Many staff are still using work devices for personal and illegal activities

laptop
(Image credit: Shutterstock / ESB Professional)

Since the transition to remote working, businesses have failed to communicate the importance of sticking to cybersecurity policies and preventing cross-contamination between work and personal activities, new data from Yubico suggests.

The password security company surveyed 3,000 remote staff from around Europe and found that almost half (42%) use work-issued devices for personal tasks. Roughly a third of this group use corporate tech for banking and shopping, while 7% visit illegal streaming websites.

What’s more, senior members of staff are among the worst offenders; 43% of business owners and 39% of C-level executives admit to misusing work devices, with many also dabbling in illegal activities online.

Although using a work computer for a bit of online shopping does not in itself pose a threat to cybersecurity, the overlap between personal and professional activities could amplify risks associated with shadow IT, including the accidental compromise of corporate data.

With employees accessing the web and other services for personal reasons, the risk of malware or ransomware infection is also increased.

Remote working security

Another area of vulnerability for many businesses operating under a remote model is password hygiene.

According to Yubico, 54% of employees use a single password across multiple work accounts and services. Meanwhile, 22% of staff still write down their passwords on paper, including 32% of executives.

However, IT departments aren’t holding up their side of the bargain either, the report suggests. Yubico found that more than a third (37%) of remote employees are yet to receive any form of cybersecurity training, which goes some way to explaining the lapses in judgement on the part of employees.

Further, only 22% of respondents said their company has adopted two-factor authentication, which is described as “the best line of defence” to protect against account takeover.

“Virtual working patterns bring new opportunities for businesses and employees, but also introduce additional risk. This includes new avenues for bad actors to breach corporate defences,” said Yubico.

“With millions of workers focused on the pressures of completing tasks in varying and sometimes unusual circumstances, security best practices are often put on the backburner.” 

“Organizations that don’t get a handle on these hazards risk lasting financial and reputational damage from attacks that can leave their assets in tatters.”

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Giant eye watching at man working at the computer. Surveillance, hacking, internet security concept. Flat vector illustration.
85% of UK employers admit to spying on their employees – and workers aren't happy
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
person at a computer
Many workers are overconfident at spotting phishing attacks
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Don’t let holidays be your cybersecurity downfall
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news