Vendor-neutral guide · 8 min read
A people-centred digital strategy for hybrid working
Shape of the topic
In short
In the post-pandemic corporate world, the hybrid model is the norm, and one survey suggests nearly 98% of workers would like to work remotely at least some of the time for the rest of their career. Making that model work is not simply a matter of letting people take a laptop home; it demands new cybersecurity training, effective remote IT support and access, and IT asset management that keeps infrastructure fit for purpose. This guide sets out how to place employee needs at the centre of hybrid policy and technology decisions.
Key takeaways
- Nearly 98% of workers in one survey want to work remotely at least some of the time, so hybrid working policy needs to be a permanent fixture, not a temporary accommodation.
- Increased remote device use raises cybersecurity risk, particularly around careless handling of sensitive information and phishing attempts aimed at remote staff.
- Secure remote access lets technicians diagnose and resolve device issues faster, which matters because outages are especially disruptive for remote employees.
- IT asset management automates the otherwise mammoth task of tracking device location, usage and lifecycle across a hybrid estate.
- Placing employee needs at the core of hybrid policy and infrastructure is what future-proofs the model for the organisation as a whole.
Hybrid working is now the expectation, not the exception
Though some employers appear keen to draw their workforce back into the office, many potential employees now expect flexible working as a standard benefit. One report suggests nearly 98% of workers would like to work remotely at least some of the time for the rest of their career. The question for businesses is how to ensure they have the right set-up and culture to support a successful hybrid working model.
Although hybrid working is sometimes viewed as employees simply taking their laptops home, the model brings countless new considerations and practices that must be introduced to ensure it helps, rather than hinders, both employee and business performance.
Cybersecurity training and policy for a dispersed workforce
Increased time spent using devices remotely can lead to heightened cybersecurity risks. One significant risk that business leaders should not overlook is how employees working remotely handle data: while working in a public setting, an employee might accidentally leave sensitive or confidential information visible to members of the public, as one embarrassing example involving a UK Cabinet Minister illustrated. Employees working remotely are also more susceptible to phishing scams, which may take the form of requests from colleagues or customers for passwords, file access or other sensitive data.
Robust data security arrangements are a legal obligation, and dedicated time spent training employees should inform organisational priorities. Understanding sector-specific requirements shapes how that training is pursued, since statutory requirements for education organisations, for example, may differ from those for hospitality businesses. Sector bodies, business networks and even technology solution providers run webinars and accredited cybersecurity training tailored to an organisation's needs.
- Train staff on how to handle sensitive information visible on screens in public settings
- Cover phishing recognition specifically for remote-working scenarios
- Align training content with sector-specific statutory requirements
- Consider that some business insurers offer enhanced benefits to policyholders who invest in this training
Effective remote IT support and access
Hybrid working can often mean employees need to access servers or devices remotely to collaborate effectively or to provide support to colleagues by taking control of their device. Secure remote access is extremely helpful, particularly for troubleshooting when IT issues arise: technicians can take control of devices remotely, facilitating faster diagnoses and quick resolutions. For a remote employee, an outage or device issue can be truly debilitating, so reducing the amount of time lost to such incidents is critical both for balancing workloads and for optimising efficiency across the organisation.
A hybrid working model relies on efficient and smooth-running infrastructure and networks. This is a constant challenge that all hybrid employers must face, working continuously to improve efficiency and allow employees to keep working together no matter where they are.
Using IT asset management to keep infrastructure fit for purpose
Constantly auditing and keeping track of the status of devices and networks, particularly for larger companies, can be a mammoth task. An IT asset management solution can automate this process by monitoring device locations, usage and life cycles, as well as measuring what solutions or processes work well or could be improved. These solutions can collect data on inventory, applications, user behaviours and even energy usage.
From this informed perspective, companies can set out on a path to improvement and efficiency by introducing policies that help maximise their technology investment and ensure infrastructure remains fit for purpose and meets all employees' needs. Supporting employees to work efficiently and easily, regardless of location, means building an IT infrastructure that flexes to the organisation's needs and supports staff when issues arise.
- Monitor device location, usage and lifecycle centrally rather than relying on manual audits
- Track inventory, applications and user behaviour to spot underused or overburdened assets
- Feed findings back into policy so the infrastructure keeps matching real employee needs
Putting people at the centre of the model
Security and the safety of data, whether belonging to customers, colleagues or the company more generally, will need to be considered in a new way to ensure new threats are mitigated as the hybrid model matures. Placing employees' needs at the core of hybrid working policies and infrastructure is critical to ensuring the model works for everyone, while also future-proofing the business against the next shift in working practices.
Best-practice checklist
1. Commission sector-specific cybersecurity training
Work with sector bodies, business networks or technology providers to deliver training tailored to your organisation's statutory requirements and risk profile.
2. Write a policy for handling sensitive information in public
Give remote and hybrid staff clear guidance on screen privacy, device locking and secure workspaces when working outside the office.
3. Establish a secure remote access protocol for support
Define how technicians gain consent-based control of an employee's device for troubleshooting, and how quickly they are expected to respond to an outage.
4. Deploy IT asset management across the hybrid estate
Automate tracking of device location, usage and lifecycle rather than relying on periodic manual audits that struggle to keep pace with a dispersed workforce.
5. Review infrastructure against employee feedback
Use asset management data and direct employee feedback together to decide what to upgrade, retire or repurpose.
6. Revisit data security policy as the model evolves
Treat hybrid security as an ongoing programme rather than a one-off project, since new tools and new threats will keep emerging.
Common pitfalls
- Treating hybrid working as simply letting staff take a laptop home, without new policy or infrastructure to match
- Leaving cybersecurity training generic rather than tailored to sector-specific statutory requirements
- Underestimating how debilitating a device outage is for an employee with no on-site IT team nearby
- Relying on manual audits to track a hybrid device estate instead of automated asset management
- Designing hybrid policy around infrastructure convenience rather than employees' actual working needs
What to measure
| Cybersecurity training completion | Track proportion of remote staff trained per sector requirement |
|---|---|
| Phishing incident rate among remote staff | Should fall as targeted training is delivered |
| Remote device resolution time | Compare before and after enabling secure remote access |
| Asset inventory accuracy | Target close to 100% of active devices tracked automatically |
| Employee satisfaction with hybrid infrastructure | Survey score, watch trend over successive quarters |
Select any column heading to sort.
Frequently asked questions
- Why does hybrid working increase cybersecurity risk?
- Employees using devices remotely, including in public settings, are more likely to expose sensitive information on screen or fall for phishing attempts disguised as requests from colleagues or customers. Robust data security training and policy, tailored to sector-specific statutory requirements, are needed to manage this increased exposure.
- How does secure remote access help hybrid IT support?
- Secure remote access lets technicians take control of a remote employee's device to diagnose and resolve issues without a site visit, which speeds up resolution considerably. This matters because an outage is especially disruptive for an employee who has no on-site IT team to turn to.
- What role does IT asset management play in a hybrid strategy?
- IT asset management automates the tracking of device location, usage and lifecycle across a hybrid estate, which would otherwise be a mammoth manual task. It also collects data on inventory and usage patterns that inform policy decisions about upgrades, retirements and infrastructure investment.
- What does a people-centred hybrid digital strategy actually mean in practice?
- It means designing cybersecurity training, remote support and infrastructure investment around what employees actually need to work efficiently and safely, wherever they are, rather than retrofitting policy around whatever technology happens to already be in place.
Sources
Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.
- A people-centred digital strategy in the context of hybrid working
Interface Magazine
Original article by Al Kingsley MBE, Interface Magazine, July 2024.
- Guidance on Data Protection and Working from Home
Information Commissioner's Office (ICO)
UK regulator guidance on organisational obligations for protecting personal data, relevant to remote and hybrid working.
- Guide to Enterprise Telework, Remote Access and BYOD Security (SP 800-46 Rev. 2)
NIST
Authoritative guidance on securing remote access and devices used outside a managed office network.
- Home and Remote Working Guidance
National Cyber Security Centre (NCSC)
UK national guidance on the cybersecurity risks and mitigations relevant to remote and hybrid staff.
Putting it into practice
This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.
More best-practice guides
Cost of missed messages
A practical, evidence-led guide to why internal messages get missed in remote and hybrid teams, the operational cost, and how to fix message delivery.
Attack surface management costs
A vendor-neutral guide to sizing attack surface management spend against risk, covering asset visibility, incident readiness, remote access and staff awareness.
IT professional development
A practical, vendor-neutral guide to planning IT professional development: setting goals, building communication, leadership and project skills, and choosing how to learn.