From the Field: Your Workforce is Remote. Your Risk is Not 

Two professionals walking side by side through a modern data center corridor, surrounded by rows of server racks. Both are wearing ID badges and appear to be in discussion, suggesting collaboration or inspection in a tech or IT environment.
by Avery Quayle
3 MIN READ

For most organizations, remote work stopped being a temporary fix a long time ago. 

It’s just work now. People log in from home, coffee shops, hotel rooms. They use personal devices for work and work devices for personal tasks. The line between inside the network and outside it has blurred to the point where it barely exists anymore. 

Most organizations adapted operationally. Fewer adapted their security posture to match. 

What the perimeter used to look like 

Not long ago, securing your organization meant securing your building. Your data lived on servers in a room down the hall. Your employees worked on company-owned devices connected to a company-managed network. Your firewall sat at the edge and kept the outside world out. 

That model made sense then. It doesn’t reflect how work happens now. 

What it looks like today 

Your data lives in cloud applications. Your employees connect from a dozen different locations on a mix of managed and unmanaged devices. Your network perimeter, the one your security was built around, is effectively gone. 

What replaced it isn’t always clear. In many cases, it’s not much. 

The tools are the same. The policies are the same. The assumptions are the same. The threat landscape is not. 

Attackers know this. Targeting remote access points, personal devices, and poorly secured home networks is easier and more productive than breaching a hardened corporate perimeter. The path of least resistance shifted with the workforce. Security strategies haven’t always followed. 

Where the exposure lives 

The gaps we find most consistently in organizations with distributed workforces aren’t exotic. They’re predictable: 

  • Remote access without proper controls 
  • VPNs that haven’t been updated  
  • Remote desktop tools left exposed to the internet 
  • Access policies that were set up in a hurry in 2020 and never revisited 
  • Personal devices touching business systems 

An employee checks work email on a personal phone. Uses a personal laptop while their work machine is being repaired. Connects to a client system from a home network shared with a dozen other devices. Each of these is a potential entry point. 

Endpoints that aren’t being monitored. When someone is in the office, their device is on the corporate network. When they’re remote, they may be invisible to your security tools. If something goes wrong on that device, you might not know until the damage is done. 

The virtual desktop question 

One of the most effective responses to this problem is also one of the most underutilized in mid-sized organizations: virtual desktop infrastructure. 

The idea is straightforward. Instead of securing every endpoint individually, the work environment moves into a controlled, centrally managed space. Employees connect to a virtual desktop from whatever device they’re on. The endpoint becomes a window, not a storage location. The data never lives on the device. The session ends, and nothing sensitive goes home with them. 

For IT leaders, this closes a significant number of exposure points in one move. For business leaders this means:  

  • Simpler device management 
  • Lower endpoint security costs 
  • Easier onboarding 
  • More secure offboarding 

It’s not the right solution for every organization. But for organizations with a significant remote workforce and a growing list of unmanaged endpoints, it’s worth a serious conversation. 

The broader point 

Remote work didn’t create new risks. It redistributed them across a much larger surface area. 

The organizations navigating this well aren’t the ones trying to bolt security onto a distributed workforce after the fact. They’re the ones that have rethought what the perimeter means now and built their controls accordingly. 

Technology decisions are no longer IT decisions. They directly impact revenue, risk, and insurability. How you secure a distributed workforce is one of the places where that reality is hardest to ignore. 

Where to start 

If you’re not sure whether your security posture has kept pace with how your workforce operates today, the self-assessment from our first post is a good starting point. Pay particular attention to the endpoint and remote access controls. 

Download the self-assessment here

And if you’d like to pressure test your environment with someone who works through these issues every day, a 30-minute reality check with a member of our team is the can get you moving in the right direction. 

[Schedule a reality check] 

Your workforce is distributed. Your risk is too. 

The question is whether your security knows it. 

This is the fourth post in our Field Notes from the Front Lines series. Next up: Buying AI Does Not Create Value. Behavior Change Does.

Avery Quayle

Avery Quayle is Senior Director of Marketing at Micro Strategies, where she leads brand strategy, demand generation, digital marketing, and corporate communications across the company's full portfolio, spanning AI, automation, managed services, cybersecurity, business process, enterprise content management, and business continuity. With over 20 years of experience in technology and professional services marketing, she holds an MBA from DeSales University and is a recipient of the Marketing Achievement Award from the Association of Accounting Marketing.

© 2025 Micro Strategies Inc. All Rights Reserved