Article Reviewed by a licensed insurance professional: Sam Meenasian (CA dept of insurance license #0F75955).
Estimated reading time: 5 minutes
Remote and hybrid work are no longer temporary workarounds. In 2025, the U.S. Bureau of Labor Statistics reported that 22.4% of people at work teleworked at least some hours, and 10.5% teleworked all hours. That means remote work remains a material commercial insurance issue for many employers, especially around cybersecurity, data handling, workplace injury, and off-premises property.
The Rise of Remote and Hybrid Work
Remote work was far less common before 2020. BLS reported that 6.5% of private-sector workers worked primarily from home in 2019, and the Census Bureau reported that 5.7% of workers primarily worked from home that year. The pandemic sharply increased remote work, but today’s market is better described as a mix of remote and hybrid arrangements rather than a permanent full-time-at-home model for nearly half the workforce.
Official labor data also show that full-time-at-home work is only part of the picture. In the first quarter of 2024, the overall telework rate averaged 22.9%, and among teleworkers, 47.9% worked all hours from home, down from 54.0% a year earlier. For insurance planning, that distinction matters because part-time telework, employee-owned devices, and off-premises equipment can create many of the same coverage questions as full-time remote work.
The Main Risks Businesses Need to Manage
Cybersecurity is usually the first risk to change under remote work. NIST’s telework guidance says companies should assume external environments, networks, and devices contain hostile threats, and it recommends a written telework security policy, tiered remote access, secured client devices, encryption, and strong authentication, preferably MFA, for enterprise access. NIST also notes that MFA adds an important security layer because passwords alone are often too easy for attackers to compromise.
Data privacy and compliance can also become more complicated. HIPAA does not apply to every employer. It applies to covered entities and business associates. GDPR can apply not only to businesses based in the EU, but also to certain non-EU organizations that target or monitor people in the EU. When remote teams use cloud vendors, personal devices, home printers, or shared networks, businesses need clear rules for access, storage, retention, and incident escalation.
Employee injury and workplace safety do not disappear just because work happens at home. OSHA says the OSH Act applies to work performed in a workplace located in an employee’s home, but OSHA also says it does not expect employers to inspect employees’ home offices. Employers should still provide ergonomic guidance, and for a home injury to be treated as work-related, state workers’ compensation rules typically look at whether the employee was being paid to work and whether the injury was directly related to work duties. Neutral workstation setup, posture changes, and regular movement are important controls.
Property and downtime exposures are often overlooked. Homeowners and renters policies are rarely adequate for business-related property loss or business liability, and the NAIC says many personal policies limit business property coverage to $2,500 in the home and $250 away from home. If remote employees rely on laptops, monitors, printers, paper files, or specialized equipment, the business should review commercial property, business personal property, off-premises property, and inland marine or equipment floater options. It should also understand that property-based business interruption usually requires a covered event that causes physical property damage.
How Commercial Insurance Responds
Cyber insurance is usually the most direct response to remote-work cyber risk. The NAIC says most commercial property and general liability policies do not cover cyber risks, and the FTC says businesses should review whether a cyber policy includes first-party coverage, third-party coverage, or both. Important items to confirm include data breaches, attacks on vendor-held data, worldwide incidents, business interruption, legal counsel, customer notification, forensic services, crisis management, cyber extortion, fraud, and duty to defend.
Workers’ compensation and commercial general liability should be explained separately, not blended together. NAIC guidance says CGL typically covers third-party bodily injury and property damage claims, while employee claims for work-related injury or loss are typically handled through workers’ compensation. Most states require employers to carry workers’ compensation for employees, but exact obligations and coverage questions vary by state and by who qualifies as an employee.
Property coverage also deserves more attention in remote-work articles. A business owner’s policy typically combines property, business interruption, and liability coverage, and many insurers customize BOPs for different businesses. But a BOP does not replace separate cyber coverage, and it typically does not include workers’ compensation. Remote-work businesses may also need endorsements or separate forms for off-premises business personal property, client property in their care, or equipment that travels between locations.
For service firms, professional liability can be just as important as cyber or general liability. The NAIC notes that some professionals working from home may need professional liability or errors and omissions coverage. That is especially relevant when employees give advice, handle sensitive client information, prepare reports, or deliver remote professional services where the alleged loss is financial rather than physical.
What Businesses Should Ask Before Renewal
The best remote-work insurance review starts with operations, not with policy marketing language. Businesses should document who works remotely, what devices they use, where data is stored, whether vendors hold sensitive data, whether clients visit home offices, and whether any employees or customers create cross-border compliance obligations. Then they should ask their broker or carrier how those facts map to policy wording, exclusions, sublimits, endorsements, territory provisions, and claims reporting requirements.
A practical review should also distinguish between property business interruption and cyber business interruption. Property forms usually look for direct physical loss from a covered peril, while cyber forms may respond to lost income from a covered cyber event. That distinction is critical for remote-heavy businesses that depend on cloud systems, collaboration platforms, and vendor-hosted data.
Conclusion
Remote work did not create one new insurance problem. It changed the shape of several existing ones. Cyber exposure, vendor risk, workers’ compensation, off-premises equipment, E&O, and cross-border data rules all deserve a place in the conversation. The strongest insurance program is not the broadest promise on a webpage. It is a program whose coverage wording, operational controls, and claims process match how the business actually works.











