About two years ago, most IT governance frameworks were designed around an assumption that the majority of an organization’s workforce operated from fixed locations on managed devices connected to a corporate network. Remote work existed as a defined exception with specific policies governing it. The pandemic invalidated that assumption almost instantly, and organizations improvised their way through the transition with a combination of VPN capacity expansions, rapid endpoint management deployments, and a lot of policy exceptions that were supposed to be temporary.
Many of those exceptions are now the permanent operating model. Organizations that tried to mandate full return to office have discovered that the labor market does not currently support that position in most sectors. Hybrid work, where employees split time between home and office, is the settled reality for a large portion of the knowledge workforce. IT governance frameworks that were not updated during the transition are running on foundations that do not accurately reflect how the organization operates.
What needs to change in the governance framework when hybrid work is permanent rather than exceptional?
Access control policies need to reflect the reality that corporate resources are being accessed from a range of network environments, not just from the corporate network or from identifiable remote access connections. The policy that says access to sensitive systems requires connection through the corporate VPN works fine as long as the VPN is an exception. When half your workforce uses it every day it becomes an infrastructure bottleneck and organizations have been moving toward zero trust network access models that do not require VPN as the controlling mechanism. The governance framework needs to authorize and govern that approach, not just document the old one.
Device management policies face a similar pressure. Managed corporate devices are standard in larger enterprises, but hybrid work has increased the frequency of employees using personal devices for work purposes, the incidence of corporate devices operating outside managed network environments for extended periods, and the need for remote endpoint management capabilities that go beyond what a perimeter-based security model required. BYOD policies that were drafted as exceptions need to become primary governance documents in organizations where personal device use for work is routine.
Data governance is the area where hybrid work has created the most nuanced new challenges. When employees work from home, data moves in ways that the governance framework may not have anticipated. Files get stored in personal cloud storage. Sensitive documents get printed on home printers. Video calls about confidential matters happen in home environments with family members present. These are not just policy questions. They are risk questions that require genuine governance attention.
The COBIT framework, which ISACA maintains, provides governance and management objectives that map well to these challenges. The current COBIT guidance is available through ISACA’s COBIT resources and is worth reviewing as a reference when updating IT governance frameworks for hybrid work environments. Governance professionals who can help organizations bring their frameworks in line with how work actually happens are doing genuinely valuable work right now.
Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.
