Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Adapting Security Strategies For A Remote Workforce
Articles

Adapting Security Strategies For A Remote Workforce

ISBuzz TeamBy ISBuzz TeamSeptember 21, 2020Updated:February 28, 20234 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The COVID-19 pandemic has forced organizations to pivot quickly from a fully on-prem or hybrid on-prem/remote office setting to a nearly 100 percent remote work environment. One of the most pressing challenges of this transition has been the instantaneous shift in how organizations must approach cybersecurity. To best protect data in a remote workforce, it is critical to first identify risks associated with this transformation, and then institute best practices that will strengthen security and reduce data exposure.

Understanding the threats

When employees move from a single, secure business network to home networks, they generally have less-robust security protections. While connecting to a VPN can help reduce security risks, critical data not saved to a protected work network can potentially be exploited.

IoT creates additional complexity. According to Deloitte, the average household has 11 connected devices — ranging from TVs and thermostats to security cameras and appliances. Each device represents yet another pathway into an employee’s home network and puts criminals one step closer to accessing sensitive data.

It is also important to consider that employees working remotely are more likely to use their work computers for activities such as shopping, paying bills and general web browsing, which increases the risk of exposing company data. When combined with the increased frequency of pandemic-related phishing attempts — such as fake offers for protective equipment or spoofed company emails that look like policy updates — an organization’s data becomes even more vulnerable.

Beyond the vulnerabilities of home networks, the rapid move many organizations have made to the cloud presents additional risks. McAfee found that cloud attacks jumped 630 percent between January and April — the first months of the pandemic — and many organizations were unprepared to fend off such attacks. The problem persists with many companies relying solely on basic security protections offered by cloud providers, often because their existing tools were not immediately compatible with cloud technology. Others have implemented new technology without the proper training.

Addressing the risks

Given the compounding internal and external risks that come with a remote workforce, taking the necessary actions to secure data should be a top priority. The following suggestions can greatly strengthen an organization’s security posture.

  • Map out a plan for network defense. Because remote work has changed the threat landscape, tabletop exercises to outline roles, responsibilities, and mitigation tactics are more important than ever. These discussions help security teams coordinate proactive decision-making, and better prepare them for emerging internal and external threats. These tabletop exercises are focused on addressing changing threat surfaces and using remote access tools that offer visibility into application use and wireless access points, and allow security teams to restrict network access should an incident occur.
  • Prioritize cloud penetration testing. Many organizations have deployed cloud solutions without the necessary security hardening. A penetration test of cloud environments and web applications can help identify vulnerabilities that need to be addressed. Threat emulations are also valuable, as they assess the state of an organization’s defensive security posture against a likely threat actor using adversary tactics, techniques, and tools.
  • Institute simulation training. Organizations should institute threat simulation training that resembles the kinds of issues employees might experience while working remotely — such as phishing attempts, ransomware and breaches of cloud-based systems. Such exercises can reinforce daily habits that help employees identify potential threats and prepare them to take the necessary actions to report them.
  • Audit remote technology security gaps. Enabling a remote workforce will require a heavier reliance on SaaS technologies and VPNs, so it is important to assess how secure these tools are, and rectify any security gaps. It is also critical to enforce password complexity and mandatory use of multi-factor authentication where possible, to prevent threat actors from gaining access to work applications containing sensitive data.
  • Reprioritize tactics and strategies. Organizations must take into account emerging threats related to remote work, and reprioritize their approaches to security accordingly. For example, delaying network firewall projects and other on-prem upgrades, and redirecting investments toward solutions that will protect data in a remote work environment. Such investments include remote access, and remote management tools that alert security teams of potential issues and position them to more easily address problems, no matter where a user is located. Organizations should also have the latest remote patching capabilities to ensure that company computers are updated with the latest security protections.

Conclusion

It is still unclear what the future holds, but a company setting that relies more heavily on remote work may likely become the status quo. By recognizing the ways in which a remote workforce changes the threat landscape, and implementing the necessary steps to address those threats, organizations will be better positioned, offensively and defensively, to secure data and maintain the business continuity necessary to remain competitive.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}