A secure home office is a workspace at a residential or remote location that connects a staff member to company systems with the same protections they would expect in the office - hardened device, strong identity, encrypted connection, and protected data. For most Geelong small businesses it is now the default way of working at least part of the week, which means the home office is now part of the business perimeter. This guide covers how to set one up properly in 2026: device, connection, identity, data, physical security, and the policy basics.
Hybrid work is standard now. Staff split the week between the office in Geelong, the kitchen table in Ocean Grove, and the occasional cafe in Torquay. What has not kept up is the security on the home side. The office has a firewall, a managed network, and someone watching the logs. The home usually has a consumer WiFi router and a laptop the family also uses to stream movies. That gap is where most small-business breaches now start, and it is the gap this guide closes.
Why home offices are a soft target
Home offices get overlooked because they feel safe. They are not. A typical home setup has four problems the office does not:
- Shared devices. A work laptop that a teenager also uses for gaming is no longer a work laptop. Personal software, browser extensions, and downloads all create risk.
- Weak WiFi. Many homes still run the router the ISP shipped years ago, with the default admin password and WPA2 on a password the whole street knows.
- No corporate firewall. The office network filters traffic and blocks known-bad destinations. The home network does not.
- Family and IoT on the same network. Smart TVs, baby monitors, and phones share the WiFi with the work laptop, and any one of them can be compromised and used as a foothold.
None of this requires a big budget to fix. It requires a few deliberate decisions, and that is what the rest of this guide walks through.
Secure the device
The device is the first line of defence. If it is compromised, every other control downstream is at risk. Wherever possible, give staff a separate work device that only they use and only for work. The cost of a second laptop is small compared with the cost of a breach.
- OS updates and patching. Turn on automatic updates for Windows, macOS, and the browser. Most attacks exploit holes that already have a patch - unpatched machines are the low-hanging fruit.
- Antivirus or EDR. At minimum, run the built-in Defender on Windows or a reputable tool on macOS. For any business with more than a handful of staff, managed endpoint detection and response (EDR) is worth the money because it catches behaviour, not just known signatures.
- Full-disk encryption. Switch on BitLocker on Windows or FileVault on macOS. If a laptop is left on a train, encryption means the data is unreadable without the key.
- Screen lock. Set a short idle timeout - two to five minutes - and require a password or biometric to unlock.
- No personal software on work devices. No games, no random utilities, no browser toolbars. If staff want a personal machine, they should have one.
Secure the connection
The home network is the next layer. A few changes to the router make a real difference and cost nothing but half an hour.
- Change the router's default admin password to something strong and unique.
- Use WPA3 if the router supports it; fall back to WPA2 only if you must.
- Set a strong WiFi pre-shared key, and treat it like any other company credential.
- Put family devices, guests, and IoT on a separate guest network so they cannot reach the work laptop.
On the question of VPN versus modern access: a VPN creates an encrypted tunnel into the office network, which made sense when files lived on a server there. In 2026 most Geelong businesses run on Microsoft 365, so the safer and simpler model is identity-based, zero-trust access. Staff log in with MFA and reach cloud apps directly over the internet; there is no office network to tunnel into. Prefer cloud access over a VPN wherever you can, and only use a VPN for the older on-premise apps that genuinely need it.
If your home WiFi itself needs an upgrade, our guide to choosing a WiFi system for your business covers what to look for.
Lock down identity
Identity is now the real perimeter. If an attacker has someone's login, they have the keys to the kingdom regardless of where they are sitting.
- MFA on every work account. Email, accounting, CRM, admin consoles - all of it. Use an authenticator app or a security key rather than SMS, which can be intercepted via SIM-swap attacks.
- Password manager. Stop reusing passwords. A business password manager generates and stores a unique strong password for every site, so a breach on one service does not cascade.
- Conditional access in Microsoft 365. Block logins from unexpected countries, require a compliant device for sensitive apps, and challenge risky sign-ins with extra MFA. These policies are included in M365 Business Premium and pay for themselves the first time they stop a login from overseas.
If you are not sure where your M365 tenant stands, our Microsoft 365 services cover the setup, licensing, and security configuration that makes identity-based access actually work.
Protect the data
Where data lives matters more than how it is encrypted in transit. A file on a local desktop is a file you can lose; a file in SharePoint is a file you can recover, audit, and share safely.
- Keep working files in Microsoft 365 - SharePoint for team files, OneDrive for personal working files - not on the local desktop or a USB stick.
- Turn on retention and versioning so deleted or overwritten files can be recovered without a helpdesk ticket.
- Add a cloud backup with its own retention. Microsoft keeps versions, but a separate backup protects you against ransomware that encrypts the live copy and the recycle bin.
- Be careful with printing. Shred anything sensitive, and avoid leaving client details on the kitchen bench.
The rule of thumb: if the laptop was stolen tomorrow, you should be able to wipe it remotely and lose no company data. That is only true when the data lives in the cloud, not on the device.
Physical security
Digital controls are wasted if someone can read the screen over your shoulder. A few physical habits close the gap:
- Lock the screen every time you step away, even at home. A curious child or a visiting friend should never see a client file.
- Work in a room you can close, and store devices out of sight when not in use.
- Do not leave sensitive information on whiteboards or sticky notes - photograph and store it properly, or do not write it down at all.
- Be careful on trains and in cafes. Use a privacy screen, sit with your back to a wall, and avoid taking sensitive calls where others can hear.
A few policy basics
You do not need a 40-page remote-work policy. A short, clear document that staff actually read is worth more. Cover the essentials:
- Who provides the device, and what it can and cannot be used for.
- Which apps and services are approved for company data.
- How to report a lost device or a suspicious email, and to whom.
- Where files must be stored, and what must not leave the cloud.
Keep it brief, review it once a year, and make sure every new starter sees it in their first week.
Getting help
Securing a home office is not a single product - it is a small set of changes across device, identity, connection, and data. For most Geelong small businesses it makes sense to do it once, properly, as a one-off project rather than piecemeal.
Better Networks runs exactly that kind of project for businesses across Geelong, the Bellarine, and the Surf Coast. We harden devices, configure MFA and conditional access, sort out home WiFi and connectivity, and put the right backup and data-handling rules in place so hybrid work is not your weak spot.
Start with our cyber security services for the security side, or our network installation and upgrades page if the home or office network itself needs work. When you are ready to scope it out, get in touch and we will put together a plan for your team.
