wp2shell: more than a month later. Confirm 6.8.6, 6.9.5, 7.0.2. Patched is not clean.

Read the advisory

Security training for newly remote workers

What to teach new remote staff: phishing, Trojans, personal devices, and public Wi-Fi. Practical training points without the pandemic filler.

Topics Hardening & checklists

Lars Koudal

Lars Koudal

Updated Published

People who just moved from an office to home often inherit “IT took care of it” habits. At home they share the network with family devices, use personal phones for Slack, and join coffee-shop Wi-Fi without thinking. Training has to make the risks concrete and the rules short enough to remember.

Companion reads: keep data safe when working remotely and customer data privacy for remote teams.

Be clear about the risks

Vague “be careful online” slides do nothing. Explain what a bad click costs: customer data exposure, ransomware downtime, lost accounts, and sometimes jobs. Human error still drives a large share of incidents. Give people ownership of the devices and logins they use every day.

Cover:

  • Strong, unique passwords (password manager) and 2FA on work accounts
  • Why video tools and shared drives need the same care as email
  • Critical thinking before installing “helpful” apps or browser extensions

Teach common scams

Attackers know remote staff are busy and often on personal gear.

Phishing: fake invoices, “IT needs you to reset,” urgent CEO requests. Warning signs include unexpected attachments, odd sender domains, generic greetings, and pressure to act now. Full primer: your guide to phishing and WordPress phishing.

Trojans and fake updates: software that looks like a codec, PDF reader, or “security patch.” Rule: install only from IT-approved sources. When unsure, ask before you click.

Physical bait: unknown USB sticks are not free gifts. Do not plug them into work machines.

Separate personal and work devices when you can

A compromised personal phone can still reach work email. Prefer company-managed laptops for sensitive systems. If BYOD is allowed, require disk encryption, screen lock, OS updates, and the same MFA rules as corporate gear. Shred or securely dispose of printed customer data at home the way you would at the office.

Public Wi-Fi and fake networks

Coffee-shop Wi-Fi invites snooping and evil-twin access points that mimic the cafe name. Prefer a company VPN before touching admin panels, banking, or customer CRMs. Mobile data is often safer than mystery SSIDs for short sensitive tasks. Session theft on open networks is an old trick that still works against lazy habits.

Put the policy in writing. Have people acknowledge it. Responsibility is clearer when it is not only implied.

Bottom line

New remote workers need short, repeated training: passwords and MFA, phishing recognition, device separation, and no sensitive work on random Wi-Fi. Pair that with company tools that make the safe path the easy path. If they manage WordPress for you, point them at the login security guide next.

Found this useful? Share it.

Larger screenshot