Article summary: Multi-factor authentication protects the moment someone logs in, but it does nothing for an unlocked laptop sitting open on a coworking desk or a hybrid office hot desk. Anyone who sits down at that screen inherits every session already logged in, no password or MFA prompt required. A properly configured inactivity timeout closes that gap automatically, without relying on employees to remember to lock up every time they step away.

‍

An employee steps away from their laptop to grab coffee or take a quick call. Ten minutes later, they are back at their desk and nothing appears to have happened.

But during those ten minutes, an unlocked computer can give anyone nearby access to email, files, business applications, and other resources without ever entering a password or getting past MFA.

That is the risk behind physical session hijacking. It does not require sophisticated hacking techniques, just an unattended, unlocked screen and enough time to use it.

In hybrid offices, shared workspaces, and other flexible work environments, automatic inactivity timeouts provide a simple way to close that window before a quick trip away from the desk becomes a security gap.

Why MFA Does Not Protect an Unlocked Screen

MFA is great at stopping someone who is trying to log in without the right credentials. But once an employee has successfully signed in, MFA has already done its job.

That matters when someone walks away from an unlocked computer. Email may already be open, business applications may be signed in, and the browser may have active sessions that do not require another password or authentication code every time the user clicks something.

Someone who sits down at that computer does not need to defeat MFA. They can simply use whatever the legitimate employee already has access to.

That is why NIST recommends automatically locking devices after a period of inactivity. MFA protects the login. A screen lock helps protect the authenticated session after the employee walks away.

‍

The Hybrid Office Multiplies the Opportunity

An unattended laptop in a private office is one thing. Hybrid work puts the same device in coworking spaces, client offices, shared desks, and other places where the people nearby may change from one day to the next.

Hot-desking changes who is nearby

In a traditional office, most people walking past an employee's desk are familiar coworkers. In a coworking space or hot-desking environment, the person at the next workstation could be a stranger, a visitor, or an employee from another company.

That makes relying on familiar faces a poor substitute for automatically locking the screen when someone steps away.

The same rule should apply at home

A home office may feel safer, which makes it easy to get out of the habit of locking a computer. But family members, housemates, visitors, or service providers can still end up near a device containing company information.

Hybrid work makes physical access harder to predict because the same device moves between environments with very different levels of control. A consistent screen-lock policy removes the need for employees to decide when a workspace feels secure enough to leave a device unattended.

Setting the Right Timeout

An automatic inactivity timeout takes the responsibility out of employees’ hands by locking the screen when they step away. The challenge is finding a timeout that closes the security gap without constantly interrupting the workday.

1.    Start with an established baseline. The CIS Critical Security Controls recommend that general-purpose operating systems should lock automatically after no more than 15 minutes of inactivity, and mobile devices after no more than 2 minutes.

2.   Apply the timeout at the operating system level. An OS-level lock protects access to everything on the device at once instead of depending on individual applications to enforce their own timeouts.

3.     Consider shorter timeouts in higher-risk environments. A laptop regularly used in coworking spaces or client sites may warrant a shorter window than one kept in a controlled office.

4.    Require authentication to unlock the device. NIST's device lock control calls for keeping the device locked until the user reestablishes access through established authentication procedures.

5.    Remember that locking is not logging out. A screen lock is useful for temporary absences, but NIST notes that it is not a substitute for logging out when a session should actually end.

Make the manual lock a trained reflex too

An automatic timeout is a backstop, not a replacement for good habits. Employees should still lock their screens whenever they step away rather than leaving the device exposed until the timeout kicks in.

It only takes a second: Windows key + L locks a Windows PC, while Control + Command + Q locks a Mac. Making that shortcut a reflex closes the gap between leaving the desk and the automatic lock taking over.

Ready to Lock Down Your Hybrid Team's Endpoints?

When employees move between home, the office, and shared workspaces, an unlocked screen can create an easy opportunity for unauthorized access without a phishing email or stolen password.

Vudu Consulting can help you review endpoint security policies, configure appropriate inactivity timeouts, and make sure those protections follow employees wherever they work.

Contact Vudu Consulting, or email us at contact@vuduconsulting.com to build stronger endpoint security into your hybrid work environment.

Article FAQs

What is physical session hijacking?

Physical session hijacking happens when someone uses an unlocked, already-authenticated device to access files, email, applications, or other resources without having to steal a password or get past MFA.

Why doesn't the MFA stop this kind of attack?

MFA verifies the user during authentication. If that user walks away while the device remains unlocked, someone else can potentially use the active session without going through the login process again.

What is a reasonable inactivity timeout for a small business?

The CIS Critical Security Controls recommend automatic locking after no more than 15 minutes of inactivity for general-purpose operating systems and no more than two minutes for mobile devices. Businesses may choose shorter timeouts for devices regularly used in shared or less-controlled environments.

‍

Start making IT magic

Schedule a Call