Security for remote teams and shared devices

Security for remote teams and shared devices

Membergate Support -

Most membership businesses run from kitchen tables, spare bedrooms, cafes and airport lounges. Your assistant answers support tickets on the family laptop, your video editor works from a shared studio, your co-host checks the forum on her phone between meetings and you process refunds from a hotel room. Nobody sits behind an office firewall, and no IT department checks whether devices are up to date.

That can work perfectly well, as long as the team agrees on some basic rules. The devices your team uses to log in are part of your security, just as much as passwords and hosting. A laptop that anyone in the household can open, with the membership admin logged in and a member export in the downloads folder, undoes every other precaution you have taken.

The basics every work device needs

Whether a device belongs to the business or to the team member, set a minimum standard for anything used to log in to your systems:

  • A screen lock with a PIN, password or fingerprint, set to lock automatically after a few minutes.
  • Encryption switched on. Most modern computers and phones can encrypt their storage so a stolen device cannot be read without the login. It is often a single setting, and sometimes on by default.
  • Automatic updates for the operating system and browser.
  • Security software appropriate to the device. The protection built into modern operating systems is often enough, provided it is switched on and updated.
  • Find-my-device and remote wipe enabled, so a lost device can be located or erased.

Shared and family computers

Many small teams work on devices other people also use. If a computer is shared with family or housemates, the team member should have their own user account on it with its own password. Their work browser, saved logins and downloaded files then stay out of reach of a child doing homework or a partner checking email.

Within the browser, a separate browser profile for work keeps business bookmarks, extensions and logins apart from personal ones. Keep extensions in the work profile to a minimum. Extensions can often read the pages you visit, including your admin area, so install only well-known ones you actually need.

Never log in to your admin area on a truly public computer, such as a hotel business center or library machine. You cannot know what is installed on it.

Working on public networks

Cafe and hotel wireless networks are convenient, and because most sites now use secure connections, traffic between your browser and your site is encrypted. Risks remain, including fake networks with official-sounding names and people nearby reading your screen. Sensible habits include:

  • Confirm the network name with staff before connecting.
  • Check the address bar shows a secure connection before logging in anywhere.
  • Use your phone’s hotspot for sensitive tasks such as payout changes, refunds or member exports.
  • Use a privacy screen filter if you often work in public.

Some teams also use a virtual private network, a service that routes traffic through an encrypted tunnel. It can add protection on untrusted networks, but it does not replace the other basics.

Member data stays in your systems, not on laptops

The biggest risk on a remote team’s devices is often member data that was downloaded and forgotten. Agree that:

  • Member lists are viewed inside your membership platform or a shared drive with access controls, not exported to personal devices.
  • If an export is unavoidable, it is deleted, including from the downloads folder and trash, as soon as the task is done.
  • Screenshots showing member details are not kept in phone photo libraries, which often sync to personal cloud accounts.
  • Members are discussed in business chat tools, not personal messaging apps.

On video calls, close windows containing member data before sharing your screen, and silence notifications so private messages do not pop up for everyone to see.

A worked example: a podcasting academy’s device policy

A hypothetical podcasting academy is run by four people in three countries. After an editor’s laptop is stolen from a car, the owner, Kenji, writes a one-page policy that everyone agrees to:

Any device you use for academy work needs a screen lock that activates within five minutes, encryption switched on, automatic updates enabled and find-my-device turned on. On shared computers, use your own user account and a separate work browser profile. Do not log in to the admin area on public computers. Use your phone hotspot rather than public wireless networks for payments, refunds and exports. Do not save member exports to your device; if you must download one, delete it the same day. If a device is lost or stolen, tell Kenji within the hour so we can sign it out of every account and change passwords. When you leave the team, you delete business files from your devices and confirm this in writing.

Kenji then books a short call with each person to check the settings on their devices together. Like everything else involved in managing a small remote team, it is framed as protecting students rather than auditing staff, and nobody objects.

When a device goes missing

  1. Report it immediately. Speed matters far more than blame.
  2. Use the device’s locate or remote wipe feature.
  3. Sign the device out of every business account, and change passwords for any account that was logged in.
  4. Remove it from two-factor authentication settings and register a replacement.
  5. Work out what member data was on it and whether you need to follow your incident plan.

The same steps apply when someone leaves the team, as part of offboarding staff and contractors securely.

Your next steps

  1. Write a one-page device policy based on the example above.
  2. Check screen locks, encryption and updates on every device used for work, starting with your own.
  3. Set up separate user accounts and work browser profiles on shared computers.
  4. Remove old member exports from laptops, downloads folders and phone photo libraries.
  5. Agree the lost-device steps and who to tell.

0 Comments

Comments are reviewed before they appear.