Remote Work Security Checklist Template

Remote staff work on networks you don’t run, in rooms you can’t see, on laptops that travel. The incident usually starts small: a router on its factory login, a reused password, a laptop left on a train and reported three days later.

This free remote work security checklist is for IT and security teams and the managers of remote and hybrid staff. It runs when someone starts working away from the office, then yearly as an attestation. It covers the managed, encrypted device, MFA and conditional access, the home router and public Wi-Fi, private screens and paper, and how to report a phishing email or a lost laptop. The output is a signed attestation per employee, with every exception approved and dated.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Setting Up the Desk Is Not the Same as Securing the Work

NIST’s telework guide, SP 800-46 Rev. 2, starts from two assumptions worth borrowing: networks outside the office contain hostile threats, and remote devices will be lost or stolen. Its answer is encryption, strong authentication and the least access for the least-controlled devices. The UK National Cyber Security Centre’s home working guidance adds the human side: staff must know who to call the moment a device goes missing.

A fully compliant laptop still leaks data if its owner prints customer files on a family printer or joins hotel Wi-Fi without the VPN. This checklist covers the person’s side and records that they understood it.

Home office setup

Is the workspace fit to work in?

Covers: chair, screen height, lighting, connection speed.

Owner: the employee, with HR.

Output: a workstation assessment.

Device enrolment

Is the device under management?

Covers: enrolment profiles, compliance policies, ownership type.

Owner: IT.

Output: a managed, compliant device.

Remote work security

Is the person working securely?

Covers: sign-in, home network, privacy, paper, travel, reporting.

Owner: IT security, with the employee.

Output: a yearly attestation per person.

Ergonomics and equipment stay in the Home Office Setup Checklist, and getting a device enrolled in the first place belongs to the MDM Enrollment Checklist. If MFA is not yet enforced across the organisation, run the MFA Rollout Checklist first; this page only confirms each person is covered.

What the Remote Work Security Checklist Covers

Seven phases run per employee at the start of remote or hybrid working, then yearly as a re-attestation. Scope answers on work devices, access tier, paper and travel decide which tasks appear, and the security approver signs off travel and the attestation.

Phase 1

Phase 1: Scope, People & Access Tier

The people picked on the first task are assigned the later tasks. The exceptions review appears only on an annual re-attestation.

  • Record the employee, working pattern, run type and owners — fully remote or hybrid, initial setup or annual re-attestation, plus the IT contact and security approver
  • Answer the four scope questions — which devices are used for work, the access tier, whether paper is handled at home and whether work abroad is planned
  • Match the access tier to the role — elevated for administrators, payment approvers and anyone handling special category or bulk personal data
  • Send the remote working security policy and record the acknowledgement — the version number is kept, so a policy change shows who has not yet read it
  • Review last year’s exceptions and incidents for this employee — an exception that was due to expire is closed or approved again, never left to roll over
Phase 2

Phase 2: Managed, Encrypted Device

Assigned to the IT contact. Each check is read from the management console, not taken on the employee’s word.

  • Confirm the work device is enrolled and reported as compliant — a device missing from the console has no policy, no remote lock and no wipe
  • Check full-disk encryption is on and the recovery key is held centrally — BitLocker or FileVault, with the key in the directory or MDM, not on a note in the laptop bag
  • Check critical and high-risk updates land within 14 days — the Cyber Essentials rule for operating systems, applications and firmware, and a sensible default elsewhere
  • Confirm a short screen-lock timeout and no local admin rights — five minutes idle is a common default to tune
  • Confirm endpoint protection and the device firewall are on and reporting — a home router you do not manage is not your firewall
  • Block removable media or allow only approved, encrypted drives — USB sticks are easily lost and can carry malware in both directions
Phase 3

Phase 3: Sign-in & Remote Access

Phishing-resistant sign-in appears only for Elevated access, and the personal-device task only when a personal device is used for work.

  • Confirm MFA is registered on every work account — an authenticator app or passkey, with SMS only where nothing else works
  • Issue phishing-resistant sign-in for elevated access — a passkey or hardware security key, so a convincing fake login page cannot capture the second factor
  • Test that conditional access refuses an unmanaged device — sign in from a personal browser and expect email and files to be blocked or limited
  • Confirm how the employee reaches internal systems — VPN or zero-trust access only, with no remote desktop port open to the internet
  • Set up the company password manager and remove reused passwords — a work password used on a breached personal site is a common way in
  • Limit personal devices to protected work apps or a work profile — the organisation can then remove work data without seeing or touching personal photos and messages
Phase 4

Phase 4: Home Network & Public Wi-Fi

Assigned to the employee, with a short guide from IT. A router the organisation did not supply is the employee’s, so these are habits, not settings IT can enforce.

  • Change the router’s default admin password and Wi-Fi key — the label on the back is the first thing anyone guesses
  • Use WPA3, or WPA2 where the router cannot do WPA3, and turn off WPS — and never leave the network open or on WEP
  • Update the router firmware and replace a router that no longer gets updates — ISP-supplied routers usually update themselves; check that yours does
  • Put smart-home devices and visitors on the guest network — if the router supports one, so a cheap camera cannot reach the work laptop
  • Follow the public Wi-Fi rule — VPN on before anything else, or tether to a phone hotspot, and no admin work on hotel or coffee shop networks
Phase 5

Phase 5: Screens, Calls & Paper

The privacy filter appears only for Elevated access, and the paper tasks only when paper is handled at home.

  • Face the screen away from windows and shared rooms — and lock it on stepping away; household members and visitors are not cleared to see work data
  • Fit a privacy filter to the laptop screen — elevated access is exactly the data a fellow passenger should not read over a shoulder
  • Take confidential calls where they cannot be overheard — headphones on, door closed, and never on speaker in a shared space
  • Agree what may be printed at home and on which printer — personal data and confidential files only where the policy allows, never on a shared family printer
  • Lock paper away and shred it with a cross-cut shredder — never household recycling; originals go back to the office instead
Phase 6

Phase 6: Phishing, Lost Devices & Travel

The travel tasks appear only when work abroad is planned, and the checklist halts until the security approver records Approved or Not approved.

  • Complete phishing awareness training and the latest simulation — remote staff cannot lean over and ask a colleague whether an email looks right
  • Show the employee how to report a suspicious email in one click — and say plainly that reporting an early mistake is never punished
  • Save the lost or stolen device contact in the employee’s phone — report within the hour so IT can lock the device, and the data protection team can assess the loss
  • Record the countries and dates of planned work abroad — holidays with a work laptop count as work abroad
  • Approve or refuse working abroad — security approver records Approved or Not approved after HR has checked tax and right-to-work questions
  • Prepare the device and sign-in rules for the trip — a clean loaner for high-risk destinations, and location exceptions in conditional access for the approved dates only
Phase 7

Phase 7: Attestation & Sign-off

The security approver picked in Phase 1 signs off, and the checklist halts until they record a decision.

  • Employee attests to each control in one table — in place or not, with a comment wherever the answer is no
  • Record every control that cannot be met as an exception — with the reason, a compensating control and an expiry date
  • Security approver signs off the attestation and exceptions — Approved or Not approved, with a reason the employee can read
  • Set the next attestation date — twelve months is a common default; bring it forward after a lost device, a move or a change of role
  • Attach the evidence and close the run — compliance report, training record and policy acknowledgement on the tasks that produced them

Company Device or Personal Device: Tiered Access

NIST SP 800-46 recommends tiered remote access: devices you control get the most access, personal computers a limited set, and personal phones perhaps only webmail. The checklist’s scope questions follow that idea. Treat the table as a starting point for your own policy.

ControlCompany-managed devicePersonal device (BYOD)Evidence for the attestation
What it can reachBusiness apps, files and internal systems by roleEmail, chat and files inside protected apps; no admin consolesConditional access policy and a test sign-in
EncryptionFull-disk, with the recovery key held centrallyDevice passcode, plus app-level encryption of work dataCompliance report
UpdatesEnforced, critical fixes within 14 daysMinimum OS version checked at sign-inCompliance report
If it is lostRemote lock, then full wipe once approvedSelective wipe of work data onlyLost-device report and wipe status
What IT can seeThe whole managed deviceWork apps or the work profile, not personal photos, messages or browsingPrivacy notice given to the employee
Elevated accessAllowed, with phishing-resistant sign-inNot allowedAccess tier on the first task

Three facts to check against your own position. NIST SP 800-46 Rev. 2, from July 2016, is still the final version; a Rev. 3 pre-draft opened for comment in 2020 and had not progressed by October 2026. Cyber Essentials v3.3, from April 2026, puts corporate and personal devices used for remote work in scope, but not a home router the organisation did not supply, so the device firewall matters. And Article 32 of the UK and EU GDPR names encryption as a security measure. A personal data breach must be reported within 72 hours unless it is unlikely to put people at risk, and encryption is the easiest way to show that it is not.

Why Run Remote Work Security in CheckFlow?

1

One attestation per person, every year

A yearly recurring schedule reopens the checklist as a re-attestation, and dynamic due dates count each phase from the start. Last year’s exceptions table is in front of the approver this year.

2

Tasks that match the person’s risk

Dropdown answers in Phase 1 drive conditional logic. A hybrid employee with a company laptop skips the personal-device and trip tasks, while an administrator who works abroad gets the security key, privacy filter and travel approval.

3

Evidence an auditor can follow

Compliance reports and training records attach to their tasks, and the activity trail shows who confirmed each control and when. Template versioning keeps a record each time the policy changes.

Security works best from day one. CheckFlow’s remote employee onboarding software can open this checklist alongside a new starter’s onboarding, so the device, MFA and policy acknowledgement are done before the first login from home.

Phishing training belongs in the Security Awareness Training Checklist. When the person leaves, the Remote Employee Offboarding Checklist undoes what this one set up, from device return to removing work data from a personal phone.

Frequently Asked Questions

What should a remote work security checklist include?

+

A managed, encrypted and patched device; MFA and conditional access that refuses unmanaged devices; a defined route into internal systems; home router hygiene and a public Wi-Fi rule; private screens, calls and paper; phishing awareness and a way to report a lost device; approval before working abroad; and a signed attestation with exceptions dated.

Do remote workers still need a VPN?

+

For anything still on an internal network, yes, or a zero-trust access service that does the same job per application. For cloud email and files, the stronger control is conditional access: MFA plus a check that the device is managed and compliant. On public Wi-Fi, a VPN still protects traffic an app might send in the clear.

How do I secure my home router for remote work?

+

Change the default admin password and the Wi-Fi key on the label, use WPA3 or at least WPA2, turn off WPS, keep the firmware updated and replace a router that no longer gets updates. Put smart-home gadgets on a guest network. Because the router usually belongs to the employee, the work device needs its own firewall too.

Can employees use personal devices for remote work securely?

+

Yes, with less access. Keep work data inside protected apps or an Android work profile so it can be removed without touching personal content, check a minimum OS version at sign-in, and keep admin and bulk-data access on company devices. Tell employees what the organisation can and cannot see. Cyber Essentials counts these devices as in scope.

What should an employee do if a work laptop is lost or stolen?

+

Report it to IT at once, using a number saved in their phone, and report a theft to the police. IT locks the device and revokes its sessions, and the data protection lead decides whether it is a reportable breach. That decision runs on a 72-hour GDPR clock, and confirmed encryption is the strongest evidence that nobody is at risk.

Does working abroad need security approval?

+

It should. HR checks tax and right-to-work questions, while security checks the destination, the device and the sign-in rules. UK GDPR transfer rules apply when personal data goes to a separate organisation, so an employee logging in from abroad is not usually a restricted transfer, but the security duty still applies.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Secure the Person, Not Just the Laptop

Free trial — no credit card required.