Device and remote work security awareness in Scotland

Help people work safely wherever the day takes them

Laptops, phones and tablets travel between offices, homes, client sites and public places. Stratiis helps Scottish organisations give staff clear device guidance, supported access and a simple route for reporting loss or unusual behaviour. The aim is secure, workable remote access that fits real jobs.

What does safe remote working involve?

Safe remote working combines a managed device, appropriate sign-in and access controls, current software, approved tools and everyday habits such as locking the screen and protecting information from view. Staff also need to know how to get help and report a lost device quickly. The exact controls depend on the work, device and information being used.

Why it matters

Protect work beyond the office

A clear device approach helps staff stay productive while limiting preventable exposure.

Safer access

People know which device and sign-in route to use for business systems.

Less data exposure

Screens, files and local copies receive protection suited to the work.

Faster response

Loss, theft and suspicious behaviour have a clear reporting route.

More consistent support

Device settings, updates and ownership can be reviewed centrally.

Device plan

What should a remote work device plan include?

Review the device, user, work location and support route together.

Area Question to answer Useful output
Device inventory Which laptops, phones and tablets access business services? Owned device list and status.
Ownership Is each device company-owned, shared or personally owned? Clear handling rules for each type.
Configuration Are screen lock, encryption and suitable protection enabled? Baseline device settings.
Updates How are operating systems and apps kept current? Update and support process.
Identity How does the user sign in, and is MFA in place where appropriate? Approved access route.
Data Where should work files be stored and shared? Approved locations and sync rules.
Remote access Which services can be reached away from the office? Access and network plan.
Incident response Who receives a report of loss, theft or unusual behaviour? Immediate reporting steps.

The NCSC device guidance also emphasises practical advice for users alongside technical device controls.

Practical starting points

What should staff do differently away from the office?

Use short, realistic guidance for the places and devices your team actually uses.

Lock the screen

Lock a laptop, phone or tablet whenever it is unattended, even for a short time.

Protect what others can see

Be mindful of conversations, screens and documents in shared or public spaces.

Use approved tools

Keep business files and messages in supported apps and accounts.

Install updates

Apply device and app updates through the agreed process; report repeated failures.

Check connectivity

Use the organisation’s approved remote access method when required and avoid assuming every network is trusted.

Report concerns early

Tell the support team promptly about lost devices, unexpected prompts or unusual behaviour.

How support starts

Build a supported remote work routine

Test the guidance with a normal workday, a device change and a lost-device scenario.

1

Discover

Identify users, devices, locations, business apps and current support gaps.

2

Design

Agree the device baseline, access rules, ownership and reporting route.

3

Roll out

Configure devices and explain the practical steps to staff.

4

Review

Check updates, access, incidents and user feedback as work changes.

Field & Hybrid Working connects device guidance to connectivity and collaboration across locations.

People and safeguards

Make ownership and support clear

Staff need simple instructions; the organisation needs controls it can maintain.

What Stratiis can help plan

Device configuration and management.

Remote access and sign-in support.

User guidance for common situations.

Loss reporting and response steps.

What your team owns

Approval for who works remotely and with which data.

Rules for personal, shared and company devices.

Prompt reporting of loss or suspected compromise.

Updates when people change role or leave.

Device choices

Which controls fit different devices?

Apply controls proportionate to the device, service and information.

Situation Practical consideration What to plan
Company laptop The organisation can configure and support the full device. Managed setup, encryption, updates and recovery.
Company phone or tablet Mobile apps and business data need consistent settings. Enrolment, screen lock and lost-device action.
Personal device Owner privacy and management rights need clear boundaries. Approved access model and written expectations.
Shared device Multiple users can blur ownership and leave local data behind. Named sign-in, session handling and review.
Public or borrowed device The organisation may not control its security or retained data. Avoid sensitive access unless an approved route exists.

Mobile Device Management can support consistent settings and device lifecycle processes. The NCSC’s BYOD guidance explains the extra considerations for personally owned devices.

When something goes wrong

Give staff a simple first response

Quick, accurate reporting helps the right team assess access and protect business information.

Device lost or stolen

Report it immediately through the agreed route and provide the device and account details.

Unexpected sign-in prompt

Do not approve it; report it and follow the account response process.

Suspicious device behaviour

Stop the affected activity and contact support through a trusted channel.

Work data shared in error

Report what was shared, with whom and when, so the impact can be assessed.

Monitoring and Response connects these reports to investigation and action.

Related Stratiis services

Connect devices to the wider working model

Secure remote work depends on device management, access and user guidance working together.

Common questions

Devices and Remote Work FAQs

Answers to common questions about business devices outside the office.

How can staff work safely from home or on site?

Use an approved device and access route, keep software current, lock the screen when unattended and store work in approved services. Follow the organisation’s guidance for the information being handled.

Should every remote worker use a company device?

That depends on the work and risk. A company device offers more direct management; a personal device may be allowed when the organisation has agreed controls, support and privacy boundaries.

What should someone do if a laptop or phone is lost?

Report it immediately using a trusted support route. Give the device, account and last known location details so access and business data can be assessed.

Is public Wi-Fi safe for work?

Treat public networks as untrusted. Use the organisation’s approved access method and avoid sensitive work on an unmanaged or borrowed device.

Why do device updates matter?

Updates address known weaknesses and keep apps supported. Staff should follow the agreed update process and report a device that cannot update.

Does MFA protect a lost device?

MFA helps protect account sign-ins, but device lock, encryption, access controls and timely reporting also matter. The response team should assess the accounts and data reachable from the device.

Can Stratiis manage personal devices?

The available controls depend on the agreed device policy and platform. The business should define what may be managed, what remains private and how access ends when someone leaves.

What should training cover for remote workers?

Use realistic examples: screen privacy, secure sign-in, approved apps, safe sharing, updates, device loss and how to reach support. Refresh the guidance as tools and working patterns change.

Talk to Stratiis

Support secure work wherever your team is

Tell us which devices and locations your team relies on. We can help review controls, access and practical guidance.

Contact Stratiis →