Business security risks rise as international hiring grows, experts warn
81% of UK-based employers who already have employees overseas intend to increase their workforce abroad, according to new data. International hiring is also rising across the world, driven by structural skills shortages, and a strategic shift by companies to source specialised talent globally.
While international hiring gives businesses access to a much wider pool of talent, each new overseas hire can also introduce additional endpoints, user accounts, devices, locations and access pathways that need to be properly secured. Given that 43% of businesses experienced a cyber security breach or attack in the last year, companies must have suitable measures in place for overseas hires.
To help businesses build a global workforce without creating unnecessary security and compliance risks, the Employer of Record experts at Teamed have revealed the cyber security and data protection mistakes employers make when hiring overseas. Joanna Castens, chief legal officer at Teamed, provides expert insight on the practical steps businesses should take to securely onboard international employees, protect sensitive data, and maintain compliance while building a global workforce.
Joanna continues “As international hiring becomes a more important part of how businesses access the skills they need, security and compliance need to be considered from the outset. The latest data shows that 43% of businesses experienced a cyber security breach or attack in the last year, so businesses should be examining how their international workforce is accessing systems and data. Clear processes around onboarding, access, devices and offboarding can help businesses build a global workforce without creating unnecessary security risks.”
Five security mistakes businesses make when building an international workforce
Treating international onboarding like standard domestic onboarding
It can be tempting to assume that the same onboarding process used for domestic employees will work for overseas hires too. But hiring internationally can mean differences in devices, access, identity verification, security policies and local requirements. Companies should take steps from day one, such as setting up multi-factor authentication (MFA), ensuring accounts are created through approved systems, and establishing appropriate endpoint security before employees are given access to sensitive information. Building these steps into the onboarding process early can help prevent security gaps before they become a problem.
Joanna Castens explains: “International onboarding requires more planning than domestic onboarding, including country-specific employment documentation and local requirements. From a risk perspective, businesses should be clear from the start about what information is being collected, who needs access to it, and which teams are responsible for each part of the process. Addressing those questions before someone starts reduces the risk before they gain access to company systems.”
“For example, in the UK, a right-to-work check must be completed before employment starts. Where a new hire holds an eVisa, HR should obtain the individual’s share code and date of birth, carry out the employer check through the Home Office service, confirm that the resulting photograph matches the individual, and retain a dated copy of the result. The process is also changing: from 1 October 2026, the UK right-to-work regime is due to extend to certain worker-contract, individual subcontractor and online-matching arrangements.”
Ignoring data protection requirements across different countries
International employees can create additional considerations around how employee and company data is collected, stored, accessed and transferred across borders. Businesses need to understand the data protection requirements that apply to their international workforce and ensure their processes reflect them.
“Businesses should avoid assuming that their domestic processes can simply be applied elsewhere. The GDPR expressly lets each Member State write more specific employment rules, including on workplace monitoring. In Germany for example, a works council has co-determination rights over any system capable of monitoring behaviour or performance. Monitoring tools, endpoint management and productivity software are all sensitive here.
“In France monitoring has to be justified, proportionate, transparent, and never continuous or systematic.
“In Italy tools capable of remote monitoring can require a prior union agreement or labour-inspectorate authorisation, even when the reason is security or organisation. That is a real constraint on invasive endpoint monitoring and device management.”
Failing to properly offboard international employees
Security shouldn’t stop when an employee leaves. Businesses need to ensure accounts and permissions are promptly revoked, company devices and data are recovered, and access to company systems is removed, no matter where the employee is based. This can include disabling user accounts, revoking authentication tokens and removing access to cloud applications, shared drives and other company resources.
“Local employment processes can affect when an employee’s employment can formally end, adding additional complexity. This is where cross-border employers most often trip up. In much of Europe, a dismissal is not effective until set steps are complete and formal notice has gone out. Pulling all accesses too early can prejudice this process. At the investigation stage, restrict only the access that presents a genuine security or evidence risk. During notice or garden leave, reduce access in line with the contract and local law, while keeping anything the employee needs to exercise their rights. On the effective termination date, remove access to all systems, keeping only controlled access needed for payroll, tax, equity or post-exit cooperation.”
Allowing employees to use unsecured, personal devices
Personal laptops, phones and other devices rarely have the same security controls as company-managed equipment. Businesses should consider basic endpoint controls such as device encryption, security updates, anti-malware protection and the ability to remotely lock or wipe company data where appropriate. Without clear BYOD (Bring Your Own Device) policies and minimum security requirements, businesses risk exposing sensitive company data through unpatched software, malware, lost devices or shared equipment.
“A personal device combines work data with private information, so a policy on its own will not justify intrusive technical control. If BYOD is permitted, it should be voluntary, with a company device available as a genuine alternative. Businesses should use a segregated workspace or managed apps, apply measures such as MFA and encryption, and be transparent with employees about what the employer can access. Where possible, they should also restrict local downloads of high-risk HR, client, financial or special-category data.”
Failing to recognise public Wi-Fi risks
When an international hire is working remotely, it’s worth considering where they’ll be working. If they’re in a public space such as a café or co-working space, this creates additional risk when accessing company systems over unsecured public networks.
“Businesses also need to consider the risks created when employees access company systems from overseas. Working abroad does not necessarily mean that personal data is being transferred internationally, but businesses should still consider the destination, the sensitivity of the information being accessed and the risks of device seizure, local access demands or insecure networks. Employees working from cafés, co-working spaces or other public locations should use company-approved security controls such as MFA and encrypted connections wherever possible.”

