ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

How hybrid workers deliberately ignore security policy

Jon Fielding at Apricorn describes how remote employees are succumbing to security policy fatigue 

 

Security awareness is integral to an effective security policy but what happens when the message isn’t hitting home? How should the organisation respond if its users are intentionally sidestepping the rules? And how can the organisation enforce policy when it is now managing a distributed workforce?

 

These are all questions that now need to be answered because there is undoubtedly a disconnect emerging between policy and practice, as revealed by a recent Apricorn survey.

 

When asked if their remote workers were aware of security risks and practices and followed the required policies to protect data, only 58% agreed, down from 92% in 2022, evidence of a sharp decline, according to the survey. Furthermore, 28% said their employees lacked awareness of the risks to data when working remotely, revealing both a lack of employee awareness and a certain level of complacency. 

 

However, some were more strident in their views. Almost half (46%) went as far as to say that their remote workers didn’t care about security and a similar number (48%) said their staff had knowingly placed corporate data at risk of a breach. In fact, employees were found to be responsible for 70% of the corporate data breaches that happened in 2023 among those who were questioned.

 

Don’t or won’t care?

So, is this a blatant disregard for policy? Not necessarily. Not caring about security could just as easily be interpreted as meaning the employee doesn’t view security as an important aspect of their day-to-day job or that they wish it was just a given without them needing to give it any thought.

 

Neither is ideal because for policy to be truly effective there needs to a security culture within the business which sees everyone step up, take responsibility and play their part. But the fact that personnel are knowingly putting data at risk suggests they aren’t just ambivalent about security but are disengaged from that culture and are resorting to workarounds. 

 

On closer inspection the survey bears this out, revealing that many of these remote workers have literally been left to their own devices. The number of businesses who allow remote users to use their own equipment without seeking permission or without installing any software to control how it is used more than doubled from 2022 to 2023 to 17%.

 

Even where device approval was compulsory, 24% of businesses did not control the access these devices had to corporate systems and data. Moreover, 19% admitted their technology did not support secure remote working and a quarter regarded such technology as too expensive. 

 

To help guard against the insider threat, many are now looking to insurance, with a fifth now seeking cover against unintentional data breaches. Cyber insurance providers are, however, all too aware of the risks involved and so are making certain measures a condition of insurance policies. Top among these was data backup, regular patching, encrypted data storage and employee training and awareness, according to the security leaders questioned.

 

That’s because taking these steps can dramatically mitigate the insider threat. The organisation doesn’t have to look to expensive technologies to make up the shortfall but can instead focus on supporting the remote workforce by putting in place these measures to protect them from pursuing those workarounds in the first place. 

 

Is the business taking a step back?

Take backup, for example. Remote working has seen a huge increase in manual backups, with 48% of companies now saying their employees backup manually compared to 6% in 2022.

 

Automated backups have also fallen to 50% compared with the 93% that did this the year before. The problem is that manual backups, while convenient for remote users, rely on people remembering to execute the backup and doing it correctly. Human fallibility being what it is, this isn’t happening, with only 27% of those organisations who were forced to recover their data being able to do so fully compared to 45% in 2022. 

 

There’s been a marked decline in encryption of remote devices too. Only 12% of organisations encrypt data on laptops, compared with 68% in 2022, and it’s a similar story for mobile phones, where 13% are encrypted versus 55% in 2022. There were dramatic drops in the encryption of USB sticks, now at 17% down from 54%, and portable hard drives at just 4% compared to 57% the year before.

 

Given that it’s possible to enforce the encryption of data across all devices automatically as standard across the organisation, this seems an unnecessary risk to be taking. But the truth of the matter is that many organisations have lost control and visibility of their data as networks have become more distributed.

 

So yes, remote and hybrid workers are becoming disaffected with security policy and are putting data at risk, but that is a result of an underlying frustration with the mechanisms, or lack of them, used to enforce it. Without processes that they can follow to protect data, they’re naturally going to find a best fit solution and will be unable to practice what is preached.

 

So perhaps the ultimate takeaway from the survey findings is not that employees aren’t doing enough to observe policy but that the business is no longer doing enough to enable and support them. 

 


 

Jon Fielding is Managing Director, EMEA for Apricorn

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543