t afford. Three of the five are settings. Flip a switch. One is a four-dollar-a-month license. The last one is a sentence on a printed page taped inside a supply closet. Nothing more.

Small businesses that skip a written policy aren’t usually skipping the technology. Most already run Microsoft 365 or Google Workspace, both of which ship the tools this requires at no extra cost. What they skip is writing down which settings apply to which device, and who a remote employee calls first if a laptop goes missing at a coffee shop. That gap is the actual policy failure, not the tooling.

VJNetworks walks small companies through this exact list during cybersecurity reviews across the Tri-State area, usually right after an insurance renewal form asks a question nobody in the office can answer with certainty. This is that list, in the order it should get tackled.

Small business owner reading a printed remote work security policy document before sharing it with the team

What Changes When Nobody’s Watching the Network

A company with an internal IT department has someone who notices. A failed login at 2 a.m. A laptop gone quiet on patches for six weeks. Small companies without that role don’t lose the risk. They lose the person who would have caught it. Same risk. No backstop. A dedicated IT department would flag the failed login within minutes, match it against a login history, and lock the account before a second attempt landed, and that entire sequence simply doesn’t happen on its own inside a five-person company running email through a phone.

The numbers back that up more than most owners expect. Verizon’s 2026 Data Breach Investigations Report put a number on all of it. Ransomware victims skewed small, about 96 percent were small or midsize businesses in cases where the report could confirm organization size. Credential abuse, stolen or reused logins, was the second most common way attackers got into SMB breaches specifically, at 13 percent, trailing only unpatched software vulnerabilities. And the human element overall, someone clicking, someone reusing a password, someone getting socially engineered, showed up in 62 percent of breaches across the full dataset, up from 60 percent the year before.

Not because small companies are careless.

That’s the entire argument for writing a policy down instead of assuming everyone already knows the basics. Nobody does, evenly, across a team. And “we’re pretty careful here” isn’t a control an insurer, a client, or a court will accept after the fact.

What a Written Policy Needs to Cover, in Order

Five categories, roughly in the order they matter for a company starting from zero.

MFA first. It closes the single most common way in. Password management second, since MFA doesn’t help much if the underlying password is “Company2024.” Device requirements third, covering what a laptop or phone needs before it touches company email. Home network hygiene fourth. Incident reporting last, the one piece that has nothing to do with software and everything to do with which specific person owns responding when something looks wrong.

Skip the order and most businesses end up buying a tool for whichever category felt most urgent that week, usually MFA, and never circling back to the rest. A policy written in sequence forces the conversation to actually finish.

Two colleagues reviewing a printed device access checklist for company and personal devices

Company Laptop or Personal Phone? Setting the Access Tiers

NIST Special Publication 800-46, the federal guide to telework and BYOD security, recommends tiering access by device type rather than treating every remote connection the same. Not every device is equal. Company-issued laptops get the most access. Personal computers get a limited set of resources. Personal phones get one or two low-risk items, usually just webmail. Less control over the device means less trust in it. That’s the whole rule. No exceptions.

Device TypeWhat It Should AccessMinimum Requirement
Company-issued laptopFull access, including internal files and line-of-business appsMFA, disk encryption, automatic updates
Personal laptop or desktop (approved BYOD)Email, shared drive, calendarMFA, screen lock, current OS patches
Personal phone or tabletWebmail and calendar onlyMFA, passcode or biometric lock
Any device, once someone leavesNothingRemote wipe of company data, same day

That bottom row is the one most policies forget to write down until the week they need it.

Multi-Factor Authentication Is the One Line Item That Matters Most

Both Microsoft 365 and Google Workspace can turn this on without a purchase order. Microsoft 365 for Business includes Microsoft Entra ID Free, and Microsoft’s own documentation confirms MFA is enabled by default for the whole tenant through Security Defaults. Someone just has to check the setting hasn’t been switched off. One checkbox. Nothing else.

Google Workspace works a little differently. 2-Step Verification exists on every plan, and an admin can enforce it organization-wide for the whole team from the standard admin console. Google’s own guidance states that 2-Step Verification can cut account takeover by as much as 50 percent, and specifically recommends against SMS codes as the second factor, since SMS is vulnerable to carrier-level attacks. SMS is weaker. Skip it. An authenticator app or a security key beats a text message every time.

Not all MFA is equal. Push notifications and SMS are phishable. App-based codes are better. A hardware key is better still. Not complicated. VJNetworks covered why MFA alone isn’t always enough in a separate piece, and for remote work specifically, turning it on everywhere is still the floor, not the ceiling.

Hand holding a physical multi-factor authentication security key near a keyboard

Passwords, Passphrases, and the One Tool We Recommend

CISA’s password guidance for small businesses is specific. Sixteen characters. Minimum. Either a mixed-character password or a passphrase of five to seven unrelated words, generated and stored in a password manager rather than memorized. CISA’s own guidance on requiring strong passwords lays out exactly that standard, and none of it requires hiring a dedicated security person to implement, which is the whole point for a company this size.

BitWarden is our recommended system. Free for individual use, with a Teams plan that runs about four dollars per user monthly and centralizes admin control across the whole staff. VJNetworks covered the fuller buying criteria in a separate post on password managers for small business teams; the short version for remote work is the same tool, just non-negotiable for anyone connecting from home.

Reused passwords are the quiet failure mode here. One password. Five accounts. One leaked credential from an unrelated breach, and all five accounts are exposed the same afternoon. A password manager doesn’t just make strong passwords easier. It makes password reuse pointless, because there’s no longer a reason to reuse one.

The Home Router Nobody Thinks to Check

NIST’s guide for teleworkers, SP 800-114 Revision 1, gets specific about home networks in a way most general security guidance skips, right down to the encryption preference order, most secure to least.

  • WPA2 with AES, the safest widely available option.
  • WPA with AES, acceptable but dated.
  • WPA with TKIP, a distant third choice.
  • WEP. Not acceptable anywhere, on any router, at this point.

The router hardening steps below matter just as much as which encryption standard runs on top of them.

  • Change the router’s default admin password. Factory logins are searchable by make and model.
  • Rename the network so it doesn’t broadcast the router brand or a home address.
  • Keep firmware current. Most modern routers do this automatically once the setting is turned on.
  • Put visitors and smart-home devices on the guest network, never the same one as a work laptop.

Patch cadence matters more than most owners assume. Firmware matters. A lot. NIST’s own guidance for routers and firewall appliances calls for checking for updates automatically, daily or weekly, or manually at least once a month if the device has no auto-update option. A router running three-year-old firmware isn’t a minor gap. It’s the front door.

Who Gets the Call When Something Looks Wrong

This piece isn’t a purchase. It’s a decision nobody’s made yet. Without an IT department, “call IT security” isn’t a real instruction. Somebody specific has to be that person. The owner, an office manager, or the outsourced provider handling the account.

NIST’s Cybersecurity Framework 2.0 Small Business Quick-Start Guide reduces this to two lists a business can write in an afternoon, one naming every individual who’s actually part of the response and reachable by phone, not “the IT team,” an actual name, and the other spelling out the communications and legal obligations tied to whatever laws, contracts, or regulations genuinely apply to that specific business. Neither list requires a security background to compile.

There’s a financial reason to get this in writing beyond the obvious one. Cyber insurers increasingly build a “failure to maintain security” exclusion into their policies. It’s fine print, but it matters, since it’s the clause that lets them deny a claim after the fact if the standards a business publicly claimed to follow turn out to have never actually been documented, communicated to staff, or enforced in any consistent way. A verbal “we’re careful” doesn’t survive a claims review. A one-page policy with a signed acknowledgment does.

Invoke the plan even when it’s probably a false alarm. That instruction alone prevents the worst outcome in this category, and it isn’t the incident itself. It’s the two-day gap where someone suspected something and said nothing because they weren’t sure who to tell.

Office manager writing an incident contact list by hand next to an office phone

Where to Start This Week vs This Month

Sequencing beats a big-bang rollout, especially with no dedicated staff to manage a large project. Here’s a realistic order. Cheapest and fastest first.

TimelineActionCost
This weekConfirm MFA is on for email and any financial or payroll logins$0
This weekWrite the “who to call” list and post it somewhere visible$0
This monthRoll out a password manager team-wideAbout $4 per user monthly
This monthCheck every remote employee’s home router against the four-item list above$0, unless hardware needs replacing
This monthPut the device tiers and offboarding step in writing, get signatures$0

Worth a second look. Four of the five rows cost nothing. This isn’t a budget problem for most small businesses. It’s a nobody-owns-it problem, and a written policy is what fixes that specifically.

Questions Owners Ask Before Writing Any of This Down

Do we need a full written policy, or is a checklist enough?
A one-page checklist with signatures counts as a written policy. What matters to an insurer or a court isn’t length. It’s that the standard existed in writing and employees acknowledged it before an incident, not after.
Who takes the call if an employee’s laptop gets stolen at a coffee shop?
Whoever’s named on the list. It has to be one specific person, not a department that doesn’t exist. Most small businesses name the owner or office manager for the first call, then loop in an outsourced IT provider for the technical response.
What’s the realistic cost to do this right for a ten-person company?
Under $500 a year in most cases. A team password manager runs roughly $480 annually for ten seats, and MFA, device tiers, and the incident-response list cost nothing beyond the time it takes to write them down.
MFA is already on for email. Does that cover us?
No, and this is the gap that trips up most companies. Financial software, payroll, and cloud file storage often need MFA turned on separately, account by account, since enabling it on email doesn’t cascade to every other login the business uses.
How often does the policy actually need updating?
Once a year at minimum, or any time a new tool gets added to the business. A policy that still references software the company stopped using two years ago reads as unmaintained to an insurer, which defeats the purpose of having one.

Not a hire. None of this requires one. It requires a decision to write five things down that most companies already half-know and never formalize. VJNetworks covers the deeper setup side of remote and hybrid work, VPN configuration, endpoint management, the technical build-out, as part of managed IT services for companies across Rockland, Westchester, and Bergen who’d rather have someone else own this list.

Not Sure Your Remote Team Is Actually Covered?

A free assessment looks at your current MFA coverage, device setup, and remote access paths before recommending anything. No strings attached, no pushy follow-up call.

Get Your Free IT Assessment →

Or call (845) 440-5000