Legal & compliance centre

HLD Group

Remote work security policy

Security requirements for working outside offices.

Last updated: 24 July 2026

Version 1.0 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines the security requirements for working outside HLD Group premises, including from home and while travelling. Remote work expands the environments in which company data is handled, and this policy ensures protection is maintained wherever work is done.

2. Scope

This policy applies to all personnel who access HLD Group systems or data from outside company premises, and to the devices, networks, and physical environments they use.

3. Device and connection security

  • Only approved, managed, and encrypted devices are used to access company and customer data
  • Connections use MFA and controlled, encrypted access paths
  • Home and public networks are not trusted; sensitive work is not conducted over unsecured public networks without protection
  • Endpoint protection and current patching are maintained under the Patch and Asset policies

4. Physical and environmental security

  • Devices are secured against theft and are locked when unattended
  • Sensitive information is protected from being overlooked in public spaces
  • Confidential conversations are held where they cannot be overheard
  • Printed sensitive material is avoided and, if produced, protected and securely destroyed

5. Data handling when remote

Company and customer data is stored only in approved locations and services, not on personal devices or unapproved cloud storage. Data classification and handling rules apply identically to remote work, and removable media use follows the Asset Management Policy.

6. Travel and higher-risk locations

Additional precautions apply when travelling, particularly to higher-risk jurisdictions, including minimising data carried, using loaner devices where warranted, and heightened vigilance against device tampering and surveillance. Export control obligations under the CUI and Export Controls policies are observed when carrying controlled technology across borders.

7. Framework alignment

  • ISO/IEC 27001:2022 Annex A control 6.7 (remote working) and 7.9 (security of assets off-premises)
  • NIST SP 800-46 (enterprise telework and remote access security)
  • NIST SP 800-53 Rev. 5 controls AC-17 (remote access) and AC-20
  • SOC 2 Trust Services Criteria CC6.6 and CC6.7

8. Roles, exceptions, and review

IT and security own remote-work controls under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.

Related frameworks

For contractual attestations or audit packs, contact [email protected].