Hybrid working is now permanent for most UK SMBs. Your team works from home some days, the office other days, customer sites and coffee shops in between. The security model that worked when everyone was in the office, a perimeter firewall protecting trusted devices on a trusted network, doesn’t work any more. The new model is identity-based: trust the team member, the device and the context, not the network they’re on.
This guide covers what hybrid security actually looks like in 2026, the three mistakes that catch most UK SMBs out, and how to roll it out without breaking productivity.
In short: hybrid working is safe when access, devices and data are secured by default, not left to chance on home networks. Here is how to get the flexibility without opening security holes.
Key takeaways
- The old “trust the office network” model is dead. Identity is the new perimeter.
- Conditional Access + Intune + MFA is the modern toolkit. Most UK SMBs already have the licences.
- BYOD without device management is the single biggest hybrid-working risk.
- Public Wi-Fi is no longer an automatic risk if your laptop is properly hardened, but coffee-shop guest networks still warrant a VPN.
- Most “we got hacked from home” incidents trace back to the same three mistakes (below).

The new security model: identity is the perimeter
Pre-2020, IT security was network-based. Devices inside the office network were trusted; devices outside weren’t. You connected from home via VPN to “be inside” the office network.
That model has been replaced by identity-based security (sometimes called Zero Trust). Every connection is verified, regardless of where it’s coming from. Trust depends on:
- Who: the team member’s identity, MFA-verified.
- What: the device’s identity, managed and compliant.
- Where: location and network risk signals.
- When: time of day, recent activity patterns.
- How: the application being accessed and its sensitivity.
Microsoft Conditional Access is how you implement this on Microsoft 365. Each policy is a rule like “If team member accessing Outlook is from an unmanaged device in a high-risk country, block. If from a managed device with MFA in the UK, allow.”
The three mistakes UK SMBs make with hybrid
Mistake 1: BYOD with no management
Bring Your Own Device feels modern and saves money. It’s also the single largest hybrid-working risk. Here’s the typical scenario: an employee uses their personal laptop to read work email at home. Their teenage son borrows the laptop, downloads a game from a dodgy site, malware sits dormant for weeks, then activates and steals the parent’s saved Microsoft 365 credentials.
Fix: require any device accessing your data to be managed (Intune-enrolled) and compliant (encrypted, screen lock, supported OS, security software running). If staff want to use personal devices, accept that the company portion of those devices needs to be managed.
Mistake 2: VPN with no MFA
Many SMBs have a VPN that’s existed since 2015. It works on a single shared username and password. It’s been on the firewall, exposed to the internet, the entire time. If those credentials leak (one phishing email, one compromised Mac), the attacker has the keys to your office network.
Fix: retire the legacy VPN. Move to either a modern ZTNA service (Zscaler, Cloudflare Access, Microsoft Entra Private Access) or, for simpler needs, the Microsoft 365 + Conditional Access model where staff access cloud apps directly without a VPN. If you must keep a VPN, require MFA on every connection.
Mistake 3: No conditional access on the M365 tenant
The most common configuration we see on a “first review” of a new client tenant: MFA per-person (so staff can disable it), no Conditional Access policies at all, allowed sign-ins from anywhere in the world. That’s a tenant where one stolen password = full takeover.
Fix: Conditional Access policies that enforce MFA, block legacy auth, restrict sign-ins to expected geographies, and require compliant devices for accessing sensitive content. We covered the specific settings in our Microsoft 365 setup guide.
The hybrid-secure stack (in 2026)
What a properly configured hybrid setup looks like for a 25-person UK SMB:
Identity layer
- Microsoft Entra ID (formerly Azure AD) as the central identity provider.
- MFA enforced via Conditional Access on every cloud app.
- Risk-based sign-in: high-risk sign-ins are blocked or trigger additional verification.
- Single Sign-On (SSO) so staff have one login for everything.
Device layer
- Microsoft Intune managing every laptop, regardless of where the laptop physically is.
- Compliance policies: encryption on, screen lock, OS up to date, EDR running.
- Conditional Access blocks unmanaged or non-compliant devices.
- Autopilot for new starter onboarding: ship laptop, team member logs in, fully configured.
Application layer
- Cloud-first: Microsoft 365 for email and docs; line-of-business apps moved to SaaS where possible.
- Sensitivity labels and DLP on confidential content.
- OAuth app consent restricted to admins.
Network layer
- Office Wi-Fi: SSID for staff (managed devices, full access), guest SSID (internet only, isolated).
- Home/remote: trust the device, not the network. No legacy VPN required.
- For staff who must access on-premise resources: ZTNA service or modern VPN with MFA.
What about new starters and leavers?
The hardest hybrid problem isn’t the technology, it’s the human transitions. Onboarding and offboarding go wrong more often than anything else.
Onboarding: Microsoft Autopilot-enrolled laptop arrives at the new starter’s home. They power on, sign in with their issued credentials, and the device automatically downloads policies, applications and access rights. They’re productive in 30 minutes.
Offboarding: within hours of HR notification, accounts are disabled, mailboxes are converted to shared (so colleagues can still access work history), Intune triggers a remote wipe of the laptop’s company data, and devices are recovered via courier. No “we forgot to disable her account” moments.
Frequently asked questions
Do I still need a VPN if I’m in Microsoft 365?
For most SMBs, no. Microsoft 365 is accessed directly over the internet (with Conditional Access enforcing security). VPNs are now mostly needed only for accessing on-premise resources (a local server, a legacy line-of-business app), or for specific compliance requirements.
How much does this cost vs the old way?
If you’re already on Microsoft 365 Business Premium, most of the tools (Conditional Access, Intune, Defender for Endpoint) are included. The cost is typically the work of configuring properly, plus device management overhead. Often net-cheaper than maintaining a legacy VPN, on-premise file server and standalone antivirus.
What about employees using personal phones for work email?
Either enrol the personal phone in Intune (with proper team member consent and a clear separation between personal and work data via App Protection Policies), or restrict mobile email access to issued devices only. Pure BYOD with no management is the highest-risk option.
Is public Wi-Fi safe?
If your laptop is properly hardened (encrypted disk, modern OS, EDR running, MFA on accounts), public Wi-Fi is no longer the major risk it was 10 years ago. Cloud apps over HTTPS are encrypted end-to-end. The remaining risk is from man-in-the-middle attacks on captive portals; for high-sensitivity work, a VPN over public Wi-Fi is still sensible.
How long does it take to roll this out?
For an SMB starting from scratch (no Intune, no Conditional Access), typically 4-6 weeks for a 25-person business. Phased: identity policies first, then device enrolment, then progressively tightening compliance.
Initial IT designs and manages hybrid-working environments for UK businesses across Lichfield, Staffordshire and the West Midlands.
