An offshore team member should be treated like any other trusted person with access to your business systems.
The location changes. Your responsibility to protect client, employee and commercial information does not.
Good security is less about one expensive tool and more about controlling access, using sensible systems and making sure everyone knows what to do if something goes wrong.
1. Give people only the access they need
Start with the principle of least privilege.
Each team member should only be able to access the systems, folders, records and customer information required for their role.
Practical steps include:
- create individual user accounts instead of shared logins;
- use role-based permissions;
- separate sensitive folders and systems;
- regularly review who has access to what; and
- remove access immediately when a role changes or an engagement ends.
2. Turn on multi-factor authentication
Multi-factor authentication should be enabled on every important account, especially:
- email;
- cloud storage;
- accounting software;
- CRM and customer databases;
- password managers;
- social media accounts; and
- website and advertising platforms.
This is one of the simplest ways to reduce the damage caused by a stolen password.
3. Use a password manager
Do not send passwords through email, chat or spreadsheets.
Use a reputable business password manager so you can:
- share access without exposing the underlying password;
- revoke access quickly;
- avoid password reuse;
- require stronger passwords; and
- keep an audit trail of shared credentials.
4. Keep work inside approved systems
Use business-managed tools such as Google Workspace or Microsoft 365 for files, email and collaboration.
For sensitive roles, consider:
- blocking local downloads;
- restricting external sharing;
- limiting copy and paste;
- controlling login locations or devices;
- using a managed browser or cloud desktop; and
- keeping customer data out of personal accounts.
The right level of control depends on the type and sensitivity of the information involved.
5. Secure devices and networks
Require practical device standards, including:
- supported operating systems and current software updates;
- reputable endpoint protection;
- automatic screen locking;
- full-disk encryption where available;
- secure home Wi-Fi;
- no use of public or shared computers;
- prompt reporting of lost or compromised devices; and
- a VPN where it is appropriate for the client’s systems and risk profile.
6. Put confidentiality and data obligations in writing
Contracts should clearly cover:
- confidentiality;
- permitted use of business and personal information;
- intellectual property ownership;
- approved systems and storage;
- incident reporting;
- return or deletion of information;
- subcontracting restrictions; and
- obligations that continue after the engagement ends.
Team Hatch uses candidate, client and contractor agreements to support these obligations across the relevant service model.
7. Be careful with personal information
Australian businesses may have obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles and industry-specific rules.
Where personal information is accessible from the Philippines, businesses should consider:
- whether access or disclosure is necessary;
- what privacy notices and consents are required;
- cross-border disclosure requirements;
- whether the recipient is contractually required to protect the information;
- whether sensitive information needs stronger controls;
- record retention and deletion; and
- what will happen if there is a suspected data breach.
The Philippines also has its own Data Privacy Act of 2012. Businesses should obtain professional advice about the laws that apply to their specific operations and data.
8. Train people before giving access
Security policies are only useful if people understand them.
Onboarding should cover:
- phishing and social-engineering attempts;
- password and multi-factor authentication rules;
- approved tools and storage locations;
- handling customer and employee information;
- restrictions on downloading or sharing files;
- what counts as a security incident; and
- who to contact immediately if something goes wrong.
Short refresher sessions are usually more useful than a policy document nobody opens again.
9. Have a simple incident-response plan
Every business should know what to do if an account, device or file may have been compromised.
At a minimum:
- Report the incident immediately.
- Disable or reset affected access.
- Preserve relevant records and logs.
- Identify what information may be involved.
- Contain the issue and prevent further access.
- Assess legal, contractual and notification obligations.
- Document the response and fix the underlying weakness.
If the Australian Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, the business may need to notify affected individuals and the Office of the Australian Information Commissioner.
10. Review access when people leave
Offboarding should happen on the final day, not a week later when someone remembers.
Use a checklist to:
- disable accounts;
- revoke sessions and password-manager access;
- recover or remotely wipe managed devices where applicable;
- transfer ownership of files and accounts;
- rotate shared credentials;
- remove access from customer and supplier systems; and
- confirm that confidential information has been returned or deleted.
Keep it practical
Most businesses do not need a dramatic cybersecurity overhaul before working with offshore talent.
They need clear contracts, individual accounts, controlled access, multi-factor authentication, secure password sharing, sensible device rules and a proper offboarding checklist.
Team Hatch can help clients build those basics into the onboarding process. For regulated industries, sensitive information or complex environments, we recommend getting advice from a qualified privacy, legal or cybersecurity professional.