Cyber fears prompt one in four firms to restrict hybrid working

hybrid working at risk due to cyber attacks

One in four organisations hit by a cyber attack have reduced employees’ access to remote or hybrid working, raising questions about whether growing cyber risks could begin to reshape flexible working practices.

Research from Hiscox found 25 per cent of organisations that had experienced a cyber attack subsequently restricted remote or hybrid working, while 30 per cent moved employees from their own devices onto company-managed technology. A further 28 per cent limited employee access to critical data.

The findings highlight a developing tension for employers between managing cyber security and maintaining the flexibility that has become embedded in working life for many employees.

While restricting remote access may help organisations manage perceived vulnerabilities following an attack, changes to hybrid working can also have wider consequences for employees who have structured their working and personal lives around greater flexibility.

That makes cyber security potentially more than an IT or risk-management issue. Decisions made in response to cyber threats could increasingly influence work design, employee experience and wellbeing.

For some employees, hybrid working can provide greater autonomy over where and how they work, reduce commuting time and make it easier to manage caring responsibilities, health needs and other commitments.Removing or restricting that flexibility following a cyber incident can therefore affect employees who were not directly responsible for the breach.

The findings come as cyber attacks remain a significant concern for smaller employers. Hiscox reported that 39 per cent of UK small and medium-sized businesses had experienced a cyber attack during the previous year.

Employees themselves are also seen as a potential route into organisations.

A quarter of businesses identified employees as the most likely way hackers could gain access through attacks including phishing, social engineering and spoofing.

However, Hiscox’s findings also suggest employers are responding by investing in their workforce rather than relying solely on restrictions.

Some 62 per cent of organisations had updated employee cyber security training, while 55 per cent had recruited additional cyber security personnel and 51 per cent had invested in software to strengthen their defences.

Eddie Lamb, Global Head of Cyber at Hiscox, said: “As organisations continue to embrace increasingly digital and flexible working environments, it’s important that security keeps pace. The goal is not to restrict people unnecessarily, but to ensure that businesses can continue to operate safely and confidently in the face of cyber risk.

“Businesses that respond most effectively to cyber incidents tend to take a balanced approach by building both their technical and human firewalls. That means investing in technology and training, but also looking closely at processes, permissions and access rights to reduce unnecessary exposure.”

For employers, that balance could become increasingly important. Hybrid working is no longer simply a question of where somebody opens their laptop. It can influence recruitment, retention, inclusion, caring responsibilities and how employees manage their health and working lives.

A cyber attack may therefore force organisations to make decisions that extend well beyond their technology infrastructure.

The challenge will be determining whether restricting flexibility is necessary to manage a specific security risk, or whether technology, training, access controls and better working practices could allow organisations to protect both cyber resilience and employee autonomy.

This could be particularly relevant for employees who depend more heavily on flexibility, including carers, disabled employees and people managing long-term health conditions.

It also underlines the importance of involving HR and people teams in decisions about cyber resilience where changes could materially affect how employees work.

The tenth annual Hiscox Cyber Readiness Report surveyed 6,800 cyber security decision-makers working in organisations with fewer than 250 employees across the UK, US and mainland Europe between 5 and 17 June 2026.

Related News

The List, your Trusted Workplace Wellbeing Directory

A curated community where People Leaders find trusted Workplace Wellbeing providers, and providers find meaningful business.