RWRemote Work Notes
remote work

Keeping Work Data Secure on a Home Network

A plain-language summary of CISA and NIST telework security guidance covering home Wi-Fi, device use, and the behaviors that create the most risk.

Working from a kitchen table does not feel like a security risk, but the government's own cybersecurity guidance treats home telework setups as a genuinely different risk category from an office, mainly because the home network, the devices, and the habits around both are outside an employer's direct control. CISA (the Cybersecurity and Infrastructure Security Agency), working with the NSA, and NIST (the National Institute of Standards and Technology) both publish detailed, specific guidance on this, and a handful of their recommendations cover most of the real risk.

Your home router is probably not secure by default

CISA's telework guidance asks and answers this directly: "Is my home router secure out of the box? The short answer: Probably not. At minimum, change the default password to one only you know." Routers typically ship with a manufacturer-set default password that is published in manuals and widely known, which means an unchanged default password is effectively no password at all from a security standpoint.

NIST's guide goes further, describing exactly what an improperly secured home wireless network exposes: "If improperly configured, a wireless home network will transmit sensitive information without adequate protection, exposing it to other wireless devices in close proximity." In plain terms, an unsecured home Wi-Fi network can let nearby devices see or intercept your traffic, not just devices you have explicitly connected.

A specific list of things not to do on telework equipment

CISA and NSA's joint telework guidance includes a direct list of practices to avoid when working remotely, adapted from Department of Defense telework cybersecurity guidance. Several of these apply just as much to everyday remote workers as to government staff:

  • Do not connect government (or work) equipment to a network you do not own and control, for example public Wi-Fi.
  • Do not share devices used for work, including with family members or other household members.
  • Do not forward work emails to a personal email account.
  • Do not store work-related content on personally owned equipment, including personal mobile devices and personal cloud or file-sharing accounts.
  • Do not leave your computer unlocked when unattended.
  • Do not send unencrypted, sensitive content.

These are framed as things to avoid rather than things to do, which is a useful distinction: they describe specific, common shortcuts that create real exposure, rather than abstract best practices.

Public Wi-Fi deserves specific caution

CISA's guidance treats public Wi-Fi as a distinct risk category, noting that "public Wi-Fi in airports, coffee shops, libraries, restaurants, malls, hotels and other public gathering spaces are not always secure." Its specific recommendation before connecting to any public network is to verify with staff that the network name you are selecting is the legitimate one offered by that business, since attackers sometimes set up fake networks with similar names in public places specifically to intercept traffic from people who connect to the wrong one.

Multi-factor authentication is one of the highest-value single steps

Among the more technical recommendations in CISA's broader telework toolkit, enforcing multi-factor authentication (MFA) for remote access to work systems and services is listed as a top action item. MFA requires a second form of verification beyond just a password, commonly a code sent to your phone or generated by an authenticator app, so that a stolen or guessed password alone is not enough for someone else to access your account.

Why this matters even if your employer has "other" security measures

NIST's guidance frames telework and remote access security as covering three overlapping components: the telework device itself, the remote access method connecting it to organizational resources, and the organization's internal systems. Importantly, weaknesses at the home-network or personal-device level can undermine security measures the employer has set up elsewhere, since an employer typically has far less visibility and control over a home router or personal device than over office equipment.

A practical checklist based directly on this guidance

  • Change your home router's default admin password to something unique, not the one printed on the device or in its manual.
  • Avoid connecting work devices to public Wi-Fi when possible; if you must, confirm the network name directly with venue staff first.
  • Keep work accounts and personal accounts separate: no forwarding work email to personal accounts, and no storing work files in personal cloud storage.
  • Do not let other household members use a device that has work access, even briefly.
  • Lock your screen any time you step away, even at home.
  • Turn on multi-factor authentication for every work account that offers it.

Key takeaways

  • CISA states plainly that most home routers are not secure with their default settings; changing the default admin password is a basic first step.
  • NIST's guidance warns that an improperly configured home wireless network can expose sensitive information to nearby devices, not just devices you have intentionally connected.
  • CISA and NSA's joint telework guidance specifically warns against connecting work devices to public Wi-Fi, sharing work devices with family, forwarding work email to personal accounts, and storing work files on personal cloud storage.
  • Public Wi-Fi networks are explicitly flagged as "not always secure," with a specific recommendation to verify the network name with venue staff before connecting.
  • Multi-factor authentication is highlighted as one of the highest-value individual security steps for protecting remote access to work accounts.

Sources

  1. CISA and NSA, Telework Best Practices
  2. NIST Special Publication 800-46 Revision 2, Guide to Enterprise Telework, Remote Access, and BYOD Security
remote workcybersecuritytelework