Security in the hybrid working era:
Is your organisation prepared for new risks?

Adjusting to a new normal

Before 2020, face-to-face interaction with employees made it easier for IT teams to solve problems, and processes often relied on this approach. When employees worked outside the office, infrastructure typically allowed secure access to internal systems via VPNs. However, as hybrid working emerged, working habits were rapidly transformed, along with the IT landscape and new hybrid work security challenges.

Departments suddenly had to adapt to evolving risks in a secure hybrid workplace, facing a range of new security challenges they hadn’t previously anticipated.

New hybrid security challenges

From a practical standpoint, access quickly became a major hybrid work security challenge. While hybrid and remote working are not new concepts, VPN access was originally designed for a limited number of users rather than supporting a fully distributed workforce. The sustained increase in demand placed pressure on infrastructure, highlighting the need for more scalable and secure hybrid workplace solutions.

At the same time, resolving issues remotely introduced new risks, particularly around verifying user identity. This contributed to a rise in social engineering attacks, where cybercriminals impersonate legitimate users or employees to gain unauthorised access to systems and data. In fact, attacks like these were listed by Verizon as the number one most common malicious breach attack in their 2021 report.

Another growing concern is shadow IT within a distributed workforce. As employees work across home and hybrid environments, they may rely on personal devices or unapproved applications out of convenience. While formal BYOD security policies are typically enforced within office environments, maintaining these standards in remote settings can be more challenging without clear governance and employee security training.

These challenges are ongoing. What began as a rapid shift to remote working has evolved into a long-term hybrid model. IT teams must now adapt their approach to hybrid work security by securing each environment individually while maintaining a unified and flexible security strategy.

Home

According to recent research, 77% of IT decision makers say that employees stop following security procedures when offsite, even though organisations are already operating an official hybrid working policy. To achieve effective hybrid work security, it is crucial for IT teams to define clear policies covering behaviour outside the office, from device safety and application downloads to connecting to networks and securely handling printed documents, rather than relying on employee judgement.

As employees may misunderstand where policies apply and why they are important, the most effective way to reinforce them is through structured employee security training, such as mandatory webinars that highlight individual responsibility when working across environments. Even with training in place, users remain vulnerable to malicious activity, so organisations should also invest in ongoing education to support phishing prevention and strengthen their secure hybrid workplace.

Shared and co-working spaces

Shared and co-working spaces

Co-working and shared spaces are increasingly used as flexible alternatives to traditional office environments. However, from a hybrid work security perspective, it is essential to review security policies and terms and conditions carefully, rather than focusing solely on cost and facilities. Organisations may assume that co-working providers are responsible for security, but in many cases responsibility is limited or excluded in contractual terms.

To support a secure hybrid workplace, organisations should assess whether co-working environments meet their internal standards. Key questions include: What are the physical security measures? Is access controlled or open to visitors? What are the policies around data loss or breach, and who is accountable if incidents occur? In addition, organisations should review policies related to shared WiFi security and printing, including whether documents can be accessed by unauthorised users.

Mobile

It’s important that employees understand the security threats associated with working on the go as part of hybrid work security. Shared WiFi in coffee shops, for example, can be accessed by anyone, making shared WiFi security essential, so employees should only access company documents through secure connections such as VPNs. In addition, workers can physically expose information by leaving devices unattended or working in public spaces. Where employees travel frequently, simple measures such as privacy screens can help protect sensitive information.

Organisations should also recognise that devices can be lost or stolen, which presents additional risks in a secure hybrid workplace. To reduce exposure, safeguards such as device encryption, secure access controls, and remote wipe capabilities should be considered to prevent unauthorised access to company data.

Organisations globally have adopted hybrid working at scale, and now security must become a primary focus. With more potential entry points in distributed environments, reviewing security policies, access controls, and user behaviour is critical. Alongside this, ongoing employee security training is essential to ensure individuals understand how their behaviour affects security. With the right awareness and controls in place, organisations can benefit from hybrid working without increasing risk.

Want to be even better prepared for the new risks that hybrid working has created?

Discover our eBook Hybrid Business Now: Security in the hybrid workspace.

Explore Further

Is ‘as-a-service’ the solution to hybrid working IT challenges?

Learn how as-a-service models meet the evolving needs of the IT team, from easier remote management to flexible response and more.

19 Oct 2022

Secure, anywhere: how to safeguard data in hybrid workspaces

Explore new data vulnerabilities, tools and technologies to boost cybersecurity and fair ways to clamp down on human error.

19 Oct 2022

Related Solutions

IT Services from Canon

Unlock the full potential of your business with Canon's innovative IT Services. Our industry-leading technology solutions offer a seamless consolidation of your print and IT infrastructure, all provided by a trusted supplier. Explore the possibilities today.

Therefore™ Document Management System

Choose Therefore, a document management solution designed to transform the way you manage and share business documents. Visit our website today!

Office Security

Discover new ways to defend your data.

uniFLOW Online

Discover Canon's suite of business software for print and scan workflows. Visit our website for secure integrated printing solutions.