Back to all articles

Working From Home Securely: A Practical Checklist

A home network was never designed with the assumption that sensitive company files would flow through it every day. A few adjustments close most of the resulting gap.

An office network is generally built with security in mind from the start — managed firewalls, monitored access, IT staff watching for anomalies. A home network was never designed with that assumption, even though for many South African employees it now carries the same sensitive company traffic every single day. A few adjustments close most of the resulting gap.

Separate your work and personal digital life where you can

Where your employer provides a work laptop, keep it for work — resist the convenience of using it for personal browsing, streaming, or a child's homework. Each additional use case is another way something unrelated to work could compromise a device that also holds company data. If you're using a personal device for work by necessity, at minimum use a separate browser profile or user account for work tasks, so work logins and personal browsing history aren't mixed in the same session.

Secure the network itself

Your home router is now effectively an extension of your employer's office network, which makes the basics worth taking seriously: change the router's default admin password if you haven't already, keep its firmware updated, and use WPA3 (or WPA2 at minimum) encryption on your Wi-Fi rather than an open network. If your household has smart home devices — cameras, smart plugs, a smart TV — consider putting them on a separate guest network from the one your work devices use, so a compromised smart device can't reach your work laptop.

Video calls and screen sharing

Set video call links to require a passcode or waiting room where the platform allows it, to prevent uninvited join attempts. Before any screen share, close browser tabs and applications with sensitive personal or company information open — an easy thing to forget mid-meeting.

Physical security still counts

Working from a coffee shop or co-working space brings back the public Wi-Fi caution covered elsewhere on this site, plus a more mundane risk: a laptop screen visible to the table behind you, or a device left unattended while you order a coffee. Lock your screen automatically after a short idle period, and treat a company laptop with the same physical care you'd want a colleague to show it in the office.

Company tools, actually used

If your employer provides a VPN, password manager, or multi-factor authentication for company systems, the biggest single win is simply using them consistently rather than finding workarounds because they're mildly inconvenient. These tools are usually the product of a real security assessment on the employer's side — skipping them under time pressure undoes work that's already been done for you.

Reporting, without embarrassment

If you click something you shouldn't have, or suspect a work device has been compromised, report it to IT or your manager immediately rather than trying to quietly fix it yourself. The delay caused by embarrassment is often what turns a minor, containable incident into a larger one — most IT teams would far rather hear about a mistake early than discover it two weeks later.

The short version

None of this requires technical expertise — it's mostly about treating your home network and your work devices with the same seriousness an office building's IT department would, and using whatever tools your employer already provides instead of working around them.