New work = new IT?
KMUtmacher guest post: key IT security requirements driven by new working models
It's become clear that new working models, such as hybrid office setups, will remain a fixture of everyday work even after the pandemic. According to a Microsoft study, 73% of employees want to keep the option of working from home in future.

Dennis Ramin is an IT consultant and managing director of Biscuit GmbH. In this KMUtmacher guest post, he explains how this is also changing the security requirements for mid-sized companies' information infrastructure.
Digital, flexible working has already become the norm in many areas. In IT support, for instance, it's now standard for us to fix problems remotely – an on-site visit is rarely needed any more. The pandemic suddenly brought home working and new work into industries that hadn't given it a thought before, sending them into what you might call “uncharted digital territory”.
Hybrid work – what does that actually mean?
Staff appraisals, team meetings and client negotiations are now held as video calls or over the phone.
Cloud tools let several people fill in digital flipcharts at once, work together on documents, and store everything digitally on servers. Training sessions, presentations and creative brainstorms are now a regular fixture in the calendar, and even team events have found their own solutions – with virtual Christmas parties or after-work drinks on platforms like “gather.town”.
New IT requirements
These changes bring new technical requirements too, if secure and uninterrupted work is going to be possible. Workflows shouldn't be held up by slow technology, poor connections or outdated software. Every workstation and every employee needs to be properly equipped to work without restrictions.
But this connectivity and flexibility also brings risks – unsecured environments, unprotected devices, or simple carelessness among staff (often down to a lack of awareness).
These are the possible security gaps in hybrid working:
- Company data is accessed from all kinds of different locations.
- People regularly switch between well-protected company networks and less secure – sometimes even unencrypted – networks or public hotspots.
- Unsecured networks like these are usually an easy target for attackers looking to get hold of sensitive data. At the same time, it's difficult for IT teams to spot suspicious access by IP address and fend off unauthorised access.
- Access to company data no longer happens solely via the work computer. Employees often use personal devices to check chats or emails on their own phone. Personal devices aren't always up to date, and adequate password protection and regular updates aren't a given. Other devices on the same network pose a potential risk too.
- Last but not least, the human factor always plays a role. During the pandemic, it became clear that employees working remotely are more vulnerable to cyberattacks. More frequent distractions at home, and less exchange with colleagues, make it more likely that a phishing attempt goes unnoticed – successfully installing malware on the device.
Here's how to close these security gaps:
- Modern, mobile devices running up-to-date software offer better security and boost productivity
- Set up access rights for staff using so-called single sign-on (SSO). This makes it easy to grant and withdraw access rights with minimal effort, so you always know who can access which data.
- Ensure encrypted data transfer with a VPN (virtual private network) to keep access from public networks as secure as possible, and make sure any software you use offers end-to-end encryption.
- Build a security culture, and run targeted training to raise staff awareness of potential threats.
- Introduce mobile device management (MDM) so devices can be configured, updated, managed, located or wiped remotely.
Checklist: IT security when working from home
Protect Wi-Fi networks with a password (and change it regularly)
Use different, secure passwords for every application and service
Install software updates regularly
Keep documents and devices safely out of reach of unauthorised people
And what fires you up?
Tell us what you’re working on right now — relaxed, over a coffee, virtually or in Munich-Sendling.
Arrange a chat