Smart working only works if the IT works
Remote working is now part of everyday business, but without the right infrastructure it becomes a constant source of problems: unstable connections, inaccessible data and security risks. Xion IT Group helps companies and their employees manage remote working by providing software, technology infrastructure and ongoing support.
Security first
Most remote working services sit in the cloud: that is why cloud security - the set of strategies used to keep a cloud environment secure - is at the heart of every well-executed smart working project. Protection must cover:
- data and its secure transmission between remote devices and the business;
- virtualisation software and programming interfaces;
- operating systems and end-user devices;
- business activity management software.
The goal is to prevent the theft and loss of personal and company data through access protection and continuous backup activity.
What we do in practice
- Creation of company VPNs for secure remote access.
- Company cloud data sharing systems.
- Configuration of remote workstations and terminal servers.
- Data migration from the office to the home workstation.
- Configuration of macOS, OneDrive and Microsoft Office.
- Resolution of connection issues and support with internet connectivity.
The benefit for your business
Your staff can work from anywhere with the same tools and the same level of security as in the office; you retain control of your data and business continuity. And when something goes wrong, there is always a Xion technician ready to step in with remote support.
The most common pitfalls of improvised smart working
Many companies enabled remote working in a hurry — and five years later they are still relying on the same emergency solutions. The issues we find most often are:
- Remote desktop exposed to the internet without a VPN: it is ransomware’s favourite entry point;
- Personal PCs used to access company data, with no security control at all;
- Shared credentials between colleagues “to save time”;
- Files scattered across email, USB sticks and personal cloud accounts — with GDPR left by the wayside;
- No backup of what employees produce at home.
Each of these issues has an established technical solution: our job is to put them in place without disrupting the habits of the people doing the work.
VPN or published service: the choice that determines everything else
When providing external access, there are two routes — and they are often confused.
A virtual private network brings the device inside the company network: from that point on, it can see what it would see in the office. It is the right solution when internal applications, network folders or management systems are needed and do not work well over the internet. There is a downside: if the home computer is compromised, the problem enters with the user. That is why a VPN only makes sense on managed devices, not personal ones.
Publishing a single service — email, a portal, a web application — exposes only that service, without opening up everything else. By definition, it is more secure, and it should always be protected with two-factor authentication.
The shortcut we see most often, and that should always be avoided, is the third option: remote desktop exposed directly to the internet. It works, it is convenient, it takes ten minutes to configure, and it is ransomware’s favourite entry point. If it exists in your business, it should be closed before any other intervention.
Personal devices
This is the question that always comes up, and the honest answer is: it depends on what they need to access.
For email alone, a personal device can be manageable — provided access is protected with two-factor authentication and the company can remotely wipe business data without touching family photos. For access to folders and management systems, an unmanaged computer is a risk that is not worth the saving: no one knows whether it is updated, whether it is shared with others at home, or whether antivirus is active.
The middle ground we recommend most often is to publish services instead of extending the network: users with a personal device access what they need through the browser, without their computer entering the company environment.
The home workstation, from a practical point of view
Three things make the difference between remote working that runs smoothly and remote working that generates calls every day.
The connection. You do not need a fast connection, you need a stable one: video calls suffer far more from interruptions than from slowness. When someone “keeps dropping out”, the problem is almost always the home Wi-Fi, not the bandwidth.
The encrypted drive. A lost or stolen company laptop without encryption is a personal data breach that may need to be assessed for notification within seventy-two hours. With encryption enabled, it is the loss of an object.
A way to ask for help. Someone working from home cannot just get up and go to the colleague who knows what to do. You need a number or a channel with written response times, otherwise small problems turn into hours of silent lost productivity.
What changes for those responsible for the data
Working off-site does not shift responsibility: the company remains the data controller even when data is being used on a kitchen table. In practice, three things need to be written down — which tools are allowed and which are not, how access from outside is handled, and what to do if a device is lost.
It is not a burdensome compliance task: it is one page of clear rules that avoids the most unpleasant discussion, the one that happens afterwards. We cover this in our page on practical GDPR, and the technical measures behind it are covered under cybersecurity.
A practical example
A services company with 18 employees, half of them working remotely 3 days a week: we replaced exposed remote desktop with a VPN using multi-factor authentication, centralised documents in a company cloud with department-based permissions, and enabled automatic backup. The result: the same flexibility, drastically reduced risk — and the office stopped acting as an improvised “internal help desk”, because we handle support for remote staff.
The secure remote working checklist
- Remote access only through VPNs or securely published portals;
- MFA on email, VPN and cloud services;
- Managed devices — company-owned or at least controlled, encrypted and updated;
- Centralised data with permissions and versioning, not scattered local copies;
- Backup including what is created off-site;
- Trained people — because phishing hits harder when people work alone.
If even one of these points is missing in your company, let’s talk: the assessment is free.