Remote work quietly changed your threat model: your office is whatever network you sit on, your login screen is the company perimeter, and nobody from IT is watching your back at the airport gate. The fix isn’t paranoia or a drawer of gadgets — it’s four tools and three habits.
The stack at a glance
| Product | Best for | Rating | Price | Buy |
|---|---|---|---|---|
| Bitwarden Bitwarden | Open-source password manager with the most generous free tier. | — | Free, or from $1.65/mo (Premium, billed annually) (verified 2026-07-10) | Get Bitwarden free |
| NordVPN Nord | Fast, well-audited VPN — our default recommendation for most people. | — | $12.99/mo, or $3.09/mo on 2-year plan (verified 2026-07-10) | Get NordVPN |
| Proton Proton | Encrypted email, VPN, and drive from a privacy-first company. | — | Free, or from $3.99/mo (Mail Plus, billed annually) — full suite (Unlimited) from $9.99/mo (verified 2026-07-10) | Try Proton |
Layer 1: a password manager (start here)
If you adopt one thing from this page, it’s this (our full password-manager comparison covers paid alternatives like 1Password for smoother family/team use). Pair it with app-based two-factor authentication on your email and anything work-critical — the two-minute setup that stops the most common account takeovers. The complete walkthrough is our secure-your-accounts afternoon plan.
Layer 2: a VPN for untrusted networks
NordVPN
For the café/hotel/airport rotation: audited no-logs policy, fast enough to forget it's on, apps for everything. Turn it on whenever the Wi-Fi isn't yours.
The honest framing (fuller version in our VPN guide): HTTPS already protects most of your traffic, so a VPN isn’t magic armor — it’s insurance against the specific sketchiness of networks you don’t control, from fake hotspots to nosy operators. If your work regularly happens on other people’s Wi-Fi, that insurance is cheap and worth it. One caveat: if your employer provides a corporate VPN, use that for work traffic — company policy beats personal preference on managed devices.
Layer 3: encrypted email and storage
Proton
For freelancers and anyone whose 'IT department' is themselves: encrypted mail, cloud storage, and a VPN in one privacy-first subscription.
Employees mostly live in employer-provided suites — fine. This layer is for the self-employed and side-hustlers: client contracts, financial documents, and sensitive correspondence sitting in an ad-funded inbox is a misalignment you can fix once. Proton’s suite (Mail, Drive, VPN, Pass) is the practical one-subscription answer, and its email aliases are quietly great for keeping client signups out of your real inbox.
Match the stack to your situation
“Remote worker” covers three quite different lives, and the tools shift weight accordingly.
The digital nomad: every network is untrusted
If your office rotates through hostels, cafés, co-working spaces, and airport lounges, the VPN stops being situational and becomes your default state — on before the first tab opens, on every network, no exceptions worth debating. Two additions matter more for you than for anyone else:
- Full-disk encryption and a tested cloud backup. A laptop that lives in a backpack will eventually be lost, stolen, or dropped. Encryption (FileVault on macOS, BitLocker/Device Encryption on Windows — both built in, both usually a checkbox) turns a stolen laptop from a data breach into a hardware loss; the backup turns it into an inconvenience.
- Your phone as a trusted hotspot. When a network feels off — a captive portal demanding odd permissions, a “Free_Airport_WiFi_2” of uncertain parentage — tethering to your own cellular data sidesteps the question entirely. Where local data is cheap, many nomads simply default to it.
The hybrid employee on a managed laptop
Counterintuitively, you need the least gear — and the most discipline. The company laptop already carries corporate security tooling, likely including a corporate VPN; adding your own on top of it helps nobody and may violate policy. Your genuine to-dos live elsewhere: your personal accounts and devices are your responsibility, not IT’s, so the password manager + two-factor afternoon still applies to your own digital life. And keep the boundary clean — personal browsing, personal cloud accounts, and personal files don’t belong on the managed machine (more on why in the employer-visibility section below).
The freelancer holding client data
You’re the interesting case: nobody manages your device, but other people’s confidential material lives on it — contracts, drafts, credentials clients really shouldn’t have emailed you but did. That makes you, functionally, a one-person IT department with obligations:
- Full-disk encryption is non-negotiable, for the same stolen-laptop reason as the nomad — except the breach would be your client’s data, and your reputation.
- Encrypted email and storage (Layer 3) earns its subscription here. Client work in a personal ad-funded inbox is the misalignment; some client contracts also specify how their data must be handled, so check what you’ve signed.
- Separate client credentials properly. Anything a client hands you (site logins, API keys) goes in the password manager, ideally in a per-client folder or collection — never in a spreadsheet, never in the email thread it arrived in. When a project ends, deleting that folder is your offboarding.
- A basic “what if my laptop dies mid-project” answer — encryption, backup, and a phone that can hotspot cover most of it.
Working while traveling: the checklist
A short pre-flight and on-the-road routine covers the travel-specific risks without turning you into a security officer:
Before you leave: confirm full-disk encryption is on; make sure “find my device” and remote-wipe are enabled (built into macOS/Windows/iOS/Android); update the OS and browser while you’re on trusted Wi-Fi; and check your two-factor setup works without SMS — authenticator apps work offline, but codes sent to a number that’s roaming or swapped out for a travel SIM may not reach you. This is also the moment to know where your backup codes are.
On the road: confirm the exact network name with staff before connecting (lookalike hotspots are the classic public-Wi-Fi trick); VPN on before you work; prefer your own charger and a wall socket — or a power-only cable — over unknown USB ports, since USB carries data as well as charge; and lock the screen every time you stand up, even “just to get the coffee.” A privacy screen filter is one of the few gadgets we’d actually endorse for people who work in public constantly — shoulder-surfing is decidedly low-tech and decidedly real.
If a device goes missing: remote-lock or wipe it from another device, change your email password first (master key, as always), and sign out all sessions from your major accounts’ security pages. With encryption already on, everything after that is logistics rather than crisis.
Don’t forget the router you work behind
“I only work from home” pushes the question one hop back: home is only as trustworthy as the router running it. Five minutes, once, and then largely forget it:
- Change the router’s admin password — the one for its settings page, not the Wi-Fi password. Defaults are printed on labels and listed all over the internet.
- Use WPA2 or WPA3 with a strong Wi-Fi passphrase. If you find an ancient setting like WEP, that router is due for replacement.
- Turn on automatic firmware updates if offered — router bugs get fixed in updates most people never install. If your router is old enough to have stopped receiving them, that’s the actual “should I buy something?” answer on this page.
- Put smart-home gadgets and guests on the guest network. The cheap smart plug doesn’t need to share a network with the laptop full of client files.
- Disable WPS and remote administration if you see them — convenience features that mostly widen the door.
If your desk setup is getting the same once-over, the home-office kit side of the site covers the physical half.
The habits that beat hardware
- Lock the screen. Every time. The oldest advice survives because the risk is real anywhere strangers share your space. (
Cmd/Win + L— make it muscle memory.) - Separate work and personal. Separate browser profiles minimum, separate OS accounts better. Smaller blast radius in both directions.
- Treat urgency as a tell. “CEO needs gift cards now,” “account closes in 24 hours” — remote workers are prime phishing targets because there’s no colleague to lean over and ask. When a message demands speed, slow down; go to the site directly instead of clicking.
- Update the boring things. OS, browser, router firmware. Most real-world exploits target patches you skipped, not zero-days.
What your employer can — and can’t — see
The remote-work privacy question people actually whisper. The honest general answer (policies and rules vary by company and by where you live — your company’s own IT/acceptable-use policy is the document that governs your situation, and worth actually reading):
On a company-managed device, assume broad visibility. Management and monitoring software runs on the machine itself, which means it can typically see what happens on the machine: installed software, visited sites, and activity — on any network, home Wi-Fi included. Two corollaries worth internalizing:
- Your home network doesn’t shield a work laptop. The visibility comes from software on the device, not from the office walls.
- A personal VPN doesn’t either. A VPN encrypts traffic between the device and the internet — but monitoring on the device sits inside that tunnel and sees activity before encryption happens. A VPN protects you from networks, never from the machine you’re typing on.
What your employer generally can’t see: your personal phone and personal laptop, on your own accounts, on your own network. That’s the boundary that matters — and it’s why “separate work and personal” appears twice on this page. The clean mental model: the work laptop is a company office you carry around. You wouldn’t do your banking, private messages, or job hunting on a shared office kiosk; don’t do them on the managed laptop either. It’s not that anyone is necessarily watching — it’s that the machine isn’t yours, so the question shouldn’t need to come up.
Two gray zones to keep clean: corporate VPNs on personal devices (while connected, your traffic routes through company infrastructure — do personal things off it), and personal accounts signed into work browser profiles, which entangle your data with corporate sync and backups. If you’ve been mixing for years, untangling is unglamorous but simple: sign personal accounts out of the work machine, move any personal files off it, and give your personal life its own hardware going forward.
None of this is fear material — it’s just the trust model, stated plainly. Employers securing their own equipment is normal; you keeping your personal life on your personal devices is equally normal. Everyone’s happier when the boundary is boring.
What you can probably skip
- Camera covers as a security strategy. Fine as a $2 comfort, but the malware that could watch you is stopped by updates and not installing junk — not by tape.
- “Military-grade” gadget dongles. Privacy hardware pitched on fear generally duplicates what the four layers above already do.
- Paying for a VPN you never toggle on. If you genuinely never leave your home network, revisit whether you need Layer 2 at all. Honest budgeting beats security theater.
How we chose these tools
The basis for the picks on this page, so you can judge them: based on specs, security track record, independent audits where published, and user consensus — not hands-on lab testing. We weighted audited claims over marketed ones (a no-logs policy means more when a third party has verified it), cross-platform coverage (remote work means your tools follow you across laptop, phone, and tablet), a usable free tier or honest pricing (a tool you won’t actually run protects nothing), and companies whose business model is the subscription, not your data. The deeper reasoning per category lives in the VPN guide, the password-manager comparison, and the three-way VPN head-to-head.
The bottom line
Password manager + two-factor today (the afternoon plan walks you through it), VPN on your laptop bag’s Wi-Fi diet, encrypted services if you’re your own IT department, and the four habits above. That’s a remote-work setup more secure than most corporate desks — for under $40 a month, most of it optional.
If you want it as a sequence rather than a stack: this week, the password manager and two-factor; this month, the VPN if your work leaves the house and the router five-minute check; this quarter, the encrypted-services question if you handle client data. Each layer stands alone, so there’s no wrong place to stop — only wrong places to start.
The full stack — and the rest of the privacy cluster as it grows — lives at the Privacy & Security Kit hub.