It’s 3:47 on a Friday afternoon. Your Controller is at the cottage, “just checking one thing” on the club laptop while the kids fight over the dock. Your Membership Director is sipping a latte at a café, replying to a new-member welcome packet from her phone. And you, the GM, are answering a board question from the kitchen table because the dishwasher repair guy is finally here.
This is remote work at a private club in 2026. It’s not “should we do it?” anymore – it’s “are we doing it well?”
Most clubs aren’t fully remote, and they never will be. The front of the house can’t Zoom in to plate a tasting menu. But the back-office side – finance, membership, HR, marketing, the GM’s inbox – runs on flexibility now. That’s a good thing for staff retention, and a great thing for the calibre of talent you can hire. It’s also where almost every cybersecurity incident in our industry starts.
So let’s get practical. Here’s how forward-thinking GMs are running remote work without losing sleep.
1. VPN + MFA is the front door. Lock it
If your staff log in from outside the club without going through a VPN and a second verification step (MFA – usually a code on their phone), you’ve got a problem you can’t afford.
Plain English: a VPN is an encrypted tunnel between the laptop at home and your club’s systems. MFA is the “yes, it’s actually me” check after the password. Together, they stop the overwhelming majority of credential attacks aimed at clubs – and clubs are aimed at constantly, because attackers know our members are high-net-worth and our IT has historically been lean.
If you’re not 100% sure whether every remote login at your club uses VPN + MFA, that’s the first question to ask your IT provider this week. The answer should be a clean “yes.”
2. Treat home Wi-Fi like a club asset
The home network of your Controller is now part of the club’s attack surface.
A reasonable home Wi-Fi setup for anyone with club access:
- A non-default router password (the sticker on the bottom of the router doesn’t count)
- Firmware updates turned on (most routers do this automatically once enabled)
- A separate guest network for kids, visitors, smart fridges, and that one questionable thermostat
- A strong Wi-Fi password – not “Smith2018”
Pass-along tip: if a team member’s home router is more than five years old, it’s time. Tell finance.
3. Write the BYOD policy. Then actually enforce it
BYOD (“bring your own device”) is when staff use personal phones or laptops for club work. Most clubs have this happening informally – managers checking email on personal iPhones, accountants pulling up reports on a home iPad. It’s fine but it’s also a leak waiting to happen unless someone’s written down the rules.
What a real BYOD policy covers:
- Passcode or biometric lock required on any personal device touching club data
- No club data over public or unsecured Wi-Fi (no, not even the airport – not even “just this once”)
- A work container or business profile that keeps club apps separate from personal stuff
- The club’s right to remotely wipe the work container if the device is lost or the employee leaves
That last point is the one staff usually appreciate, by the way. They don’t want their personal photos wiped. A business profile means you wipe the work bucket only, and their kid’s birthday videos stay safe.
4. Slow. Down. On wire transfers and “urgent” emails
This is the practice that separates a normal week from a very bad week.
Here’s a scenario we’ve seen play out at clubs more than once. David, the Controller of a yacht club, gets an email at 4:00 on a Friday. The display name and signature match the GM, who David knows is traveling. It reads:
“David, I need your urgent help. We’re closing a confidential deal for a new fleet of sailboats and I need you to wire $38,500 before the end of the day to secure the order. This is highly time-sensitive and confidential – please do not discuss it with anyone else.”
David trusts the GM. He wires it but the email was fake. The money’s gone.
Remote work makes this attack easier, because the hallway version of “hey, are you actually emailing me about this?” doesn’t happen anymore. So build the policy:
- Any wire transfer above a set threshold requires a verbal confirmation by phone – using a number you already have, not the one in the email
- Vendor banking changes require the same verbal check
- “Urgent + confidential + don’t tell anyone” is the exact phrasing scammers use. Treat it as a huge red flag.
Walk your finance team through this once. Then walk them through it again in three months. The repetition is the point.
5. Get everyone on a password manager – including the board
A password manager creates and stores a unique, strong password for every account, behind one master password. It sounds like extra work; it actually saves time once it’s set up. More importantly, it removes the single human habit that causes most breaches: reusing the same password in five places.
Pair the password manager with MFA on the password manager itself, and you’ve taken one of the cheapest, highest-impact security steps available to a club.
Yes, this includes board members. Especially board members. They’re high-profile, their personal email is a target, and they often have access to sensitive committee documents from devices nobody at the club has ever seen.
6. Define when remote works and when it doesn’t
This one isn’t a security tip but a management one. It’s the question GMs ask us about really often, so it earns its spot.
Remote work has trade-offs at a club. Member-facing roles need to be on property. Finance can run from anywhere most weeks – but not during close. Membership outreach is half on-site and half wherever the calls happen. HR runs hot during onboarding seasons and cool the rest of the year.
The clubs that handle this well don’t draw a hard line – they draw a calendar. Who’s expected where, when, and why. Written down and reviewed quarterly. It saves you the awkward “where is everyone today?” conversation, and it protects the people who do excellent work from home from looking absent.
7. Have a “the laptop got stolen” plan
Picture this: your assistant controller’s laptop is taken from the back seat of a car on a Saturday night. What happens Monday morning?
Clubs we work with that have a plan answer this in under an hour: device wiped remotely, credentials rotated, MFA re-enrolled, encrypted member data confirmed safe, club continues running. Clubs without a plan answer it in three weeks – with a forensic firm, a letter to members, and a very long board meeting.
Write the plan and practice it once. You will not regret it.
Quick wins for this month
If you only do three things from this list, do these:
- Confirm with your IT provider that every remote login uses VPN + MFA. If it doesn’t, fix it.
- Walk your finance team through the verbal-confirmation rule for wire transfers and vendor banking changes.
- Get yourself on a password manager. Then nudge the board to do the same.
That’s it. Three steps, an afternoon of work, and you’ve eliminated a meaningful chunk of risk.
Conclusion
Remote work isn’t a security problem – it’s a security context. The clubs doing it well aren’t running scared; they’re running clearly. Clear policies, clear tools, clear “who calls whom when something looks off.”
If you’d ever like a second pair of eyes on how your club’s remote setup is holding up, that’s what we do all day at Club Support. We’ve spent 20+ years working only with private clubs across Canada and the U.S., so your operations are not a mystery to us – we know what a Friday close looks like, and we know why your tournament weekend can’t have an outage. Happy to share what we’re seeing across the clubs we serve anytime. Just reach out.
Stay safe out there. And enjoy your weekend – actually offline, for once.

