Most conversations about remote work focus on the good stuff — flexibility, no commute, better work-life fit. And those are real. But there’s a quieter side to working from home that doesn’t get the same airtime: the risks that don’t announce themselves until they’ve already cost you something. A promotion that went to someone more visible. A security incident that started with a simple click. Recent data found that 78% of organizations experienced a security incident linked to remote work in the past year. That’s not a scare statistic — it’s a signal that the way we work has changed faster than the way we protect it, and the way we advance within it.
Career Security Visibility
Heads up — this post may include links to things I use or like, and I might earn a little something if you shop through them. Doesn’t cost you anything extra, and I only mention stuff I’d actually recommend.
The Career Penalty Nobody Talks About
When people worry about remote work risks, they usually picture data breaches or layoffs. But the slowest-moving risk might be the most damaging: the career drag that comes from simply not being seen. This hits hardest for workers early in their careers, though it affects anyone who isn’t intentional about visibility.
A Stanford study of software engineers found that those sitting near teammates received roughly 18% more feedback on their code and produced higher-quality work. The gains were concentrated among less-tenured and younger employees — exactly the people who need feedback most to grow. The implication isn’t that everyone needs to be in an office five days a week. It’s that the informal learning you absorb through proximity — watching a colleague negotiate a tense call, overhearing how a decision got made, reading the room during a meeting — doesn’t replicate well over Slack.
If you’ve ever wondered whether being out of sight means being out of mind for raises and promotions, you’re not imagining it. The research bears out that out of sight often means out of the loop — not through malice, but through the simple physics of attention. When you aren’t in the room, you don’t get the accidental career fuel that happens in hallways, before meetings start, and over shared coffee.
Early-career learning happens through what researchers call observational osmosis — watching senior colleagues handle conflict, present ideas, build relationships. These moments are hard to engineer over Zoom. A CNBC report on remote work career risks for younger workers notes that fully remote arrangements early in a career are best avoided when possible, and that young workers may be better off taking a hybrid role that pays less if it gives them access to sharper colleagues. The logic is simple: fast raises and promotions can overtake a remote pay premium within a few years.
This doesn’t mean remote work is a dead end. It means the default assumption — that good work will be noticed — is unreliable when you’re not visible. The fix isn’t dramatic. It’s structural.
- Send a structured weekly summary to your manager — wins, blockers, next steps — using a template you reuse every week. This makes your contribution impossible to ignore.
- Schedule short virtual coffee chats with leaders and peers across teams, not just your direct group. Fifteen minutes, no agenda, repeated monthly.
- If you can, plan a quarterly office visit focused on intense networking — schedule back-to-back meetings, group lunches, and spontaneous conversations. One concentrated day can replace months of remote facetime.
◈
The Security Risks Hiding in Your Home Office
Career risks are slow. Security risks are fast. And they’re expensive. The same survey that found 78% of organizations experienced a remote-work-linked security incident also calculated that breaches involving remote work cost an average of $173,774 more than other breaches. That extra cost comes from the difficulty of containing incidents across distributed devices, home networks, and personal accounts that blur into corporate systems.
The attack surface has expanded dramatically. In 2024, 4.3 million devices were infected by infostealers, malware that quietly harvests saved passwords, browser cookies, and credentials. These infections often start on personal devices used for work — a laptop shared with family members, a phone connected to an unsecured home Wi-Fi network, a work app installed on a personal tablet. Once an infostealer gets in, it can exfiltrate credentials for corporate systems, cloud services, and VPNs before anyone notices.
Phishing attacks have become more personal and more convincing. Generative AI allows attackers to craft emails that mimic a specific colleague’s voice, reference real internal projects, and request urgent action. Remote workers, often operating without the informal safety net of a nearby coworker to ask “did you get this weird email too?”, are more vulnerable. Forbes reports that 71% of employees knowingly take risky actions despite security training — not because they’re careless, but because the fastest path to finishing a task often bypasses security protocols.
Assuming a VPN solves everything. A VPN encrypts your connection to the corporate network, but it doesn’t protect against a stolen session token, a phishing email that tricks you into approving a login, or personal cloud backups that sync corporate files to an unsecured account. Security in a remote setup isn’t one tool — it’s a chain of small, consistent habits. The weakest link is almost always the gap between knowing the rule and following it under pressure.
Another growing threat is shadow IT — employees using personal Notion accounts, ChatGPT instances, or unapproved file-sharing apps for work tasks. A report on shadow AI found that 68% of employees use unauthorized AI tools, and 54% of that usage involves sensitive data. The convenience of these tools is real. The risk is that your company has no visibility into where your data is stored, who else can access it, or how it’s secured.
For context, 38% of all cyberattacks now target remote infrastructure, and 62% of breaches exploit weak or stolen remote credentials. The days of assuming the office firewall protects you are over. The new perimeter is wherever you open your laptop.
◈
What to Do About Both
The career risks and the security risks share a common thread: they both require you to be more deliberate about things that used to happen automatically in an office. Neither is a reason to give up remote work. But both are reasons to stop treating remote work as a passive arrangement.
For career visibility, the weekly summary I mentioned earlier is the single highest-leverage habit. Create a template, send it every Friday, and make it boringly consistent. Pair it with one virtual coffee chat per week and one in-person office visit per quarter if you can. That combination — routine documentation, intentional relationship-building, and periodic concentrated facetime — covers the bases that proximity used to cover for free.
For security, the baseline is simple but non-negotiable:
- Use a reliable VPN on every device you use for work, even for quick tasks. Make it automatic, not optional.
- Turn on multifactor authentication everywhere — corporate accounts, personal email, cloud storage. Use an authenticator app, not SMS, if you can.
- Keep your operating system and antivirus updated. Endpoint security software with real-time scanning catches many infostealer attempts before they take hold.
- Treat your browser as a high-risk endpoint. Don’t save work passwords in it, clear cookies regularly, and use separate browser profiles for work and personal activity.
- When you’re tempted to use a personal AI tool or file-sharing app for a work task, pause and ask: does my company have an approved version of this? If not, the fastest route is also the riskiest.
These aren’t glamorous steps. They’re the kind of maintenance work that’s easy to skip when you’re trying to get things done. But the research is clear that the gap between knowing and doing is where most breaches happen. The same applies to career advancement: knowing you need visibility isn’t the same as building the systems that create it.
There’s a related piece on the site that goes deeper into the hidden risks of job security in virtual workplaces, if you want to keep pulling on this thread.
Remote work isn’t going anywhere, and it shouldn’t. But the version of it that works long-term is the version where you’re intentional about visibility and security. That means a weekly summary to your manager, a VPN on every device, a quarterly office visit if you’re early in your career, and a much lower tolerance for convenience that bypasses security. The goal isn’t to be paranoid. It’s to stop treating the absence of a problem as proof that the problem doesn’t exist.