# Remote Work Security: VPN, Wi-Fi, Working From Home and Mobile Device Risks

**URL:** https://securesys.com.tr/en/learning/end-user-security/remote-work-security

![Remote Work Security: VPN, Wi-Fi, Working From Home and Mobile Device Risks](/images/bilgi-merkezi/covers/cover-sonkullanici-09.webp)

Remote working, hybrid working and mobile working models are no longer the exception but a permanent part of the corporate way of doing business. Employees can access corporate systems outside the office from home, from a hotel, from an airport, from the customer's location or over a mobile connection.

**While this flexibility provides important advantages it also creates a new attack surface.**

Inside the office the user is generally behind many controls such as the corporate firewall, NAC, network segmentation, centralized monitoring and physical security. However, when the user works remotely some of these security layers may not be directly in play.

**For this reason the modern Remote Work Security approach cannot be handled only at the level of:**

**"Open the VPN and connect."**

this level.

Today secure remote access;

**Identity Security, Endpoint Security, Device Compliance, VPN, ZTNA, Conditional Access, MFA, DLP, Secure Web Access, Cloud Security and SOC Monitoring**

requires these layers to work together.

The fundamental principle is this:

**The user being outside the office does not mean that security should be reduced; the security policy must work independently of location.**

### What Is Remote Work Security?

Remote work security is the body of technical and organizational controls that provides for employees to access corporate applications, data and systems safely from outside the office.

Within the scope of Remote Work Security:

VPN Security,

Secure Remote Access,

ZTNA,

MFA,

Device Compliance,

BYOD,

MDM/UEM,

Public Wi-Fi Security,

Endpoint Security,

DLP,

SASE,

SSE

many components such as these are evaluated.

The aim is not only to encrypt the connection.

The real aim is:

**to provide for the right user, with a secure device, under appropriate conditions, to access only the resource they are authorized for.**

### What Is Work From Home Security?

Work From Home Security is the management of the cyber risks that users working from home can face while accessing corporate systems.

The home environment is generally not as controlled as the corporate network.

The user can use a personal router.

There can be family members' devices on the same network.

The router firmware may not be up to date.

The Wi-Fi password can be weak.

For this reason home network security is a part of the remote work risk model.

### What Is a VPN?

**A VPN, that is, a Virtual Private Network, is the technology that creates an encrypted tunnel between the user device and the corporate network or gateway.**

Thanks to a VPN traffic passing over a public network can be protected with cryptographic protection.

This is one of the fundamental methods used for many years especially for remote access.

However, the existence of a VPN does not on its own mean secure remote working.

### Why Is VPN Security Important?

A VPN can provide the user with access to the corporate network.

If the attacker obtains VPN credentials an important risk can arise for the organization.

For this reason modern VPN Security:

**Strong Authentication + MFA + Device Control + Least Privilege + Monitoring**

should be supported with these.

Giving VPN access only with a username and password can be insufficient for many environments.

### Does Using a VPN Make Everything Safe?

No.

A VPN protects the connection but does not guarantee that the endpoint is safe.

For example if there is an infostealer or malware on the user laptop, even if the VPN tunnel is encrypted the attacker can access the data on the endpoint.

Therefore:

#### Secure Connection ≠ Secure Endpoint

this principle is important.

### What Is a Full Tunnel VPN?

A Full Tunnel VPN is the large part of the user's internet traffic being directed to the corporate security infrastructure over the VPN.

This structure can provide centralized web filtering and monitoring.

However, it can create bandwidth and performance effects.

### What Is a Split Tunnel VPN?

Split Tunnel is the model in which only particular corporate traffic is sent to the VPN and internet traffic goes out directly over the local connection.

It can provide a performance advantage.

However, the organization can lose visibility over some web traffic.

For this reason the Split Tunnel decision should be made by taking the security architecture and business requirements into account.

### What Is the Difference Between VPN and ZTNA?

**ZTNA, that is, Zero Trust Network Access, aims to provide more granular access than the traditional VPN approach.**

While a VPN in most cases takes the user inside at the network level, ZTNA can provide for the user to access only a particular application or resource.

ZTNA evaluates the following questions together:

Who is connecting?

From which device are they coming?

Is the device compliant?

Which application do they want to access?

What is the risk level?

For this reason ZTNA is becoming increasingly more important in modern Secure Remote Access architectures.

### What Is ZTNA?

Zero Trust Network Access is the security approach that aims to provide application-level access instead of giving the user network presence.

The fundamental principle is expressed as:

#### Never Trust, Always Verify

this.

However, in practice the more correct interpretation is:

**Verify every access request through identity, device and context.**

in this way.

### How Is Zero Trust Applied in Remote Working?

When a remote user tries to access a corporate application not only the password is checked.

At the same time:

the MFA state,

device compliance,

EDR health,

location,

risk level,

application sensitivity

can be evaluated.

This information can be included in Conditional Access or ZTNA policies.

### What Is Conditional Access?

Conditional Access is the access decision being evaluated together with different security signals beyond the user identity.

For example:

Known User

Managed Device

Low Risk

↓

Access Allowed

In another scenario:

Known User

Unmanaged Device

High Risk

↓

Access Blocked

This structure is extremely valuable for remote work security.

### What Is Device Compliance?

Device Compliance shows whether the device conforms to the security requirements determined by the organization.

For example for a compliant device:

EDR active,

disk encryption on,

operating system up to date,

screen lock active,

no root/jailbreak

conditions such as these can be required.

This control is important especially for remote access.

### What Is an Unmanaged Device?

An Unmanaged Device is a device that is not managed by the organization's endpoint management or security control system.

This device can be a personal laptop or an external contractor device.

On an unmanaged device:

the patch level,

antivirus,

disk encryption,

malware status

may not be known.

For this reason access can be limited for sensitive resources.

### What Is BYOD?

BYOD:

#### Bring Your Own Device

is employees using their own personal devices for work purposes.

BYOD can provide a productivity advantage.

However:

the separation of corporate data and personal data,

device security,

privacy,

offboarding,

data deletion

it creates risks such as these.

### How Is BYOD Security Provided?

In a BYOD environment the organization may not want to manage the whole device.

For this reason containerization, MAM or application-level controls can be used.

For example corporate data can be kept only inside a managed business application.

The aim is to provide a balance between personal privacy and corporate security.

### What Is MDM?

MDM:

#### Mobile Device Management

provides for mobile devices to be managed with centralized security policies.

Through MDM:

PIN requirement,

encryption,

remote wipe,

application policy,

device compliance

controls such as these can be applied.

### What Is MAM?

MAM:

#### Mobile Application Management

focuses on policy being applied on corporate applications and data instead of managing the whole device.

It is especially valuable for BYOD environments.

For example data inside a corporate application being copy-pasted to a personal application can be prevented.

### What Is UEM?

UEM:

#### Unified Endpoint Management

is the broader management approach that provides for different endpoint types such as laptops, desktops, smartphones and tablets to be managed centrally.

As the remote workforce grows UEM gains importance in terms of the central management of the security posture.

### Why Is Mobile Device Security Important?

On a smartphone and tablet:

corporate e-mail,

the MFA application,

cloud files,

messaging applications,

business apps

can be found.

Therefore when a mobile device is lost it is not only a phone that has been lost.

Corporate identity and data can also come under risk.

### What Should Happen If a Mobile Device Is Lost?

According to the organization policy the device can be subjected to:

remote lock,

remote wipe,

session revoke,

device revoke

these operations.

In addition the user authentication methods should be checked.

Especially if the MFA application is on the same phone identity security should be evaluated separately.

### Why Is a Rooted or Jailbroken Device Risky?

Root or jailbreak can cause the operating system security restrictions to be removed.

This situation can make it easier for malicious applications to obtain broader privileges.

For this reason a Conditional Access policy can evaluate rooted/jailbroken devices as non-compliant.

### Is Public Wi-Fi Safe?

Public Wi-Fi is not completely and automatically unsafe but it is risky.

On airport, café or hotel networks:

the network operator may not be known,

there can be a fake access point,

there can be untrusted users on the same network.

For this reason when public Wi-Fi is used a secure connection and endpoint security are important.

### What Is an Evil Twin?

An Evil Twin is a fake access point that imitates the name of a legitimate Wi-Fi network.

For example the user can see:

Hotel_WiFi

and

Hotel_WiFi_Free

similar networks such as these.

The attacker may have created the second network.

When the user connects to the fake access point the traffic can pass over attacker-controlled infrastructure.

### What Is a Rogue Access Point?

A Rogue Access Point is a wireless access point that is not approved by the organization.

This device may have been set up by an attacker or an employee may have created an unauthorized hotspot with their own device.

In both cases the security policy can be bypassed.

### What Is Captive Portal Phishing?

On public Wi-Fi connections a captive portal can ask the user to carry out a login or terms acceptance over the browser.

An attacker with a fake captive portal can try to collect credentials or personal information.

For this reason the user should not use their corporate password on a public Wi-Fi portal.

### Are Public Wi-Fi + VPN Safe?

A VPN provides traffic encryption and can significantly reduce the risks on a public network.

However, a VPN does not automatically solve:

a malware infected endpoint,

a phishing attack,

a fake login page

these.

For this reason a VPN is an important control but is not sufficient on its own.

### Is a Mobile Hotspot Safer?

The user's own mobile data connection can be more controlled than some public Wi-Fi scenarios.

However, device and mobile network security are still important.

In critical operations preferring a trusted network can be more correct.

### What Is Home Router Security?

The router of the user working from home becomes a part of the corporate access chain.

For the home router:

the default admin password being changed,

firmware update,

strong Wi-Fi encryption,

a strong password

are important.

### What Are WPA2 and WPA3?

WPA2 and WPA3 are modern Wi-Fi security standards.

WPA3 provides more up-to-date security capabilities.

However, endpoint compatibility and network requirements should be taken into account.

Weak protocols such as the old WEP should not be used.

### Wi-Fi Password Security

The home network password should not be easy to guess.

In addition the router admin password and the Wi-Fi password not being the same is a safer approach.

Default credentials must definitely be changed.

### Why Should Router Firmware Be Updated?

A vulnerability can be found in the router software.

When the vendor publishes a security update the firmware update should be applied.

Unsupported router devices can create a security risk in the long term.

### How Is DNS Security Provided for a Remote User?

While the remote user is outside the office they can fall outside corporate DNS Security.

With cloud-delivered Protective DNS or endpoint-based DNS security the same policy can be continued for remote workers.

This approach provides location-independent security.

### Why Is a Secure Web Gateway Important for Remote Work?

The office firewall may not see remote user web traffic.

With a cloud-based Secure Web Gateway, wherever the user is:

URL filtering,

malware protection,

DLP,

web access policy

can be applied.

This is an important part of the modern remote work architecture.

### What Is SSE?

**Security Service Edge, or SSE, is important for remote workers as the approach that brings cloud-delivered security services together.**

Inside SSE:

SWG,

CASB,

ZTNA

capabilities such as these can be found.

The aim is to apply the same security policy wherever the user is.

### What Is SASE?

**SASE, that is, Secure Access Service Edge, is the approach of networking and security functions being combined within a cloud-based architecture.**

As remote work and cloud adoption increase it aims to reduce the limitations of the traditional perimeter model.

Within the scope of SASE:

SD-WAN,

SWG,

CASB,

ZTNA,

security services

can be handled together.

### The Relationship Between Remote Work and Identity Security

In remote access one of the most valuable targets for the attacker is the identity.

As a result of credential theft the attacker can log in like the employee.

For this reason:

MFA,

phishing-resistant MFA,

Conditional Access,

Risk-Based Authentication

are critical controls.

### Should MFA Be Mandatory for Remote Work?

While a risk-based evaluation is made, MFA for remote access is one of the fundamental controls of the modern security architecture.

Password-only access creates a serious risk especially for internet-facing applications.

For high-risk users phishing-resistant MFA can be preferred.

### Why Is Phishing-Resistant MFA Important for Remote Work?

A remote worker uses many digital communication channels.

A phishing attack can come over e-mail, Teams, SMS or a messaging application.

Phishing-resistant methods such as FIDO2, WebAuthn and a security key can help to reduce the credential phishing risk.

### Can Phishing Happen over Teams and Slack?

Yes.

Social engineering does not take place only over e-mail.

The attacker can send messages on collaboration platforms over a compromised internal account.

For this reason:

Teams,

Slack,

WhatsApp,

business messaging

these channels are also part of the human attack surface.

### The Fake IT Support Attack

Remote workers can need technical support more.

The attacker can introduce themselves as IT support personnel and try to persuade the user to:

install a remote access tool,

approve MFA,

share credentials

do these.

For this reason help desk verification and security awareness are of critical importance.

### The Remote Access Tool Risk

Legitimate remote support tools can be abused by the attacker.

For this reason unauthorized remote access software installation on the endpoint should be limited.

Application Control and EDR can provide visibility on this subject.

### Remote Desktop Protocol Security

Remote administration technologies such as RDP should not be exposed directly on the internet.

They should be protected with a secure gateway, VPN, ZTNA, MFA and network controls.

Remote administration access should be evaluated as high-risk.

### Home Office Physical Security

Working from home does not create only cyber risk.

The screen or printed documents can be seen by family members, visitors or other people.

For this reason:

screen lock,

clean desk,

document handling

physical security principles such as these are valid for remote work too.

### How Does Shoulder Surfing Happen in Remote Work?

While the user is working in a café, airport or train another person can see the sensitive information on the screen.

A privacy screen and user awareness can reduce this risk.

Confidential information in particular should not be displayed in a public area.

### Confidential Call Risks

A remote worker can join a meeting from a public area.

Sensitive business discussions can be heard by the people around.

For this reason the physical environment is also part of the information security context.

### Is It Risky to Work with a Personal Computer?

If a personal device is not managed by the organization:

security updates,

malware protection,

other users,

installed software

may not be controllable.

For this reason the use of a managed device should be preferred for corporate data.

### Why Is a Shared Home Computer Risky?

If different family members use the same device the corporate session or data can be accessed by the wrong user.

For this reason a dedicated user profile and where possible a dedicated managed device should be preferred for corporate work.

### The Local Data Storage Risk

A remote worker can download a cloud document to the local device.

When the device is lost unencrypted local data can create risk.

For this reason disk encryption and DLP are important.

### Why Is Full Disk Encryption Critical for Remote Work?

Because a laptop is carried outside the office more often the theft and loss risk increases.

Full Disk Encryption helps to protect the stored data when the device is physically lost.

For this reason it is an important requirement in the remote workforce endpoint baseline.

### How Is DLP Used in Remote Working?

A remote user can take corporate data outside over:

personal e-mail,

USB,

personal cloud,

a public AI service

these.

Endpoint DLP and cloud DLP can apply policy over these channels.

### Clipboard DLP

Sensitive data can be copy-pasted from a corporate application to a personal application.

MAM or endpoint DLP can apply clipboard restrictions in some scenarios.

This is important especially for BYOD environments.

### Print Security

A remote worker can print a confidential document on a home printer.

How this printed data will later be stored or destroyed is also part of the security policy.

The remote work policy should not cover only digital data.

### The Use of Personal E-mail

The user can use personal e-mail in order to quickly send a corporate file to themselves.

This can provide operational convenience but can create:

DLP bypass,

data retention,

compliance

these risks.

For this reason secure file-sharing alternatives should be offered.

### The Personal Cloud Storage Risk

Personal storage services such as Dropbox, Google Drive or similar can be used for work convenience.

However, corporate data can move outside organization control.

CASB and DLP can provide visibility about this use.

### Why Is SaaS Security Important for Remote Work?

The remote workforce accesses many corporate applications directly over the internet.

For this reason the security perimeter is no longer the office network.

Identity, device and application security have become the new perimeter.

### How Should Cloud Application Access Be Protected?

For corporate SaaS access:

MFA,

Conditional Access,

Device Compliance,

Session Control,

DLP

can be applied.

Actions such as download from an unmanaged device in particular can be restricted.

### What Is Session Control?

Session Control provides for the operations that can be carried out during the session after the user has authenticated to be limited.

For example a sensitive application can be viewed over an unmanaged device but file download can be blocked.

This is a strong control for Zero Trust and cloud security.

### The Shadow IT Risk in Remote Work

If a user working outside the office has difficulty reaching approved IT support they can use their own tools.

Personal file-sharing, remote desktop software or AI tools are examples of this.

For this reason Shadow IT can increase in remote work periods.

### Remote Work and Generative AI

While working from home the user can upload corporate content to public AI tools.

Controlling this can be harder while outside the office network.

Cloud-delivered SWG, CASB and DLP are therefore important.

### The Lateral Movement Risk After VPN

If a traditional VPN gives the user broad internal network access the attacker can carry out lateral movement over a compromised endpoint.

Network segmentation and least privilege reduce this risk.

One of the important advantages of ZTNA is that it can provide application-specific access instead of network-wide access.

### Least Privilege Remote Access

Not every remote user needs to access the whole internal network.

Access should be limited on the basis of:

role,

application,

business requirement

these.

This is the foundation of the Zero Trust remote access approach.

### Privileged Remote Access

The remote access of system administrators is higher risk than that of normal users.

For privileged remote access:

PAM,

phishing-resistant MFA,

session recording,

JIT access,

an approved device

additional controls such as these can be applied.

### What Is PAM?

PAM:

#### Privileged Access Management

is the security approach used to control, monitor and where necessary record the access of highly privileged accounts.

PAM is especially important for remote administration.

### What Is Just-in-Time Access?

JIT Access is privileged permission being provided only in the short time interval in which it is needed instead of being given continuously.

In this way permanent administrative access can be reduced.

### Endpoint Security in Remote Work

Because remote users are outside the office endpoint telemetry becomes more important.

The EDR agent must be able to send telemetry to the centralized security platform over the internet.

In this way the SOC can see the incident wherever the endpoint is.

### How Does EDR Protect the Remote User?

EDR:

malware execution,

a suspicious process,

credential theft,

remote tool abuse

can detect behaviours such as these.

If necessary the remote endpoint can be isolated from the network.

This is a critical response capability especially when the user is outside the office.

### Remote Endpoint Isolation

If a compromised remote laptop is connected to the corporate VPN the attacker can access the internal network.

EDR isolation can limit lateral movement by cutting this connection.

For this reason the isolation capability should be tested regularly.

### How Does the SOC Monitor Remote Work Events?

The SOC:

VPN logs,

Identity logs,

EDR alerts,

SWG events,

DLP alerts,

Cloud audit logs

can evaluate different sources such as these together.

The success of remote work security depends on centralized visibility.

### Why Is SIEM Important in Remote Work Security?

The SIEM correlates events coming from different security layers.

For example:

Unusual VPN Login

New Device

EDR Alert

Large Cloud Download

when these are seen for the same user it can be a high-risk incident.

### What Does Impossible Travel Mean in Remote Work?

If a user appears to have logged in from very distant geographic locations within a short time the possibility of compromise can be evaluated.

However, because of VPN egress and cloud infrastructure a false positive can arise.

For this reason context is necessary.

### What Is a Risky Sign-In?

A Risky Sign-In is an authentication event being evaluated as unusual or potentially malicious because of various signals.

For example:

an anonymous proxy,

a malicious IP,

a new device,

an unusual location

can increase the risk score.

Conditional Access can apply an additional control accordingly.

### Remote Work Threat Detection

Mature security programmes do not monitor only login success/failure.

User and device behavior is also evaluated.

For example a user who normally downloads 100 MB of data downloading very large data overnight can require investigation.

### What Is UEBA?

UEBA:

#### User and Entity Behavior Analytics

is the analytics approach aimed at creating normal behavior patterns for users and devices and detecting deviations.

Because normal behavior can be more variable in remote work environments tuning is important.

### Remote Work Incident Response

When a remote user reports a security incident physical access may not be possible.

For this reason the remote response capability should be planned in advance.

EDR,

MDM,

Identity Provider

some actions can be carried out remotely over these.

### What Should Be Done If a Remote Laptop Is Compromised?

Depending on the situation:

device isolate,

account disable,

session revoke,

password reset,

MFA review,

forensic investigation

can be applied.

The user continuing to use the device can be prevented.

### Incident Response If a Mobile Device Is Lost

First of all the user should report it quickly.

Afterwards according to the risk level:

remote wipe,

session revoke,

device block,

MFA reset

can be evaluated.

The identity risks associated with the SIM or telephone number should also be checked.

### The SIM Swap Risk

If the phone number is used in some authentication processes the risk of the number being compromised should be taken into account.

For this reason for high-risk accounts phishing-resistant methods can be preferred instead of SMS authentication.

### Remote Work Security Awareness

Remote work scenarios should be explained to users instead of generic security training.

In particular:

public Wi-Fi,

fake IT support,

an unexpected MFA,

a lost device,

personal cloud,

sensitive calls,

screen privacy

these subjects should be covered.

### What Should the User Do for Cyber Security When Working from Home?

The fundamental behaviours:

Use the corporate device.

Keep the device up to date.

Use MFA actively.

Do not approve an unexpected MFA request.

Be careful on public Wi-Fi.

Use the corporate VPN/ZTNA.

Do not upload company data to personal cloud.

Do not share the device with others.

Lock the screen.

Report a lost device immediately.

These simple behaviours should be supported with technical security controls.

### The Most Frequently Made Mistakes in Remote Work Security

The mistakes frequently seen in organizations are these:

- Using only a password for remote access
- Seeing the VPN as the single security control
- Giving all VPN users broad network access
- Not evaluating the split tunneling risk
- Not evaluating ZTNA
- Not using MFA
- Not using stronger MFA for privileged remote access
- Giving unrestricted access to unmanaged devices
- Not applying device compliance
- Not creating a BYOD policy
- Not using MDM/UEM
- Not creating a lost device response process
- Not using Full Disk Encryption
- Not monitoring EDR health on remote endpoints
- Not taking public Wi-Fi risks into the awareness scope
- Not providing SWG/DNS Security for remote workers
- Not controlling the use of personal cloud storage
- Not applying a remote DLP policy
- Ignoring collaboration platform phishing
- Not evaluating the Fake IT Support risk
- Not sending remote access logs to the SIEM
- Not correlating VPN and identity events
- Not testing the remote incident response capability

### Remote Work Security Checklist

Organizations can regularly evaluate the following controls:

- Is a Remote Work Security Policy present?
- Is remote access protected with MFA?
- Has phishing-resistant MFA been evaluated?
- Is the VPN configuration reviewed regularly?
- Are VPN logs monitored centrally?
- Has a Split Tunnel risk assessment been made?
- Has the need for ZTNA been evaluated?
- Does remote access conform to the least privilege principle?
- Is privileged remote access managed with PAM?
- Are remote devices managed?
- Is the MDM/UEM deployment sufficient?
- Is Device Compliance active?
- Are non-compliant devices being blocked?
- Is Full Disk Encryption mandatory?
- Is EDR active on all remote endpoints?
- Is EDR agent health monitored over the internet?
- Is there a remote endpoint isolation capability?
- Are browser and SWG policies applied to remote users?
- Is DNS Security active for remote users?
- Does DLP work outside the office too?
- Is there a personal cloud storage policy?
- Is a BYOD policy defined?
- Has the use of MAM been evaluated?
- Is public Wi-Fi awareness training being given?
- Is a Lost/Stolen Device playbook present?
- Is cloud application access protected with Conditional Access?
- Are session controls being applied?
- Are identity logs going to the SIEM?
- Are VPN, Identity, EDR and DLP events being correlated?
- Does the SOC use a playbook for remote work incidents?

### Remote Work Security Maturity Model

#### Level 1 – VPN-Focused Remote Access

Remote users connect to the corporate network with a username-password and VPN.

Device posture and user risk are evaluated to a limited extent.

#### Level 2 – MFA and Managed Endpoint

The VPN is protected with MFA.

Corporate laptops are managed with EDR, encryption and centralized patch management.

A BYOD policy is created.

#### Level 3 – Identity and Device-Aware Access

Conditional Access, Device Compliance, MDM/UEM and risk-based authentication are applied.

Remote user security becomes more consistent with office security.

#### Level 4 – ZTNA and Cloud-Delivered Security

Traditional network-wide VPN access is reduced.

Application-level secure access is created with ZTNA, SWG, CASB, DLP and SSE capabilities.

#### Level 5 – Adaptive Zero Trust Remote Work

User identity, device posture, application sensitivity, behavior and threat risk are evaluated in real time.

Access is dynamically allowed, restricted or revoked.

The security policy becomes completely location-independent.

### Frequently Asked Questions

#### What is remote work security?

Remote work security is the management of the identity, endpoint, network and data security risks that employees face while accessing corporate applications and data from outside the office.

#### What is a VPN?

A VPN is the Virtual Private Network technology that creates an encrypted tunnel between the user device and the corporate network or security gateway.

#### Is using a VPN safe?

With correct configuration, MFA, endpoint security and monitoring it can provide secure remote access. However, a VPN does not on its own remove all remote work risks.

#### If there is a VPN is MFA necessary?

Yes. MFA provides an important additional authentication layer against VPN credentials being obtained.

#### What is ZTNA?

Zero Trust Network Access is the security approach that aims to provide context-aware access only to the authorized application or resource instead of giving the user broad network access.

#### What is the difference between VPN and ZTNA?

While a VPN mostly provides network-level connectivity, ZTNA focuses on providing application-specific and identity/device-aware access.

#### Is public Wi-Fi safe?

Public Wi-Fi can be risky. Against risks such as a fake access point, an untrusted network and phishing, a VPN, endpoint security and user awareness should be used.

#### What is an Evil Twin?

It is an attacker-controlled fake wireless network that imitates the name of a legitimate Wi-Fi access point.

#### What is a Rogue Access Point?

It is a wireless access point that is not approved by the organization.

#### What is BYOD?

Bring Your Own Device is employees using their personal devices for corporate work.

#### Is BYOD safe?

If correct MDM/MAM, Conditional Access, DLP and data separation controls are applied the risk can be managed. Uncontrolled BYOD can create a serious security and compliance risk.

#### What is MDM?

Mobile Device Management is the technology that provides for mobile devices to be managed with centralized security policies.

#### What is MAM?

Mobile Application Management focuses on the corporate application and data being managed with security policies instead of the whole device.

#### What is UEM?

Unified Endpoint Management is different endpoint types being managed over a central security and management platform.

#### What is Device Compliance?

It is the state that shows whether the endpoint conforms to the encryption, EDR, update and security policy requirements determined by the organization.

#### What is Conditional Access?

It is the security approach that provides for an access decision to be applied according to the user, device, location, risk and application context.

#### What is SASE?

Secure Access Service Edge is the model that aims to combine networking and cloud-delivered security services under a common architecture.

#### What is SSE?

Security Service Edge is the security architecture approach that brings cloud-delivered security capabilities such as SWG, CASB and ZTNA together.

#### What should be done if a remote laptop is lost?

The organization's incident process should be started; device block/remote wipe, session revocation and an identity security review should be carried out.

### Conclusion: Remote Work Security No Longer Consists of Setting Up a VPN

For many years the first technology thought of when remote work security was mentioned was the VPN.

The VPN is still an important security control.

However, in the modern working environment it is not sufficient on its own.

Because the attacker:

can obtain the VPN password.

There can be malware on the user's device.

A sensitive application can be accessed over an unmanaged device.

The user can connect to a fake access point on public Wi-Fi.

Corporate data can be transferred to personal cloud.

The attacker can carry out social engineering over a collaboration tool.

For this reason the real Remote Work Security architecture should be thought of as follows:

#### Identity Security

↓

#### MFA / Phishing-Resistant Authentication

↓

#### Device Compliance

↓

#### Endpoint Security / EDR

↓

#### VPN / ZTNA

↓

#### SWG / DNS Security

↓

#### CASB / DLP

↓

#### SIEM / SOC

At the foundation of this structure lies the Zero Trust principle.

The user:

because they use a corporate account,

because they are connected to the VPN,

because they use a corporate laptop

should not automatically be accepted as trusted.

Every access request:

**User + Device + Context + Resource + Risk**

should be evaluated with these.

The most important consequence of this approach is that the security perimeter changes.

In the past the perimeter was the office firewall.

Today the perimeter is:

**Identity + Endpoint + Application + Data**

the combination of these.

The user can be in the office in Istanbul.

They can work from home in Ankara.

They can connect from a hotel in another country.

The logic of the security policy should not change.

For this reason the fundamental formula of modern remote work security:

**Strong Identity + Trusted Device + Least Privilege Access + Secure Connectivity + Data Protection + Continuous Monitoring**

can be thought of in this way.

And the most important sentence of this chapter is this:

**In remote work security the aim is not to connect the user to the corporate network; it is to connect the right user, with the right device, safely to only the right resource.**
