forumNew topic

employees connect from their own laptops without VPN — police account?

EEbru K***MemberCommunity member
Joined
Aug 2025
Message
113
#1

we saw during the audit: employees are connecting to company systems from personal computers at home (Windows 10 + no antivirus). none have VPN, none have endpoint security. the accounting person is forwarding company mail to gmail. is it really this risky?

should we write a policy? 'company laptop mandatory', 'VPN required', 'no personal devices'. if we impose this, employees won't like it (no BYOD from home). budget is limited (laptop = 20k, MDM software = 50k/year).

Should we start with a hybrid approach: mandate company devices for those accessing critical data (accounting, IT) and be flexible for others? Or should we make it mandatory for the whole company?

UUğur Ö***Member
Job title
Sales Manager
Sector
IT services
Organization type
regional distributor
Joined
Jan 2024
Message
5

Doki · Brand identity · 2026

Most Helpful#2

Phase 1: give laptops to critical roles. Phase 2: make VPN + antivirus mandatory for everyone (policy). Phase 3: set up MDM. If you go in that order the budget will blow up.

MMelekNew member
Job title
Daycare owner
Joined
Sep 2024
Message
40

Doki · Log management setup · 2026

#3

I agree.

ÜÜlkü N***Member
Job title
Courier coordinator
Sector
Energy
Organization type
300-person organization
Joined
Mar 2024
Message
64
#4

You're right, I've been down that road too. Forgotten test environments are more often the entry point than live systems.

Proven by experience.

PPolat E***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
cooperative
Joined
Mar 2024
Message
273
#5

Same here. If permission and scope aren't in writing, don't start that test.

When you try to change everything at once, nothing settles. Proven by experience.

İİlknur Y***MemberCommunity member
Joined
Sep 2025
Message
2
#6

Let me share my experience. If you get three different answers on a topic, the question was asked wrong.

If permission and scope aren't in writing, don't start that test. That's all, sorry if I went on too long.

SSinan Ç***Member
Job title
Administrative manager
Sector
Security services
Organization type
20-person company
Joined
Jan 2025
Message
159
#7

I didnt know that.

GGamze G***Expert
Job title
Human Resources Manager
Sector
Security services
Organization type
medium-sized business
Joined
Apr 2022
Message
218

Doki · Phishing awareness training · 2025

#8

I felt relieved reading this answer, so it's not just me. People defend habits, not processes. Resistance comes from there.

Good luck with that.

YYavuz G***Member
Job title
Courier coordinator
Sector
Packaging
Organization type
family business
Joined
Jun 2025
Message
45

Doki · Log management setup · 2023

#9

My questions are cleared up, thanks.

KKadir K***MemberCommunity member
Joined
Dec 2024
Message
25
#10

I completely agree. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

That's all sorry if I went on too long.

YYavuz Y***MemberCommunity member
Joined
Mar 2026
Message
15
#11

I'll argue the opposite, don't get mad... Most incidents start with a leaked password, not a vulnerability.

Mistakes made on the employee device security side are usually reversible but expensive. Proven by experience.

SSelin V***Veteran
Job title
Operations manager
Sector
Law
Organization type
a company within a holding
Joined
Feb 2022
Message
21

Doki · Phishing awareness training · 2023

#12

Do you think this works at any scale? Security isn't absolute; it's about making attacks not worth the effort.

Hope this helps.

MMurat T***MemberCommunity member
Joined
Apr 2025
Message
53
#13

I was thinking the same thing... If you scold false alarms, nobody will report again.

VVildan Ö***Member
Job title
Secretary
Sector
Retail
Organization type
family business
Joined
Dec 2024
Message
66
#14

following.

YYiğit Y***New member
Job title
Sales Manager
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Aug 2026
Message
4
#15

There's a part I don't understand. The answer varies greatly by industry; there is no one-size-fits-all rule.

The biggest time-waster for us was not knowing who had the final say. Correct me if I'm wrong.

EEmre E***VeteranCommunity member
Joined
May 2025
Message
283
#16

I didn't know that. If you don't write this down from the start, it leads to arguments later.

If you don't write this down from the start, it leads to arguments later.

MMetin P***ExpertCommunity member
Joined
Jun 2023
Message
186
#17

saved.

HHilal B***ExpertCommunity member
Joined
Feb 2026
Message
66
#18

I'd appreciate it if you shared the outcome.

NNuri K***Member
Job title
Purchasing manager
Sector
Plastic
Organization type
boutique agency
Joined
Sep 2024
Message
335
#19

It's rare to find an explanation this clear. Hasty decisions become decisions you have to fix six months later.

Proven by experience.

YYavuz B***MemberCommunity member
Joined
Apr 2022
Message
203
#20

Don't miss this: Payment information changes are never verified through the channel they came from.

This is my opinion I'm not claiming it's absolute truth.

Reply