How cloud security should change when your workforce is hybrid
Hybrid working is increasingly prevalent in the UK, as evidenced by the Office for National Statistics, which reported that 30% of employees were hybrid workers between January and March 2025, rising to 34% for full-time workers.
Hybrid working is increasingly prevalent in the UK, as evidenced by the Office for National Statistics, which reported that 30% of employees were hybrid workers between January and March 2025, rising to 34% for full-time workers.
This shift necessitates changes in cloud security strategies. Traditional models that assume work occurs within a single office perimeter are outdated. Instead, a more integrated approach is required, encompassing cloud, cybersecurity, and managed support.
Cloud Platform Risks and Security Responsibilities
Many businesses mistakenly focus solely on choosing a well-known cloud provider for security. However, the National Cyber Security Centre advises that service configuration and secure use are equally important. In a hybrid model, risks shift towards identity, access, device health, user behavior, and visibility.
Hybrid work environments require security strategies centered on identity. This involves implementing:
Multi-factor authentication Conditional access policies Least-privilege permissions Role-based access controls Sign-in monitoring and alerting
Access management needs to be precise, minimizing unnecessary access and ensuring temporary permissions are not left open-ended.
Traditional models that assume work occurs within a single office perimeter are outdated.
Hybrid setups reduce IT teams' direct control over hardware. Therefore, it is essential to track which devices access cloud systems, their encryption status, and adherence to security standards. Clear policies on trusted access, such as managed devices requirement for sensitive file access, should be established.
Security Policies Reflecting Real Behavior
Hybrid work results in employees frequently switching networks and using various applications, increasing security risks. Security policies should address:
Regulate external file sharing and manage link settings to prevent unrestricted access.
Unauthorized app usage due to slow approved tools should be monitored, with safe alternatives approved.
Enforce restrictions on session activities, such as downloads and device access.
Implement audit information, alerting, secure user management, and identity controls to detect unusual behavior.
Security awareness training should address specific hybrid work risks, such as phishing, shared device usage, and mobile device prompt approvals. Customized training can mitigate these risks effectively.
Ensuring business continuity during incidents is crucial. The NCSC emphasizes asset protection and resilience. Review backup strategies, recovery testing, incident response plans, and response speed to manage distributed workforce challenges effectively.
Cloud security in hybrid work settings requires a shift from technical background layers to integral operational components. This involves strict identity controls, clear device standards, intelligent access management, and realistic user behavior assessments. Balancing convenience with security is key as hybrid work becomes the norm in the UK.
Based on reporting by TechBullion.
