Distributed work is no longer a contingency. For most organizations it is simply how work happens, and the security arrangements made quickly during the shift to remote working have long since become permanent architecture — usually without anyone deciding that they should be.
The useful review is not whether remote work is secure. It is which of the temporary decisions are still in place, and which of them would survive scrutiny today.
1. The perimeter moved to identity
When staff, contractors and systems all sit outside the corporate network, network location stops describing trust. The practical boundary becomes the identity provider and the posture of the device making the request.
This is not a philosophical point. It changes where security investment should go. Spending concentrated on network controls, while the identity provider carries weak authentication and unreviewed recovery paths, protects the part of the estate that matters least.
2. What tends to still be there from the transition
A review usually surfaces the same items:
- Broad VPN access that grants network-level connectivity where per-application access would do
- Personal devices reaching corporate data under an exception that was never revisited
- Collaboration platforms with external sharing defaults set for speed rather than intent
- Contractor and supplier accounts that outlived the engagement
- SaaS applications procured by individual teams and never brought under central identity
- Home network and personal router assumptions inherited from 2020 guidance
None of these are dramatic on their own. Together they describe an estate where access is wider than anyone intends and nobody holds the full picture.
3. Identity sprawl is the quiet problem
The most common finding is that the organization has more identity systems than it believes. Applications adopted departmentally often carry their own user directories, their own password rules, and no connection to the joiners-movers-leavers process.
The consequence appears at offboarding. A departure processed correctly in the central directory can leave active access in several applications that were never integrated — and because those applications are unmanaged, nobody is reviewing them.
Consolidating applications behind single sign-on is unglamorous work with a direct security return: it makes access removal reliable, and it makes access review possible at all.
4. Device posture, honestly assessed
Managed corporate devices with enforced patching, disk encryption and endpoint detection remain the strongest position. Where that is not achievable — contractors, temporary staff, personal devices under an accepted exception — the realistic answer is to constrain what those devices can reach rather than to pretend the exception does not exist.
Options include browser-based access with no local data storage, restricted application sets, and conditional policies that account for unmanaged status. What does not work is an undocumented exception that quietly grants the same access as a managed laptop.
5. A review worth running annually
Distributed work arrangements drift. A yearly review against a short list keeps the drift visible:
- Which applications sit outside single sign-on, and what is the plan for each?
- Does offboarding reliably remove access everywhere, and has that been tested with a real departure?
- Which accounts belong to contractors or suppliers, and are any past their engagement?
- What are the external sharing defaults on collaboration platforms, and were they chosen deliberately?
- How many devices reaching corporate data are unmanaged, and what can they access?
- Which access exceptions exist, who approved them, and when were they last reviewed?
6. Where the geography actually matters
One item that is genuinely different in a distributed organization, and frequently missed: employment and data protection obligations follow the location of the person, not the location of the company. Staff working from other jurisdictions can create data residency, tax and employment exposure that the security team is not positioned to notice.
This belongs in the same review, even though it is not strictly a security control, because the information needed to spot it usually sits in systems the security function already touches.
Review the arrangements you inherited
Most organizations did not design their current distributed working posture. They arrived at it under time pressure and kept it. That is not a failure — but the decisions deserve a deliberate second look, made with the estate as it is now rather than as it was during the transition.
When the estate needs a deliberate second look
JLS Technology provides Fractional CIO and Fractional CISO leadership, cybersecurity strategy, and managed security operations for organizations reviewing access, identity and device posture across distributed teams.
Explore Fractional CISO services · Explore Fractional CIO services · Request a Strategic Technology Session
This article is general educational guidance, not legal advice, a certification, or a substitute for an organization-specific security assessment.

