Share of Employees Working From Home
Home office share records the proportion of staff regularly working remotely rather than at a company premises, relevant to occupational accident classification and cyber exposure underwriting.
- Category
- People · %
- Data type
- Number
- Risk drivers
- Frequency, Accumulation
- Underwriting impact
- Premium, Condition/Warranty, Exclusion
Typical proposal-form questions
- What proportion of employees work from home on a regular or permanent basis, and for how many days per week?
- What devices, network access and data are home-office employees using or handling remotely?
- What security controls (VPN, multi-factor authentication, endpoint protection) apply to remote access?
Evidence
- HR remote-work policy and headcount split by work location
- IT asset and remote-access inventory
- Endpoint security and VPN configuration documentation
Why it matters for underwriting
A significant home-office share changes the risk profile on two distinct fronts. For occupational accident cover, the boundary between covered work activity and private, non-work incidents at home is harder to establish than on company premises, which affects claims adjudication and, in some jurisdictions, the split between occupational and non-occupational accident cover. For cyber risk, a large remote workforce expands the attack surface through home networks, personal devices and distributed access points that are typically less controlled than a centralised corporate network, increasing the likelihood and potential severity of a breach.
Capturing the attribute and evidence
Underwriters ask for the proportion of staff working from home regularly or permanently, the typical number of remote working days per week, and what data, systems and devices those employees access remotely. Evidence includes the HR remote-work policy with headcount split by location, the IT asset and remote-access inventory, and documentation of the security controls, such as VPN and multi-factor authentication, applied to remote connections.
Effect on coverage, premium and conditions
A higher home-office share without commensurate endpoint and network security controls typically increases cyber premium and can trigger a condition requiring minimum security controls such as mandatory multi-factor authentication and encrypted remote access, with declinature possible for organisations with weak or undocumented controls. On the accident side, the share mainly affects claims handling practice and wording clarity rather than premium directly, but insurers may request a clear remote-work policy defining insured working hours and locations.
Mitigation measures
Recommended measures include enforcing a documented remote-work policy with clearly defined working hours and locations, mandating VPN and multi-factor authentication for all remote access, maintaining an up-to-date inventory of devices used off-premises, and providing security awareness training tailored to remote-work risks such as phishing and unsecured home networks.
Standards and codes
- ISO 31000:2018 – Risk management, Guidelines