The modern workplace is not limited to the walls of a single building or even a campus.
Over the last few years, the traditional office has been replaced by individual kitchen tables, coffee shops, and home workspaces, from the hills above Oakland to the lofts near Jack London Square.
Honestly, this shift in working patterns has brought a sense of freedom that cannot be quantified and has opened many doors for individuals to design their days around their lives rather than the other way around.
Yes, it’s great to be able to work in your slippers.
Still, there is a quiet yet growing concern that keeps many operational managers up at night: data security outside the organization’s perimeter.
But how often do we actually stop to look at the physical gaps in our own homes?
For teams based in an office, there are clearly defined boundaries for what is considered secure.
However, for teams based at home, it’s far more complicated. You know, it’s easy to forget about the tangible world when we live entirely on Zoom.
While a large proportion of a team’s work may be conducted online, printed documentation such as papers, notebooks, whiteboards, and more will be kept in team members’ physical homes.
To take full advantage of working in slippers, we need to consider the physical aspects of information in the same way we would in an office and ensure that all physical aspects of work are also protected.
The vast majority of companies, including plenty of the tech, logistics, and professional service firms headquartered around Oakland, focus on locking down their digital information.
This could include setting up a Virtual Private Network (VPN), using Multi-Factor Authentication (MFA) to access information, or ensuring that any cloud storage used is encrypted to the highest possible level.
These are just a few examples, but it is clear that companies have to spend a lot of time and money trying to stay on top of security when it comes to information stored in digital format.
The problem, however, is that this information is only half the story.
Yes, information stored digitally is highly vulnerable, but the same cannot be said for information stored in a physical format.
Just because information has not been converted into a digital format does not mean it is any less valuable.
In fact, many organizations fail to realize just how vulnerable physical information can be, simply because they focus on stopping hackers from gaining access to information stored in digital format.
Have we become so focused on hackers that we forgot about the simple recycling bin?
It is not until information is left to be disposed of that the true extent of vulnerability becomes apparent.
People generally do not think about the information that is printed out and then thrown away.
And yet, it is in these discarded pieces of paper that the greatest risk may lie.
Just as there are typical life cycles of information in a corporate building, there are similar cycles in a home workspace.
For instance, printed information is distributed and then reviewed during meetings, such as video conferencing sessions. Sometimes notes are even jotted down on legal pads and then distributed to team members during meetings.
Most such printed information, including customer information, financial information, and even information about ongoing projects, is tossed in the recycling bin or the trash once it is no longer needed.
But in a typical corporate building, printed information no longer needed is tossed into a secure gray bin.
And that’s where the breakdown happens.
I have often found myself at my home office at midnight, gazing at a stack of printed-out strategy notes, wondering what the big deal would be if I threw them all in the regular trash.
Maybe no one would even care. Maybe they would. Between the lines of our digital lives, there is a lot of data that can easily reveal our information if it is not handled properly.
This is the biggest risk in today’s workplace and is far more threatening than a company engaging in industrial espionage. And that’s the point.
To address the many physical security gaps associated with working from home today, the organization must foster a culture that supports the mindset of data security found in an office, promoting new work habits and maintaining a work-from-home environment that supports these security habits.
While this does not mean that all work-from-home employees must be under constant surveillance and monitoring of all activity, it does not mean that extreme rules must be put in place either.
Extreme and unrealistic security measures can actually increase risk rather than reduce it, as employees are less likely to maintain a secure work environment when they constantly find ways to work around the rules in place to achieve their goals.
Thus, the organization must create new security work habits that are realistic, promote work-from-home security, and maintain a secure working environment simultaneously.
First, by bringing the clean desk policy home.
There is nothing like leaving a bunch of printed-out work papers scattered around your dining table, whether that’s in a Rockridge bungalow or a downtown Oakland high-rise, to freak out your family and other guests.
So long as you have a decent amount of drawer space at home, it is a simple matter to lock up any active work papers each evening and bring the chaos of work to an end.
It brings a bit of mental peace, too.
So, where do we draw the line between what is public and what is private?
Second, organizations must inform employees as to what type of information is considered sensitive in nature and thus must be kept secure.
Many people would not realize that certain everyday documents and pieces of information are, in fact, very sensitive.
This can include customer names and contact information, internal information about how a company operates, and financial information in general.
The final lifecycle problem for physical information is destruction.
Printed information that has served its purpose of review needs to be destroyed to prevent reuse by others.
Home shredders are typically not suitable for most remote workers, as they tend to clog, are limited to a few sheets at a time, and make simple strip cuts that can be easily reassembled.
It’s a frustrating mess.
For teams based in large business hubs, the best solution for the physical security of paper documents is to use available professional disposal services.
These companies have the equipment, experience, and a track record of responsible disposal of sensitive documents.
They can arrange for certified shredding services in Oakland to be carried out at a location near your team’s base. Oakland is a good example of what this looks like in practice, a business hub where a dedicated facility handles secure destruction for teams throughout the area, whether that means dropping documents off directly or scheduling a pickup. Most metro areas have something similar within reach.
Alternatively, the disposal company can collect the documents from your team’s location.
Once the documents have been destroyed, the team can be assured that all sensitive information has been destroyed and there is no risk of an accidental disclosure.
Protecting information and physical documents is the responsibility of everyone who works for a company, and, ultimately, protecting the organization means protecting its employees and customers.
Implementing security policies and procedures to protect information at employees’ home offices should not make employees feel as though they are being punished or that the procedures are unnecessary.
Employees will accept security responsibilities and adhere to security procedures if they understand the reasons behind the procedures.
But it requires a conscious shift.
Protecting an organization is about protecting its employees and its customers.
In enabling employees to work from home, organizations can enjoy the benefits of flexibility without compromising security.
As with so many things in life, developing good physical security habits at home is key to successful security.
With the right culture and a few simple practices, security can become second nature to every remote team, Oakland’s included.