{
  "id": 10400829,
  "title": "Remote & Hybrid Work Security: What Small Businesses in New Mexico Get Wrong",
  "url": "https://urgent.news/2026/09/28/remote-hybrid-work-security-what-small-businesses-in-new-mexico-get",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T08:09:35.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/zianetworksinsight/remote-hybrid-work-security-what-small-businesses-in-new-mexico-get-wrong-amg"
  },
  "original_language": "en",
  "account": "Small business owners in New Mexico often struggle to secure their remote and hybrid work environments. Most security breaches aren't from advanced attacks, but rather stem from five common issues.\n\nFirst, passwords are the primary entry point. If a password is stolen or reused, hackers can gain access to various systems. The solution is to implement multi-factor authentication (MFA) for all accounts, especially email, which can act as a gatekeeper to reset other credentials. Using authenticator apps or hardware keys is preferable over SMS-based verification. A password manager can help prevent password reuse across different platforms.\n\nSecond, unmanaged devices and home Wi-Fi networks pose significant risks. Outdated laptops and routers with default admin passwords provide easy access points. Regularly updating software, enabling full-disc encryption, and setting up a robust password for the router are essential measures. Staff should be reminded of these security checks regularly.\n\nThird, employees may inadvertently share sensitive information due to urgent requests, especially when working from home. It's crucial to establish a policy where any request involving money transfers or changes to payment details must be verified by phone using a pre-existing contact number. Encouraging a safe reporting culture for mistakes is also vital, as delays can exacerbate security incidents.\n\nFourth, backup systems often remain untested. The \"3-2-1 rule\" is recommended: maintain three copies of data, store two of them on different types of media, and keep one backup offline or in a remote location. Verifying backups through restoration ensures data can be recovered if needed. A recurring reminder in the calendar can help maintain this routine.\n\nLastly, legal requirements regarding data breaches vary, including New Mexico's Data Breach Notification Act. Businesses must comply with relevant regulations like HIPAA, PCI DSS, and federal standards such as NIST SP 800-171 and CMMC. Creating an incident response plan with contact information for IT support, cyber insurance providers, and legal counsel is crucial. Staying informed about applicable laws and thresholds through legal consultation is advisable.\n\nFor immediate steps, businesses should ensure multi-factor authentication is enabled for their email systems. Numerous resources are available, including small business development centers in New Mexico, CISA's free resources for small organizations, and advice from cyber insurance carriers, which may offer free risk assessments. This guidance provides a foundation for addressing the most common security gaps faced by small businesses.",
  "summary": "If you're the developer, freelancer, or \"computer person\" at a small business, you probably also became the IT department. Remote and hybrid work made that job bigger: company data now lives on home routers, personal laptops, and cloud accounts nobody audits. I'm writing this with New Mexico small businesses in mind, but the fixes apply anywhere. Most small business breaches aren't sophisticated.…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}