Cybersecurity / Source date:

Home Network Security: The New Corporate Perimeter

Unmanaged routers and shared devices became part of the attack surface overnight.

Illustration of a work laptop used separately from household devices in a home office; its protection cannot be inferred from the scene.

The phrase of the season is that the home network is the new corporate perimeter. It is a good line and it points security teams in exactly the wrong direction, because a perimeter is something you own, configure and monitor, and you own none of the several thousand networks your staff are currently working from. Four months of trying has made the point. Campaigns to get employees to change router passwords produce a response rate somewhere between a quarter and a half. Nobody updates router firmware. A meaningful number of people cannot log into their own router because the internet provider administers it remotely and the admin page is locked. Any control that depends on the household being configured correctly is a control you cannot verify, and an unverifiable control is a hope. The workable position is the opposite one: treat every home network as hostile, and make the device able to defend itself without help from whatever it is plugged into.

What is actually on the network, and what actually goes wrong

A typical home network holds a provider-supplied router with default administrative credentials and firmware from two years ago, a smart television, a games console, a printer, several phones, a child's laptop with games of uncertain origin, and, in flats and shared villas, devices belonging to people your employee has never met. The imagined threat is that an attacker compromises that router and pivots into the corporate network. It happens, and it is rare, and it is not where the losses are. The real exposures are duller. A corporate laptop sitting on a flat home network with file sharing enabled is directly reachable by an infected household device. Router settings can be altered to point DNS at a server the attacker controls, which quietly breaks name resolution security for everything on the network. Printers and shared drives invite people to move documents off the managed device. And the largest category by far is not the network at all: it is a device that has not received a patch since March because the update service it depends on only works inside the office. That last one deserves emphasis, because it is the genuine security consequence of remote working and it is invisible. Organisations running internal patch distribution, internal antivirus update servers and internal management infrastructure have fleets that silently fell out of compliance the week everybody went home, and many still have not noticed.

Make the endpoint self-sufficient

The target is a device that is fully protected while connected to a network you would not trust with a guest password. That means full disk encryption, verified centrally rather than assumed. A host firewall that blocks inbound connections on every network profile, not just public ones, which alone removes household lateral movement. Patching that works over the internet without a tunnel, for the operating system and for the browsers, document readers and conferencing clients that are now the main attack surface. An endpoint detection agent managed from the cloud so it reports whether or not the user connects to the corporate network. DNS filtering on the device rather than at the office gateway. Local administrator rights removed, with a documented elevation path. And backup that runs to a cloud target rather than to a file server behind the VPN. None of that is new advice. What is new is that every item has moved from good practice to load-bearing, because there is no longer a network layer behind it. For unmanaged personal devices, do not attempt to secure the device. Change what it can reach: browser-based access to specific applications, no local data, no synchronisation client, session controls that prevent download. The distinction between managed and unmanaged has to be enforced technically, because as a policy it is simply ignored.

What to tell employees, and what to expect from telling them

There is still value in household advice, provided you accept its limits and keep it to five things people will actually do: change the router administrative password if you can, apply the firmware update if the interface offers one, use a strong wireless passphrase, put televisions and smart devices on the guest network, and never let anyone else use the work computer. Print it on one page, send it once, and design nothing that depends on it. Partial compliance is the realistic outcome, and the endpoint controls above are what make partial compliance acceptable. The question worth asking internally is different: what would we do if a household member's device were compromised tomorrow? If the answer involves any assumption about the home network, it is not an answer.

Ask for endpoint evidence outside the officeQualitative evidence checks from the article. Test the actual configuration; a VPN, cloud agent or browser restriction alone does not guarantee device security.
ControlEvidence to check
Updates and check-inA remote device receives updates and reports its state.
EncryptionCentral confirmation and an authorised recovery-key process.
Host network rulesInbound rules tested on the profiles the device actually uses.
Backup and restoreA remote backup completes and a restoration is tested.
Access classManaged and unmanaged devices receive the intended access.

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Practical Guidance for Remote Endpoint Security Review

  • Audit patch compliance for devices that have not touched the corporate network since March. This is the highest-value hour of work available, and the result is usually worse than expected.
  • Move patching, endpoint protection and device management to internet-facing delivery. Anything that requires a tunnel to function stops functioning for the people who need it most.
  • Block inbound connections on all network profiles at the host firewall. One setting, deployed centrally, that neutralises most household lateral movement.
  • Verify encryption and recovery keys centrally rather than trusting the build. Lost and unrecoverable devices are a much larger problem in a distributed workforce.
  • Remove local administrator rights and publish an elevation path. Home-working users install more software, from worse sources, with less supervision.
  • Put DNS filtering on the endpoint. The office gateway is no longer in the path, and DNS-layer blocking is the cheapest remaining control against malicious destinations.
  • Treat unmanaged personal devices as a separate access class, enforced technically. Browser access to named applications, no local data, no sync client.
  • Fix backup for devices that never come back to the office. A laptop that has not backed up since February is a business continuity problem, not just a security one.

The Regional Angle

Four specifics shape how this plays out here. Start with the routers, because most household hardening advice does not apply in this market. Home internet is overwhelmingly delivered on operator-supplied equipment that the operator manages remotely, frequently bundled with television service so it cannot simply be replaced, and often with the administrative interface restricted. Employees are not being lazy when they fail to update the firmware; they cannot. That has two consequences worth stating plainly: the household network is administered by a third party you have no relationship with, and any security programme built on employees reconfiguring their routers will fail here more completely than elsewhere. Spend the effort on the endpoint. Second, watch the expiry dates on your regulatory permissions. Several sector supervisors in the region allowed home working for regulated activity in the spring on a temporary and conditional basis, with conditions attached: virtual desktops rather than local data, no printing, restricted call recording arrangements, periodic attestation, and a review date. Those approvals were written for an emergency lasting weeks and some are now reaching their review points. If your operation depends on one, get the extension in writing, confirm you are actually meeting the conditions, and be able to produce evidence, because an expired permission is worse than never having asked for one. Third, close the gap in your offboarding process. When employment ends here, it frequently ends quickly and involves the person leaving the country, and this year that has happened at volume. The final settlement, visa cancellation and clearance sequence in most regional groups was designed around handing in a desk key, not around recovering a laptop from an apartment in another emirate or from someone already on a flight. Add asset recovery to the clearance checklist with a named owner, hold the device return as a condition of final clearance where the law and the contract allow, and make sure remote wipe and account disablement are one procedure rather than two. Fourth, plan device logistics across the group rather than per country. A distributed workforce spread across several GCC entities makes every hardware replacement a cross-border shipment with customs paperwork, and devices sent to employees who travelled home to South Asia or Europe may be difficult and expensive to retrieve. Keep a small buffer stock in each country of operation, record which serial number is in which country, and think carefully before shipping a company asset outside the GCC at all.

The objection worth taking seriously

The strongest objection is about who pays. Advising employees to buy a better router, upgrade their internet package, use a separate room and keep the household off the work machine is advice with a price attached, and it lands on people who are already funding the electricity, the connectivity and the furniture that the office used to provide. Security programmes that quietly transfer cost to staff while reporting improved posture are not achieving what they claim; they are moving an expense off the balance sheet. The second objection is about the framing itself. "The home network is the new perimeter" is a marketing line, and a whole product category has appeared behind it: home security appliances, consumer router management, household monitoring agents. The evidence that corporate breaches are originating from compromised domestic routers remains thin, while the evidence that they originate from phishing, unpatched internet-facing systems and stolen credentials is overwhelming. A security team that spends this year on home networks has chosen the interesting risk over the likely one. Both objections point the same way. Do not try to own the household. Own the device, own the identity, pay for the connectivity and equipment you require people to use, and accept that the network in between is somebody else's problem and always will be. That is a cheaper programme, a more honest one, and it is the only version that can actually be verified.

Common Questions

Should we require employees to use a separate work network at home?

Recommend it, do not require it. You cannot verify it, and making an unverifiable requirement creates a compliance fiction rather than a control.

Is a VPN enough to protect a device on an untrusted network?

No. A tunnel protects traffic in transit; it does nothing about a device reachable from an infected machine on the same subnet, or about a device three months behind on patches.

What about family members using the work laptop?

Prohibit it clearly, remove local administrator rights so it is harder, and offer an alternative if the household genuinely has one computer. A rule with no alternative is broken quietly.

What should we expect over the next twelve months?

Expect hardware refresh cycles to be reshaped around devices that never see an office, with cloud-managed builds becoming the default rather than the exception. Expect regulators to convert this spring's temporary home-working permissions into permanent conditional frameworks, with explicit control requirements attached. Expect a wave of findings in next year's audits about patch compliance during 2020. And expect the phrase "the home network is the new perimeter" to persist in marketing long after security teams have concluded that the device, not the network, is the thing they can actually defend.


Remote Endpoint Security Review — we make the device self-sufficient on a network you will never control, then prove it with patch, encryption and check-in evidence rather than assurances.

Continue reading

Talk to OPS

Start with the operating problem.