TL;DRIT device security for distributed teams has three layers: the device itself (encryption, MDM enrollment, endpoint detection), the physical device (what happens when it crosses borders, gets lost, or is returned at offboarding), and the data lifecycle (what remains on the device when it leaves the company). Most security guides cover the first layer well and ignore the second and third almost entirely. This guide covers all three.
A device sitting on an employee's desk in a managed office has a well-understood security profile. You know where it is. You know what network it is on. You can physically retrieve it if needed.
A device sitting on an employee's kitchen table in a country you do not operate in has a different security profile. You know what your MDM tells you, which is its last check-in time and compliance status. You do not know what network it connects to between check-ins, whether the physical device is secure, or whether it will come back to you when the employee leaves.
Distributed IT security is not harder than office security because the tools are worse. It is harder because the attack surface is wider and some of the most significant risks (physical device loss, unretrieved devices at offboarding, data on devices crossing international borders) are operational problems that software cannot fully address.
This guide covers the complete security baseline for distributed devices in 2026: the software layer, the physical layer, and the data lifecycle.
What Is IT Device Security for Remote Employees?
IT device security for remote employees is the set of controls, policies, and processes that protect company data on devices used by employees who work outside a managed office environment. It includes technical controls applied via MDM (encryption, screen lock, remote wipe), network controls (VPN, DNS filtering), endpoint detection and response, and operational processes for device provisioning, physical security, and retrieval at offboarding.
For EU-based companies and teams hiring in Europe, IT device security also intersects with GDPR obligations: the lawful basis for MDM data collection, employee notification requirements, data minimisation in device monitoring, and the obligation to ensure data is deleted from devices when employment ends.
Layer 1: The Device Security Baseline
Every company-owned device issued to a remote employee should meet a minimum security baseline before it reaches the employee. This baseline is applied via MDM during provisioning and verified at regular intervals through compliance checks.
Minimum Device Security Baseline (Apple and Windows)
- Full-disk encryption enabled: FileVault (macOS) or BitLocker (Windows). This is non-negotiable. An unencrypted lost device is a data breach.
- Screen lock with short timeout: Maximum 5 minutes idle before lock. Password or biometric required to unlock.
- MDM enrollment verified before device ships: Device must be enrolled and compliant before leaving the warehouse or office.
- Automatic OS and security updates enabled: MDM should enforce update policies. Unpatched systems are the most common initial attack vector.
- Firewall enabled: macOS built-in firewall on. Windows Defender Firewall on.
- Remote lock and remote wipe capability confirmed: Test that the MDM can successfully lock and wipe the device before it ships to the employee.
- Endpoint Detection and Response (EDR) agent installed: For teams above about 25 employees, an EDR tool (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or similar) provides threat detection that MDM compliance checks alone do not.
- DNS filtering or web protection enabled: Blocks known malicious domains even on uncontrolled home networks.
MDM compliance policies for remote employees
MDM compliance policies define the conditions a device must meet to be considered compliant. Non-compliant devices can be blocked from accessing corporate resources (email, Slack, internal tools) until they meet the standard again.
Key compliance conditions for remote employee devices:
| Condition | Why It Matters | Action If Non-Compliant |
|---|---|---|
| Encryption enabled | Lost or stolen device is unreadable | Block corporate resource access |
| OS version current (within one major version) | Unpatched OS has known exploits | Alert and grace period, then block |
| Screen lock configured | Prevents physical access when unattended | Alert employee |
| MDM certificate valid | Confirms device is still under management | Alert and re-enroll prompt |
| EDR agent running | Active threat detection | Alert IT |
| No prohibited software installed | Reduces attack surface | Alert and remediation request |
Layer 2: Physical Device Security for Remote Employees
Physical security is the layer that most remote IT guides skip entirely. It matters more for distributed teams than for office-based ones, precisely because physical controls are weaker.
Device security during transit
A device in transit, whether being shipped to a new hire or returned by a departing employee, is outside the control of both the company and the employee. Physical security during transit means:
- Full-disk encryption active before shipment. A device that is lost or stolen during transit is unreadable if encrypted. This should be verified in MDM before the device is handed to a courier.
- Appropriate packaging. Physical damage to a device during transit exposes storage components that are theoretically inaccessible in normal use. Double-walled corrugated packaging with foam protection is the baseline for safe transit.
- Full replacement value insurance. Lost devices should trigger insurance recovery, not just a write-off. Insurance also triggers formal loss documentation, which supports any necessary breach notification assessment.
- Tracking throughout transit. Real-time courier tracking allows the company to identify if a device goes missing during transit and initiate a remote wipe immediately, before a potential attacker has time to attempt physical access.
Device security at customs
When a device crosses an international border, customs authorities in some countries may inspect the device physically or request that it be powered on. This is relatively rare for standard laptop shipments but occurs more frequently in certain markets.
For sensitive or regulated data, companies should consider whether devices shipped internationally should be wiped and re-provisioned at the destination, rather than shipped with existing data. This is particularly relevant for devices being redeployed rather than new devices.
Lost and stolen device response
A lost or stolen device is a security incident. The response sequence should be documented in advance and rehearsed, not improvised when it happens at 23:00 from a different time zone.
Lost Device Response Sequence
- Employee reports device loss immediately (policy should require reporting within 2 hours of discovery).
- IT remotely locks device via MDM. This prevents casual access while preserving data for investigation.
- IT confirms encryption status in MDM. Encrypted and locked device: lower breach risk. Unencrypted device: treat as confirmed data breach immediately.
- If device is not recovered within 24 hours: remote wipe initiated.
- Incident logged. If personal data was on the device, GDPR Article 33 may require notification to the supervisory authority within 72 hours of becoming aware of the breach (EU companies). UK GDPR has equivalent requirements.
- Insurance claim filed if device is not recovered.
- Replacement device provisioned and shipped.
Related: IT Equipment Policy for Remote Employees: What to Include
Layer 3: Data Security at Offboarding
The most consistently underestimated security risk in distributed IT is the device that is never returned at offboarding. A device with company data in the hands of a former employee, whether through negligence or intent, is a persistent data risk that grows over time.
For EU companies and teams with EU employees, GDPR specifically requires that personal data is not retained beyond its purpose. A device containing company data in the possession of a former employee represents a failure of data lifecycle management, independent of whether that former employee has any malicious intent.
Offboarding device security checklist
- Access revocation initiated on last working day (SSO, email, Slack, SaaS tools, VPN). This happens before device retrieval in most cases.
- Device added to retrieval watchlist in MDM. Remote lock scheduled for the day after last working day if device is not returned.
- Packaging dispatched to employee's current address (not address on file from hire date).
- Employee communication sent from neutral logistics partner, not from HR or the former manager.
- Device collected and in transit.
- Device received. Remote wipe initiated via MDM. Wipe confirmed in MDM dashboard.
- Certificate of data destruction issued (required for some compliance frameworks; useful for GDPR documentation).
- Device assessed for redeployment or disposal.
On remote wipe timing: Do not initiate a remote wipe while the device is in transit. If the wipe completes but the device is never recovered (lost in transit), you lose the ability to verify the wipe was successful. Wipe the device after it is received and confirmed. Lock it remotely during transit if needed.
What happens to data on unretrieved devices
For devices that are never returned despite the retrieval process, two options exist. If the device is still checking into MDM (the employee has it but has not returned it), MDM can perform a remote wipe. If the device has been offline for more than 30 days and has not checked in, the remote wipe command will execute the next time it connects, but that may never happen.
This is why the physical retrieval process matters for data security, not just asset recovery. The only reliable way to ensure data is destroyed on an unretrieved device is to retrieve it and wipe it physically. Remote wipe is a fallback, not a substitute.
Related: How to Recover Laptops from Remote Employees When They Resign
Related: IT Offboarding Process for Distributed Teams
GDPR and Device Security: What EU Companies Need to Know
For companies based in the EU, or any company with employees in the EU, GDPR intersects with device security in four specific ways.
Transparency about MDM monitoring. Employees must be informed about what data the company collects from their enrolled device. MDM tools can collect location data, application inventory, network information, and compliance status. All of this must be disclosed in a privacy notice and, in some cases, in the employment contract. Undisclosed monitoring is a GDPR violation, regardless of the security purpose.
Data minimisation in MDM configuration. MDM should collect only the data necessary for its security and management purpose. Continuous location tracking of an employee's laptop, for example, may be hard to justify under GDPR's data minimisation principle unless there is a specific, documented operational need.
Data breach notification. A lost or stolen device that contained personal data may trigger GDPR Article 33 notification obligations: the supervisory authority must be notified within 72 hours. Full-disk encryption on the device, if confirmed active and uncompromised, is a mitigating factor that may reduce or remove the notification obligation. This is one of the strongest operational arguments for enforcing encryption via MDM as a non-negotiable baseline.
Right to erasure at employment termination. When an employee's employment ends, their personal data should be deleted from company systems according to the retention policy. Company data on the device must also be wiped. The certificate of data destruction is documentation that this obligation was fulfilled.
Security Comparison: In-House Management vs Managed Logistics Partner
| Security Element | In-House IT Management | With a Managed Logistics Partner (Raal) |
|---|---|---|
| Encryption verification before shipment | Manual check required | Built into pre-shipment verification |
| Secure packaging for transit | Ad hoc; variable quality | Tested transit packaging standard |
| Insurance on device in transit | Often missed or undervalued | Full replacement value, every shipment |
| Real-time transit tracking | Courier dashboard only | Consolidated tracking with alerts |
| Neutral offboarding retrieval contact | HR or IT contacts employee directly | Third-party logistics contact, no HR association |
| Certificate of data destruction | Manual process; often skipped | Issued on every wiped and returned device |
Related: Raal vs Managing IT Devices In-House
Related: Zero-Touch Deployment for Remote Teams: What MDM Covers and What It Doesn't
FAQ
What is the most important IT security control for remote employee devices?
Full-disk encryption is the single most important control. An encrypted device that is lost or stolen is, in practice, inaccessible without the decryption key. FileVault on macOS and BitLocker on Windows are both MDM-manageable, meaning the company can verify encryption is active on every enrolled device. A device that is lost without encryption active is a confirmed data breach. A device that is lost with encryption active and a strong screen lock passcode is, under most GDPR interpretations, not a reportable breach.
What should happen to company data when a remote employee's device is returned?
The device should be remotely wiped via MDM after it is received and the return is confirmed. The wipe should be verified in the MDM dashboard (both Apple and Windows MDM tools provide wipe confirmation). A certificate of data destruction should be issued and retained in the company's data processing records. Under GDPR, this certificate is documentation that the data lifecycle obligation was fulfilled. The device can then be assessed for redeployment or disposal.
Does GDPR require companies to notify employees about MDM monitoring on company devices?
Yes. GDPR requires transparency about all personal data processing, including data collected from enrolled devices via MDM. This means the types of data collected (compliance status, application inventory, network information, location if enabled) must be disclosed to employees in a privacy notice. This disclosure should happen at onboarding, before the device is issued. Undisclosed monitoring on a company-owned device is still a GDPR violation if personal data is collected in the process.
How do you remotely wipe a device if the employee does not return it?
If the device is still enrolled in MDM and connects to the internet, a remote wipe command can be sent via the MDM console (Jamf, Intune, Kandji, or similar). The wipe will execute the next time the device checks in. If the device has been offline for an extended period or the MDM profile has been removed, remote wipe may not be possible. This is why physical retrieval is preferable to relying on remote wipe: the wipe can be confirmed, the device is recovered, and the data destruction certificate is issued based on verified erasure.
About Raal: Raal handles the physical layer of device security for distributed teams: secure transit packaging, encryption verification before shipment, full replacement value insurance, and neutral third-party retrieval at offboarding with certificate of data destruction. Get a live estimate.



