Remote and Hybrid Work: Closing the Human Risk Gap
Hybrid work is now the norm — and attackers follow employees home. The human risks of distributed work and how to manage them with training and controls.

The corporate perimeter did not dissolve in a breach. It dissolved in a calendar. According to Gallup's ongoing tracking, roughly half of remote-capable U.S. employees — 51% as of mid-2025 — work hybrid and another 27% work fully remote, figures that have barely moved since 2022. Return-to-office headlines notwithstanding, distributed work is not an experiment anymore. It is the operating model.
Security programs have mostly caught up on the technology side: VPNs gave way to zero-trust access, laptops got endpoint agents, cloud apps got single sign-on. The human side is where the gap remains. The Verizon 2026 Data Breach Investigations Report still puts the human element in 62% of breaches — and finds that social engineering aimed at mobile devices, where hybrid employees increasingly live, converts about 40% more often than email phishing. Attackers noticed that work left the building. Many awareness programs have not.
This guide covers what actually changes about human risk when work is distributed, the four gaps that drive most remote-work incidents, and a practical program for closing them.
Why the home office favors the attacker
Nothing about working from a kitchen table makes a person more gullible. What changes is the environment around each decision.
In an office, a suspicious invoice gets shown to the colleague at the next desk. A strange call from "IT" gets checked by walking to IT. That informal verification layer — security's oldest control — disappears over distance, and attackers deliberately exploit the gap: the urgent CEO text, the help-desk call that "just needs your MFA code," the deepfake voice on a hurried phone call. Isolation converts hesitation into compliance.
The channels shift, too. Distributed work runs on phones, and mobile screens truncate URLs, hide sender details, and blend work and personal notifications into one stream. Verizon's 2025 Mobile Security Index found 85% of organizations report mobile attacks increasing year over year; among those running smishing tests, 39% found that up to half of employees tapped the malicious link. The same report notes 93% of organizations see employees using generative AI on mobile devices, and 64% rank data leakage through those tools as a top mobile risk.
Finally, the boundary between corporate and personal simply blurs. Work happens on the family laptop, over the home router that still has its installation password, beside a personal inbox with none of the corporate mail filtering. Each of those is an entry point that no data center firewall ever sees.
The office was never just a place. It was a security control — a verification network of nearby colleagues — and hybrid work switched it off without a replacement.
The four human risk gaps of hybrid work
Most remote-work incidents trace back to one of four gaps. They make a useful audit checklist:
| Gap | What it looks like | Primary countermeasure |
|---|---|---|
| Unmanaged devices | Corporate data on personal laptops and phones with no enrollment, patching, or screen lock | Formal BYOD policy, MDM or app containers, posture checks at login |
| Unsanctioned tools | Personal cloud drives, messaging apps, and private AI accounts handling work data | Sanctioned alternatives, discovery controls, clear shadow IT and shadow AI policy |
| Insecure networks | Default-credential home routers, coffee-shop Wi-Fi, spoofed evil twin hotspots | VPN or zero-trust access, router hardening guidance, HTTPS-everywhere habits |
| Verification gaps | Payment changes, credential resets, and "urgent" requests approved without a second channel | Out-of-band verification rules, callback procedures, a culture where checking is rewarded |
The scale of the second gap is easy to underestimate. The Verizon 2026 DBIR found the share of employees using generative AI on corporate devices tripled from 15% to 45% in a year, much of it through personal accounts — and Netskope's 2026 cloud research found 30% of AI users at work rely only on personal accounts. Every one of those sessions moves data outside the controls the security team spent a decade building.
A practical program for securing hybrid work
The fix is not a return-to-office mandate; Gallup's data says distributed work is here to stay. It is a program that treats the distributed employee — device, network, tools, and judgment — as the new perimeter.
1. Write the policy down
Start with a telework and BYOD policy employees can actually follow: which devices may touch which data, required OS versions and screen locks, sanctioned tools and their alternatives, and what to do when something goes wrong. NIST SP 800-46 remains the reference framework for enterprise telework and BYOD security, and the UK NCSC's home working guidance is a concise, employee-friendly companion.
2. Make the secure path the easy path
People route around friction. If the sanctioned file-sharing tool is slower than a personal drive, the personal drive wins. Provide fast corporate alternatives for the tools employees actually reach for — storage, messaging, AI assistants — and pair discovery controls with amnesty rather than punishment when unsanctioned use surfaces.
3. Harden identity for a perimeterless world
With no network boundary, identity is the control point. Deploy phishing-resistant MFA — passkeys or hardware keys where possible — and number matching everywhere else, because remote workers are prime targets for MFA fatigue push-bombing. Route access through zero-trust or VPN gateways that check device posture, so a phished password on an unmanaged laptop is not enough.
4. Train for the channels attackers actually use
Annual email-phishing training does not prepare anyone for a smishing text, a QR code on a parking meter, a Teams message from a "vendor," or a voice clone of their CFO. Run short, frequent, scenario-based training and extend simulations beyond email to SMS, voice, QR, and collaboration channels — then coach the people who struggle rather than shaming them.
5. Replace the shoulder tap with process
The office's informal verification has to become explicit procedure: any request to change payment details, share credentials, buy gift cards, or bypass a control gets verified on a second, independently obtained channel — no matter how senior the requester or how urgent the tone. Write the callback numbers down before the incident, and make "I verified first" a praised behavior in front of the whole team.
6. Measure risk per person, not per office
Distributed teams fail unevenly: one employee reports every lure, another approves every push prompt at midnight. Aggregate signals — simulation results, reporting speed, training completion, risky-tool use — into a Human Risk Score so you can target coaching where the risk actually sits, prove trend lines to leadership, and stop treating a 500-person hybrid workforce as one undifferentiated audience.
The metric that matters
For a distributed workforce, the single most telling number is the reporting rate: what share of employees flag a suspicious message, and how fast. Clicks can be reduced by filters; reports can only come from people. A remote employee who reports in ninety seconds gives your SOC the early warning a colleague's raised eyebrow used to provide — which is the entire human risk gap of hybrid work, closed by other means.
Remote and hybrid work removed the building, the badge gate, and the shoulder tap. It did not remove the human judgment those things quietly supported. Rebuild that support deliberately — policy, easy secure paths, hardened identity, channel-realistic training, explicit verification, and per-person measurement — and a distributed workforce can be measurably safer than the office ever was.
Frequently asked questions
Is remote work actually a security risk?
Distributed work does not make employees careless, but it removes the informal safety net of the office — the colleague you'd show a suspicious email to, the IT desk down the hall — and moves work onto home networks, personal devices, and mobile channels where controls are thinner. Verizon's 2026 DBIR found social engineering delivered to mobile devices converts about 40% more often than email phishing, and 85% of organizations in Verizon's Mobile Security Index report mobile attacks are increasing. The risk is manageable, but only with controls and training designed for how people actually work now.
What are the biggest human risks in a hybrid workforce?
Four gaps account for most incidents: personal and unmanaged devices handling corporate data (BYOD without enrollment or posture checks); unsanctioned tools, from shadow IT file sharing to personal AI accounts; insecure networks, including home routers with default credentials and spoofed public hotspots; and verification gaps — remote employees approving requests over email, chat, or a phone call that an office worker would have checked with a quick shoulder tap.
How should security awareness training change for remote employees?
Train on the channels remote workers are actually attacked through, not just email: SMS phishing, voice calls, QR codes, collaboration-app messages, and MFA push prompts. Short, frequent, scenario-based lessons outperform annual marathons, and simulations should reach mobile and chat channels too. Pair training with a no-blame reporting culture — a distributed team that reports fast is the closest thing you have to a colleague noticing something is off.
Does BYOD make phishing worse?
It widens the blast radius. On a personal device, work email sits beside personal SMS, social apps, and browsers with saved passwords, and corporate protections like URL filtering often are not present. A phished personal device can expose cached work sessions and app tokens even if the corporate laptop stays clean. If you allow BYOD, formalize it: enrollment or app-level containers, minimum OS versions, screen lock, and a documented policy per NIST SP 800-46 — plus training that covers the personal side of the device.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo