Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - From Stop-Gap To Sustainable: Securing IT’s New Normal
Articles

From Stop-Gap To Sustainable: Securing IT’s New Normal

ISBuzz TeamBy ISBuzz TeamMarch 30, 20204 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
badlock vulnerability
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The global pandemic is challenging the world to creatively and intelligently adapt to rapid change. People and organizations must define their new normal while adjusting to sweeping modifications such as social distancing and extensive remote work. For IT leaders, there is immense pressure to perform fantastic feats quickly. With as little as 24-hours-notice in some cases, organizations are asking IT to stand up comprehensive work-from-home programs, opening corporate networks to a wide range of new connections and sending corporate hardware out into the wild with little-to-no preparation.

These fast and drastic changes are pushing the collective IT community way beyond its comfort zone. Almost overnight, many of the controls and protocols that previously managed corporate security postures are being strained or exceeded. Attack surfaces are expanding exponentially in the blink of an eye.

Fortunately, we live in technological age where, believe it or not, this is manageable. There is a wealth of information and tools available to help IT find a more comfortable foothold while working to scale security and manage their rapidly expanding networks.

The best approach involves three main principles: Stay Informed and Vigilant, Plan to Scale and Sustain, and Properly Prioritize. Adhering to these guidelines can help organizations and IT teams of any size successfully navigate uncharted waters.

Stay Informed and Vigilant

The number of remote workers everywhere is growing. As organizations expand their remote workforce, they are opening themselves up to possible infections or breaches. Whether yours is an organization that has always practiced WFH policies or is enacting them for the first time, it’s important to know the common missteps that can create vulnerabilities. Some of these pitfalls are caused technologically, while others are the result of end user mistakes.

Technological missteps:

  • Using unencrypted connections
  • Poorly secured RDP
  • Misconfigured VPN
  • Bandwidth constraints
  • Outdated, unpatched user software

End user missteps:

  • Poor password protocol
  • Using public WiFi
  • Unencrypted data sharing
  • Using poorly configured routers
  • Falling victim to social cyberattacks such as phishing attacks

Regarding cyberattacks, it is common for malicious actors to ramp up their game during times of crisis. Sadly, we have already seen an alarming number of fraudulent websites and other resources using the COVID-19 topic to entice visitors.

Tip: It is considered a best practice to run regular, on-demand vulnerability and threat scans, especially when your network is rapidly changing and involves extensive BYOD.

Plan to Scale and Sustain

Because many organizations are facing quick ramp-up times, they’ve had to create manual process and supports that do not scale easily and will eventually become unsustainable. As the deployment dust begins to settle, it is important for IT organizations to examine recent measures and evaluate expansion or scale-down capabilities as well as automation opportunities. This is particularly crucial for maintenance and security processes as they are vital to the overall security posture of the organization.

Cloud security solutions are indispensable when it comes to adjusting scale. Their flexibility and agility make it possible for organizations to grow or shrink specific security functions as needed. This is particularly necessary during times of uncertainty.

SaaS solutions are ideal when it comes to automation. SaaS solutions use automation by nature and are tailor-made to automate business-critical functions. Automation is a best practice for many key security and maintenance functions, as it removes the fallibility introduced by manual processes. Additionally, SaaS solutions also facilitate workflow integrations as well as secure data sharing. These are essential capabilities when employing a remote workforce.

Tip: Identify security solutions that are cloud-native. Because they are built for the cloud and not retrofitted, they run faster, operate intuitively, and provide essential on-demand data access.

Properly Prioritize

There will be no shortage of tasks heaped up on IT departments in the coming months. Even before the recent changes, IT teams struggled to juggle competing priorities. This is especially true for small to medium business, though no organization is immune.

Among the most pressing needs are operational and security tasks. Often these tasks are weighted equally in importance, but not everything can be priority number one. It’s best to use comprehensive security tools to evaluate to-do lists from a number of angles and help provide well-rounded, informed prioritization. This ensures teams focus their efforts on the most pressing vulnerabilities and threats first, helping to secure systems efficiently, without unnecessary resource drain.

Tip: Look for a vulnerability management solution that offers comprehensive scanning, actionable results, and well-rounded rating criteria, to provide essential context for remediation prioritization.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Cloud Security Controls Explained: A Definitive Guide

March 19, 20269 Mins Read

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}