Day: Friday
Time: 17:05
Period: End of Month
Threats: JHB Traffic of Doom
Employee Status: Stuck at office
Said employee still needs to finish a presentation, update the report and review the final artwork. Stay any longer and they get home at 7 (date night starts at 6.30). It’s just wrapping up, and the files are on the company network, so they can email it to themselves and finish everything at home.
The intention? Innocent. Finish the work, meet the deadline, keep the project moving. The risk, however? Significant. This “harmless” solution is really moving sensitive company information beyond organisational control in seconds.
This isn’t just an employee problem. It’s usually a sign that an organisation has failed to provide a secure and practical way for true remote flexibility.
It’s 2026: Personal Email and USB Drives now compromise Secure Remote Work:
Once a file leaves the approved system, an organisation may lose visibility and control over it. Documents shared to personal emails could be stored on unmanaged devices, which presents its own share of risks. A USB drive can be lost, stolen, infected, or passed around without any access control or traceability. This in turn creates a magnet for:
- Data Loss/Theft
- Unauthorised Access to Confidential Information
- Malware/Ransomware Infections
- Accidental Sharing
- Compliance/Privacy Breaches
- Retrieval Issues Upon Employee Termination
Even deleting the file later doesn’t guarantee the loss of older versions, copies, downloads, backups or synced storage. What felt in the moment like an easy workaround is now a permanent security gap.
The real problem? Convenience:
Employees generally choose the quickest route available to complete their work. If the secure option is difficult, slow or unavailable outside the office, people will find another way. Too much effort? No worries, we’ll make a plan (South African proverb).
Here’s the thing, though: security needs to support productivity.
A policy that simply says, “Do not email files to yourself,” is unlikely to solve the underlying problem. Employees still need to access documents, collaborate with colleagues and meet deadlines after hours or away from the office. Businesses need to give them a safer alternative that is just as convenient.
The USB drive is not the problem. The workaround is.
Secure cloud storage should make working from home feel no different from working at the office (minus the traffic and questionable communal milk)
Employees should be able to open the files they need, continue working and save everything in one controlled environment. No emailing documents to a Gmail account. No mystery USB drive floating around a laptop bag. No five versions of “FINAL_Final_v7_ACTUAL FINAL.xlsx”.
Everyone works from the correct file, while the business decides who may view, edit, download or share it. The result is simpler collaboration, reliable backups and far better control over company information. More importantly, employees no longer need to choose between meeting a deadline and following security policy.
But putting files in the cloud does not automatically make them secure. If every employee can access everything, the business has simply moved the filing cabinet online and left every drawer unlocked.
Boundaries Matter, even with work stuff:
The salesperson preparing a proposal needs access to client documents. They probably do not need access to payroll. The finance team needs invoices and payment records. They do not need unrestricted access to confidential HR files.
This is where controlled access matters. Employees should have access to the information required for their jobs and nothing more. If an account is compromised, that distinction can determine whether the attacker reaches one folder or the entire business. Multi-factor authentication, individual user accounts and role-based permissions provide the first line of defence. Access should also be reviewed regularly and removed immediately when an employee changes roles or leaves the company.
Activity logs add another layer of visibility. The business can see who opened a file, what they changed and whether they downloaded or shared it. That is considerably more useful than discovering three weeks later that “someone” copied the client database.
Why not security policies people can actually follow?
Employees do not usually create risky workarounds because they are plotting against the company. They do it because the approved process is slow, confusing or unavailable when they need it.
A secure remote work policy should therefore answer practical questions:
- Where should company files be stored?
- Which devices may access sensitive information?
- How should documents be shared with clients and colleagues?
- Are downloads and USB drives permitted?
- What should an employee do if they make a mistake?
The answers should be clear, easy to find and supported by the right technology.
Employees should also feel comfortable reporting an incident immediately. If someone emails a document to the wrong address or loses a device, silence makes the situation worse. Early reporting gives the business time to revoke access, secure accounts and limit the damage. Cybersecurity awareness training helps reinforce these habits, but training cannot compensate for clumsy systems. Telling employees not to take files home is easy. Giving them a secure, convenient way to work from home is what solves the problem.
Make the safe option the obvious option
The employee who copied company files onto a USB drive was probably trying to finish their work, not trigger a data breach. The real failure happened earlier, when the safest way to work was not also the easiest.
Secure cloud storage, controlled access and clear remote working policies allow employees to work wherever business happens without taking company data beyond the company’s control. Vox helps businesses create secure, connected working environments through cloud, connectivity and cybersecurity solutions built for modern teams.
Give your employees the freedom to work remotely—without giving your company files the freedom to disappear. Speak to Vox.