Remote work extends the office boundary to home routers, personal computers, shared spaces and cloud services. A VPN protects a network path, but weak accounts, missing patches, exposed Remote Desktop or careless file sharing can defeat the value of that encrypted tunnel.
Know which VPN you are using
A personal VPN protects public traffic between a device and its service. A corporate VPN or zero-trust gateway grants controlled access to internal resources. Never use a personal tool to bypass company policy or enter corporate credentials into an unapproved client.
Seven checks before work begins
Before opening email, repositories or admin consoles, confirm Windows updates, firewall, disk encryption, the expected VPN route and MFA on important accounts.
- Install clients and updates only from official sources
- Use a strong router password and current firmware
- Disable unnecessary file and printer sharing
- Require Windows Hello or a password after lock
- Update browsers and office applications
- Keep sensitive files in approved storage
- Lock the screen whenever you step away
Do not expose Remote Desktop directly
Opening RDP to the internet invites password attacks and exploit scanning. Place it behind an approved corporate VPN or gateway, then add Network Level Authentication, MFA, source restrictions and audit logs. Disable RDP when it is not needed.
Prevent meeting and sharing leaks
Close unrelated windows and notifications before screen sharing. Confirm whether you share one window or the entire desktop. Check file-link scope and expiry. Meeting invitations, QR codes and “sign in again” pages are common phishing lures.
Isolate first when something looks wrong
For an unknown sign-in, repeated MFA prompts, certificate warning or suspicious file change, disconnect from the network and contact the administrator. Do not approve MFA fatigue requests. Preserve timestamps and messages, then revoke sessions and investigate from a trusted device.
- Keep the error evidence
- Reset credentials from a trusted device
- Review sign-in history and mail-forwarding rules
- Use the organization's incident process
Turn security into a repeatable routine
A consistent start-of-day checklist outperforms improvised cleanup. Teams should also rehearse account revocation, lost-device and connection-failure procedures.
Windows download · Security and privacy · Service status
Video reference
This original checklist builds on Computerphile's public explanation of VPNs and remote work, then adds practical Windows controls: VPN & Remote Working — Computerphile.
