WGU D490 Risks Resulting from Remote Resources – Max Anderson |
Actual verified study set complete Solutions | 2026 Updates | 100% correct
Risks Resulting from Remote Resources
MCSIA from Western Governor’s University
D490 Cybersecurity Graduate Capstone
Brett Schaefer
7/14/26
, Table of Contents
A. Security Problem Under Investigation
3
B. Stakeholders
7
C. Historical Data
16
D. Implementation Procedures and Docummentation
19
E. Training
26
F. Cost of Remote Resources
28
G. Deliverables and Timeline
31
H. Project Evaluation
34
I. Conclusion
39
, Security Problem Overview
A mid-sized and growing company named Workhorse Tools has seen an increase in the
demand for customer service facing roles as they have secured and will continue to likely secure
contracts with businesses and individuals for the products and services that they provide. The
increase in business meant an increase in production, but the headquarters where the company
conducts all its financial transactions is a somewhat isolated area on the east coast. For this
reason, and for the sake of space and property, they have decided to start outsourcing some new
roles to individuals working from a remote location. The prudent problem here is that they are
worried about the security of their transactions and interactions while performing business using
these resources. IT awareness just isn’t at the forefront of the company, and there has been proof
that there are some major risks that can come with outsourcing services.
Since the adoption of remote work due to the COVID-19 pandemic, businesses have
begun to outsource jobs to globally isolated individuals at an increasing rate. In the aspects of
business practicing sales, remote work has expanded over 30% in Q1 of 2026 (Chorpenning,
2025). The job force is growing, but so are the risks. From 2019-2024, organizations reported
that insider attacks increased from 66% to 76%, with up to 55% of insider threat indicators being
linked directly to remote employees (Above Security, 2025). Bringing in remote employees
increases the overall attack surface of your threat profile, drastically. Every new end point
introduced to your internal network is a new potential threat horizon. The data that is transmitted
and stored on each respective device brings new risk into the equation. IBM’s report stated that
the average cost of a data breach was $4.4 million in 2025 (Sheldon, 2026).
, Targeting end points is one thing, but trends have shown that not only are the users being
targeted, but the infrastructure used to store this data. That means using compromised credentials
to target internal services, compromising the authenticity of stored or transmitted data. Attackers
may even go so far as to modify the configuration settings, restricting access and causing a
denial of service – essentially a ransomware attack (Sheldon, 2026). Remote workers rely on
authentication means to prove their access to data, but it is ever more evident that there are risks
when accessing this data. If these credentials are ever compromised, then the access that the mid-
level employee 1,000 miles away may be abused by any number of malicious actors. Remote
employees tend to be laxed when securing the system they are operating on. It may be using the
remote desktop protocol with an outdated patch, or some other oversight. One article stated that
“58% of respondents said their employees lack the tools or skills to secure data properly”
(Watson, 2025). It may not be an individual’s intentions to exploit data, but without proper
oversight, they can unwillingly be a cog in a threat actor’s scheme.
To collectively summarize and specify the risks, an overall consumption of evidence and
data shows these threats to propose the problem. Remote employees may not be informed from a
security aspect, and may be subject to unintentional insider threats, such as ransomware, social
engineering, or phishing, which can lead to a substantial breach (Pratt, 2024). Moving along with
the ideology that the individuals aren’t informed of the subject, there may be use of improper or
insecure devices or methods. This needs oversight and management to allow and configure
access accordingly. The accounts need to be centrally managed and maintained. In the haste of
implementing remote solutions, IT may forget to apply certain stringent access controls, leaving
the door wide open once an account is compromised. Staying in the theme of acceptable use,
there is also the possibility of shadow IT, which is the unauthorized use of applications to
Actual verified study set complete Solutions | 2026 Updates | 100% correct
Risks Resulting from Remote Resources
MCSIA from Western Governor’s University
D490 Cybersecurity Graduate Capstone
Brett Schaefer
7/14/26
, Table of Contents
A. Security Problem Under Investigation
3
B. Stakeholders
7
C. Historical Data
16
D. Implementation Procedures and Docummentation
19
E. Training
26
F. Cost of Remote Resources
28
G. Deliverables and Timeline
31
H. Project Evaluation
34
I. Conclusion
39
, Security Problem Overview
A mid-sized and growing company named Workhorse Tools has seen an increase in the
demand for customer service facing roles as they have secured and will continue to likely secure
contracts with businesses and individuals for the products and services that they provide. The
increase in business meant an increase in production, but the headquarters where the company
conducts all its financial transactions is a somewhat isolated area on the east coast. For this
reason, and for the sake of space and property, they have decided to start outsourcing some new
roles to individuals working from a remote location. The prudent problem here is that they are
worried about the security of their transactions and interactions while performing business using
these resources. IT awareness just isn’t at the forefront of the company, and there has been proof
that there are some major risks that can come with outsourcing services.
Since the adoption of remote work due to the COVID-19 pandemic, businesses have
begun to outsource jobs to globally isolated individuals at an increasing rate. In the aspects of
business practicing sales, remote work has expanded over 30% in Q1 of 2026 (Chorpenning,
2025). The job force is growing, but so are the risks. From 2019-2024, organizations reported
that insider attacks increased from 66% to 76%, with up to 55% of insider threat indicators being
linked directly to remote employees (Above Security, 2025). Bringing in remote employees
increases the overall attack surface of your threat profile, drastically. Every new end point
introduced to your internal network is a new potential threat horizon. The data that is transmitted
and stored on each respective device brings new risk into the equation. IBM’s report stated that
the average cost of a data breach was $4.4 million in 2025 (Sheldon, 2026).
, Targeting end points is one thing, but trends have shown that not only are the users being
targeted, but the infrastructure used to store this data. That means using compromised credentials
to target internal services, compromising the authenticity of stored or transmitted data. Attackers
may even go so far as to modify the configuration settings, restricting access and causing a
denial of service – essentially a ransomware attack (Sheldon, 2026). Remote workers rely on
authentication means to prove their access to data, but it is ever more evident that there are risks
when accessing this data. If these credentials are ever compromised, then the access that the mid-
level employee 1,000 miles away may be abused by any number of malicious actors. Remote
employees tend to be laxed when securing the system they are operating on. It may be using the
remote desktop protocol with an outdated patch, or some other oversight. One article stated that
“58% of respondents said their employees lack the tools or skills to secure data properly”
(Watson, 2025). It may not be an individual’s intentions to exploit data, but without proper
oversight, they can unwillingly be a cog in a threat actor’s scheme.
To collectively summarize and specify the risks, an overall consumption of evidence and
data shows these threats to propose the problem. Remote employees may not be informed from a
security aspect, and may be subject to unintentional insider threats, such as ransomware, social
engineering, or phishing, which can lead to a substantial breach (Pratt, 2024). Moving along with
the ideology that the individuals aren’t informed of the subject, there may be use of improper or
insecure devices or methods. This needs oversight and management to allow and configure
access accordingly. The accounts need to be centrally managed and maintained. In the haste of
implementing remote solutions, IT may forget to apply certain stringent access controls, leaving
the door wide open once an account is compromised. Staying in the theme of acceptable use,
there is also the possibility of shadow IT, which is the unauthorized use of applications to