Home office security is the practice of protecting five areas at the same time: the room, Wi-Fi router, work devices, online accounts and business information. Start with the router and work computer, then add multi-factor authentication, secure backups and physical privacy controls.

**Last reviewed: **

Home Office Security at a Glance

Priority What to do Why it matters
1 Change your router's default admin password Default credentials are easy for attackers to guess
2 Use WPA3 or WPA2 Wi-Fi encryption Encryption helps protect information sent over your wireless network
3 Turn on automatic updates Security patches fix known weaknesses
4 Require multi-factor authentication MFA protects accounts even if a password is stolen
5 Lock and encrypt your work device This reduces the impact of theft or unauthorized access
6 Separate work devices from guest and smart-home devices A compromised device can put other devices on the same network at risk
7 Back up important files Backups help you recover from hardware failure, theft or ransomware
8 Secure paper documents and video calls Physical access and visual eavesdropping can expose sensitive information

1. Secure Your Home Wi-Fi Router

Your router connects the home office to the internet. Log in to its administration page and:

  1. Change the default administrator username and password.
  2. Use a unique Wi-Fi password that is not based on your name, address or router brand.
  3. Enable WPA3 encryption if your devices support it. Otherwise, use WPA2.
  4. Install router firmware updates when they become available.
  5. Disable remote administration unless you have a specific security reason to use it.
  6. Create a guest network for visitors and, where practical, smart TVs, cameras, speakers and other connected devices.
  7. Choose a neutral Wi-Fi network name that does not reveal your address, family name or router model.

The Federal Trade Commission recommends changing default router credentials, enabling encryption and checking for firmware updates. CISA also recommends WPA2 or WPA3 encryption and disabling older wireless protocols such as WEP and WPA.

A guest network limits the connection between visitors, less-trusted devices and the network used by your work computer. NIST recommends considering network segmentation so connected devices have limited access to computers containing sensitive information.

2. Secure the Work Computer

Use a company-managed laptop or desktop when your employer provides one. These devices usually include security controls, approved software and remote support that can be difficult to reproduce on a personal computer.

For every computer used for work:

  • Use a strong password, PIN, fingerprint or facial login.
  • Set the screen to lock automatically after a short period of inactivity.
  • Install operating system, browser and application updates promptly.
  • Enable full-disk encryption, such as BitLocker on Windows or FileVault on macOS.
  • Use approved antivirus or endpoint security software.
  • Avoid using an administrator account for everyday tasks.
  • Do not install unapproved remote-access tools or browser extensions.
  • Keep the computer physically secure when you are away from it.

NIST recommends device authentication, automatic updates and secure home Wi-Fi for telework devices. The FTC also recommends full-disk encryption for laptops and mobile devices that connect remotely to business networks.

Personal Computer Versus Company Computer

Situation Recommended approach
Company-issued computer Follow your employer's security policy and use the approved VPN, file storage and collaboration tools
Personal computer for limited work Use it only if your employer permits it; keep the operating system updated and use encryption and MFA
Personal computer for sensitive customer or company data Avoid it unless your employer has formally approved and secured the setup
Shared family computer Do not use it for confidential work; use a separate protected device or user account

NIST advises workers to check whether personal devices are permitted and whether they may access sensitive information.

3. Protect Work Accounts With Multi-Factor Authentication

Turn on multi-factor authentication for:

  • Work email
  • Cloud storage
  • Payroll and accounting systems
  • Project management platforms
  • Video-conferencing services
  • Company VPNs
  • Password managers
  • Banking and payment accounts

Use these options in order when they are available:

  1. A physical security key using a phishing-resistant standard such as FIDO2.
  2. An authenticator app with number matching or one-time codes.
  3. A biometric login paired with another authentication factor.
  4. Text-message codes when stronger options are unavailable.

CISA recommends MFA for email, file storage, remote access and administrative accounts. It also identifies hardware security keys and other phishing-resistant methods as stronger options than SMS codes.

Use a password manager to create a separate, long password for every account. Do not reuse your Wi-Fi password, work password and personal email password.

4. Use Secure Remote Access

If your employer provides a VPN, use the employer-approved VPN when accessing internal systems or sensitive business information. A consumer VPN is not a substitute for your company's required remote-access tools.

Follow these rules:

  • Connect only through approved work applications and services.
  • Do not expose Remote Desktop Protocol or similar remote-access services directly to the internet.
  • Do not forward work email to a personal email account.
  • Store work files only in approved company storage.
  • Log out of remote sessions when your workday ends.
  • Use a personal hotspot or another trusted connection when home Wi-Fi is unavailable.
  • Treat public Wi-Fi as a higher-risk environment and use your employer's approved protections before accessing sensitive systems.

The FTC warns that remote access must be secured before employees, contractors or vendors connect to business systems. NIST also recommends following organizational telework rules and using approved security controls.

5. Protect Files With Encryption and Backups

Encryption protects data stored on your laptop, external drives and removable media if a device is lost or stolen. Enable full-disk encryption on work computers and encrypt sensitive files when your operating system or approved business software supports it.

Create backups for important work files using an approved cloud service or external drive. Keep at least one backup separate from the computer. If you use an external drive, disconnect it when the backup is complete. Ransomware can potentially reach a continuously connected backup drive.

A workable backup routine is:

  • Keep active files in approved business cloud storage.
  • Enable automatic version history where available.
  • Back up essential local files regularly.
  • Store an external backup in a secure location.
  • Test that you can restore a file before you need the backup.

Do not copy confidential work files to personal cloud storage, USB drives or personal email unless your employer explicitly permits it.

6. Add Physical Security to the Room

Cybersecurity cannot protect an unlocked laptop or a printed customer record. Improve the physical security of the office by:

  • Positioning the monitor away from windows, hallways and visitors.
  • Locking the office door when confidential work is in progress.
  • Using a privacy screen when other people may view the display.
  • Locking your computer whenever you leave the desk.
  • Keeping laptops, external drives and security keys out of sight.
  • Storing paper records in a locked cabinet.
  • Shredding sensitive documents instead of putting them in household recycling.
  • Keeping work devices away from children, visitors and unauthorized users.
  • Using headphones for confidential calls when other people are nearby.

NIST includes physical security for telework devices, removable media, papers and other non-computer records in its telework guidance.

7. Prevent Phishing and Social Engineering

Many home office breaches begin with a convincing email, text message or phone call rather than a technical attack.

Before opening an attachment, approving an MFA prompt or transferring money:

  • Check the sender's full email address.
  • Hover over links before clicking them.
  • Be cautious with urgent requests involving passwords, invoices or payment details.
  • Verify unusual requests through a separate trusted channel.
  • Never share passwords or MFA codes with someone who contacts you unexpectedly.
  • Report suspicious messages to your employer or IT provider.
  • Do not approve an MFA request that you did not initiate.

CISA and NIST identify phishing, suspicious attachments, unusual links and social engineering as telework risks.

8. Secure Video Calls and Smart Devices

Before joining a confidential meeting:

  • Use a meeting password or waiting room.
  • Do not share meeting links publicly.
  • Check what is visible behind you.
  • Remove whiteboards, documents and customer information from view.
  • Mute your microphone when you are not speaking.
  • Use headphones when confidential audio could be overheard.
  • Close unnecessary screen-sharing windows.
  • Cover or disable cameras and microphones when they are not needed.

Keep smart speakers, cameras and other internet-connected devices on a guest network when possible. Change their default passwords, enable available two-factor authentication and install firmware updates. The FTC recommends changing default credentials, using two-factor authentication and keeping connected-device software updated.

9. Follow Your Employer's Security Policy

Your employer's policy should determine:

  • Whether personal devices are allowed.
  • Which VPN and collaboration tools you must use.
  • Where business files may be stored.
  • Whether printing is permitted.
  • How to report a lost device or suspected phishing attack.
  • What information may be discussed in shared spaces.
  • Whether family members may use the work device.

If a work laptop is lost, stolen or behaving unusually, report it immediately. Early reporting may allow your employer to disable accounts, revoke sessions or remotely wipe a managed device.

A 30-Minute Home Office Security Setup

If you need a starting point, complete these actions first:

  1. Change the router administrator password.
  2. Enable WPA2 or WPA3 Wi-Fi encryption.
  3. Update the router firmware.
  4. Create a guest network.
  5. Turn on automatic updates for the work computer.
  6. Enable full-disk encryption and automatic screen locking.
  7. Turn on MFA for email, cloud storage and VPN access.
  8. Install or activate a password manager.
  9. Set up an approved backup.
  10. Move confidential documents away from windows and shared areas.

The main gains come from unique credentials, MFA, updated devices, encrypted storage, secure Wi-Fi, backups and physical privacy. Start with the controls your employer requires, then close the remaining gaps in the room, router and devices.