Hmm. Do you allow people to VPN in from non-company-controlled laptops? Because I figure that anyone doing work at home is going to be maybe unwittingly having local copies made of data that they’re working with.
No, we do not. Our corporate network connectivity is pretty tightly controlled, and non-issue devices are not permitted on sensitive networks - either VPN or on-premises. I haven’t bothered asking, but I would assume they’re doing system-wide MAC filters as one of the security layers.
I mean yeah it’s possible to exfil data, but it definitely takes some effort, and doing so would be a willful violation of some pretty significant security policies (up to and including “you’re fired, security will escort you out”, depending on the data and the circumstances”), and, you know, it’s nice having a job. Not to mention, I think HIPAA and GDPR privacy stuff, while often tedious in terms of implementation, are absolutely good and worthwhile things for consumers and users, and should not be ignored for expediency or profit.