It's 7:20 on a Sunday night. Your estimator is at her kitchen table finishing three quotes that have to go out first thing Monday. She's on her own laptop, the one her son uses for games, remoted into the office PC through a program your last IT guy set up years ago. One password. No second step. Same login since 2019.
Nothing goes wrong that night. Nothing goes wrong for eight months.
Then on a Thursday at 5:55 in the morning, first shift clocks in and nobody can open a print.
Remote work security for a small manufacturer isn't really about whether people work from home. It's about the doors standing open into your shop network, who else knows where they are, and what happens to production when somebody walks through one. Here's the plain-English version we walk through with shops around Parkesburg and across Chester and Lancaster County.
Your Shop Has More Remote Access Than You Think
Most owners we talk to say the same thing: "We're a manufacturer. Nobody here works remote." Then we count the connections.
- The office manager who finishes payroll from home on Thursday nights
- The estimator quoting on a Sunday
- You, checking email on your phone from a customer's lobby
- An engineer opening SolidWorks or Mastercam files from a home PC
- The machine vendor who remotes into a controller when something acts up
- Your outside accountant with a login to the books
- The guy who left in March whose account nobody ever turned off
Every one of those is a door. A few of them you knew about.
Here's what sits behind those doors: the JobBOSS or E2 or Epicor database that tells you what job is where, the prints and CAM programs the floor pulls all day, your customer list and your pricing, open POs, quality records, and payroll. Lose access to that on a Thursday morning and the floor doesn't run. You can't pull a print, you can't tell a customer where their parts are, and you can't ship. By the following week you're on the phone with your biggest account explaining something you'd rather not explain.
There are also two outside forces pushing on this whether you like it or not. Your cyber insurance carrier now asks, in writing, whether multi-factor authentication is turned on for email and remote access before they'll renew you, which is worth understanding before renewal season arrives. Read up on what your cyber insurance carrier is actually asking for if you haven't seen an application lately. And sooner or later a Tier-1 customer sends over a vendor security questionnaire with a section on remote access that somebody has to answer truthfully.
What Remote Work Security Actually Looks Like in a 20-Person Shop
You don't need a security department. You need eight things done once and then kept up.
1. Multi-factor authentication on email and every remote connection
This is the single highest-value hour you will spend. A stolen password stops being useful the moment a second step is required. CISA's guidance for small businesses says the same thing in plain terms: turn multi-factor authentication on for email, file storage, and remote access, and start with the administrator accounts. Use an authenticator app rather than text messages where you can. Text codes are better than nothing and easier to steal than most owners realize.
2. Close the remote desktop door that's open to the internet
A lot of shops have a remote desktop connection published straight to the open internet because it was the fastest way to let somebody work from home five years ago. Those get found by automated scanners within hours of going live, and they get hammered around the clock. Anything that reaches into your network should sit behind a connection that requires a second step to open, not a port anybody on the internet can knock on.
3. Decide which computers are actually yours
There's a real difference between a company laptop you control and a family PC in a basement. On the machine you own, you can require encryption, push updates, and wipe it if it goes missing. On the family PC, you can do exactly none of that. You don't have to buy everyone hardware tomorrow. You do have to decide, on purpose, which machines are allowed to touch shop files, and then make the other ones work a different way.
4. Real endpoint protection on everything that connects
The free antivirus that came with the laptop watches for files it already recognizes. Modern protection watches behavior instead, so when something starts encrypting files at 2am it gets stopped and isolated before it spreads across the network to the file server. If you want the longer explanation, we broke down the difference between old antivirus and EDR in a separate post.
5. A password manager instead of the sticky note
Your office staff is juggling logins for the ERP, the bank, the shipping portals, three supplier sites, and email. Nobody remembers twelve strong passwords, so they reuse one good one everywhere. That's how one breach at some website you've never heard of turns into somebody reading your email. A business password manager fixes it and is genuinely easier for your people than what they're doing now.
6. Patching on a schedule, including the laptops that never come back to the shop
Unpatched software is one of the most common ways attackers get in, and it's the most boring problem on this list, which is exactly why it never gets done. Updates should install on a schedule, tested first and pushed overnight, on every machine including the ones that live at somebody's house. Nobody should be responsible for remembering.
7. Back up like you're going to need it, then prove it
Two questions decide how bad a bad morning gets: how long can the floor sit idle, and how much re-entered work can you live with. Your backup should be able to answer both, it should include the ERP database and the CAD files, and one copy has to sit somewhere the shop network cannot reach or overwrite. Then somebody has to actually restore from it before you need it. Untested backups fail at the worst possible moment. Here's a backup and recovery plan built for a shop if you want the full version.
8. Ten minutes a month beats an annual lecture
The office side is who gets targeted, usually with an email about an invoice or a shipping change or a password reset. Short monthly training and the occasional harmless test email work far better than one long presentation in January that everybody sleeps through. Make it about spotting the trick, not about punishing whoever clicks.
The 90-Day Version for Owners Who Don't Have a Spare Weekend
You don't have to do all of it at once, and you shouldn't. Order matters more than speed.
Days 1 to 30. Multi-factor authentication on email and every remote connection. Find and close anything exposed straight to the internet. List every account that can reach your systems and turn off the ones belonging to people who left. Confirm your backups are actually running.
Days 31 to 60. Modern endpoint protection on every machine that touches shop data. Roll out the password manager. Get patching on a schedule. Put monitoring in place that's watching at 9pm, because second shift is still your money.
Days 61 to 90. Test a real restore. Write the remote work rules on one page in words your people will actually read. Build the evidence folder for your next insurance renewal while everything is fresh.
The Quiet Bonus: An Easier Renewal and a Faster Answer for Your Biggest Customer
Everything above was worth doing on Thursday morning at 5:55 alone. The other payoff shows up at renewal time. Carriers are asking harder questions every year, and the shop that can answer yes with documentation gets a cleaner renewal than the shop guessing on the application. Same story when a customer's purchasing group sends a security questionnaire. The controls in this post are most of what those forms ask about, and having them already handled turns a two-week scramble into an afternoon.
Remote Work Security FAQs for Small Manufacturers
Do we really need MFA if we only have 15 people?
Yes. Attackers do not check your headcount before they try a stolen password. Most break-ins at shops your size start with one office login that was phished or bought somewhere else. Multi-factor authentication on email and remote access stops nearly all of that, and your insurance carrier is going to ask whether you have it either way.
Is a VPN enough to secure remote access?
A VPN encrypts the connection, but it does not verify who is on the other end. If someone steals a password, the VPN carries them straight into your network. Pair remote access with multi-factor authentication, keep the VPN appliance patched, and give every person their own login instead of one shared account the whole office passes around.
Can my office staff work from their home computers?
They can, but it is the riskiest option on the table. A home PC shared with kids and games has no protection you control and no way to wipe it if it walks off. A company laptop you manage is the cleaner answer. If that is not in the budget this year, at least keep shop files off the personal hard drive.
What does cyber insurance require for remote access?
Carriers vary, but most renewal applications now ask whether multi-factor authentication is turned on for email, remote access, and administrator accounts, and whether backups are kept separate from the network. Answer honestly. A wrong yes on the application gives the carrier a reason to fight the claim at the exact moment you need it paid.
Is OneDrive or SharePoint a backup for our CAD files?
No. Sync is not backup. When a file gets encrypted or deleted on a laptop, sync faithfully copies that change up to the cloud. Version history buys you a little room and usually not enough after ransomware. You want a separate backup the shop network cannot reach, overwrite, or encrypt.
What is the fastest thing we can fix this week?
Turn on multi-factor authentication for email, then find out what is exposed to the open internet. Those two take a few hours and close most of the easy ways in. After that, list every account that can reach your systems and shut off the ones belonging to people who no longer work there.
Not Sure Who Can Get Into Your Network Right Now?
Starlux IT is in Parkesburg, and we work with small manufacturers around Coatesville, Downingtown, Gap, and across Chester and Lancaster County. We know what a file server full of SolidWorks files means to a shop, we monitor around the clock because second shift is still running at 9pm, and we put together the cyber insurance documentation you can hand straight to your broker. When something needs hands on it, our techs are local and on-site the same day. Our managed IT plans built around shops your size cover the whole list above.
Give us 30 minutes. No pressure and no pitch. We'll look at what you have, show you which doors are open, and you'll know exactly where you stand whether you hire us or not.