Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Preparing For Tomorrow – Why Weathering The Initial Covid-19 Storm Isn’t Enough For Security
Articles

Preparing For Tomorrow – Why Weathering The Initial Covid-19 Storm Isn’t Enough For Security

Steve BeechingBy Steve BeechingMarch 1, 2021Updated:February 13, 20235 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Covid-19 pandemic already presented a robust security challenge. As organisations rushed to adapt to remote working during lockdown, they also had to act quickly to shut down new security vulnerabilities that opened up. At the same time, the climate of fear and uncertainty meant there was fertile ground for phishing attacks. For the most part, best practice has prevailed – organisations have weathered the first wave of challenges and appear to have entered a period of relative calm. However, at best we are only in the eye of the storm. There are still going to be massive changes to working habits worldwide; economic crises; and the risk of further waves of Covid-19 and ongoing global upheaval. Organisations need to take advantage of this period to ensure they are prepared to weather the whole storm.

Security vs. access

The guiding principle of security has always been relatively simple: the more sensitive data is, the harder it should be to access. In the most extreme cases, this means ensuring data can only be accessed physically, in a single location. With employees increasingly remote and dispersed, this has become much harder – meaning organisations need to prioritise their strategy for ensuring employees can still access the data they need without increasing risk.

First, organisations need to be certain they are providing employees secure access to the data they need. Most organisations will have rushed to give employees laptops and other technology to ensure they can work remotely in the early stages of lockdown. They should now revisit these devices and confirm they are protected adequately – for instance, are laptops encrypted at either the hardware or software level? If employees are using their own devices or, as is highly likely, their own internet connection, do they have access to a VPN or other secure network to ensure data isn’t put at risk?

Data sharing

With employees’ devices and networks secured, the second question is how they will actually access data. In some cases, data will be so sensitive that the only option is to require employees visit the workplace – meaning the organisation has to take measures to ensure they are protected. Yet even when employees can access data remotely, the organisation has to choose its approach – whether this means encrypting the data so it can be shared over an unencrypted internet connection; keeping the data on encrypted servers that can only be accessed via a secure VPN; or even couriering encrypted hard drives with extremely sensitive data to employees.

Data storage

With remote devices such as  laptops and  mobile phones now embedded in networks, it is essential that organisations decide if their data is hosted in the cloud, on remote servers, or whether it is stored on these local remote devices. Often businesses decide to opt for a hybrid of options, so the security roadmap of a business should consider device storage with password protection, dual access keys to secure data at rest drives and storage mediums. Secure drives are especially important for protecting sensitive data when considering the risk  of devices being lost, damaged, accessed by third  parties or even stolen.

A frame of mind

More broadly, securing an increasingly remote workforce in uncertain times demands a change in mind-set. It may seem a cliché, but organisations should see this as the equivalent of a military operation. If each employee is seen as the equivalent of a unit in the field, then the correct approach to take becomes clear. Employees need to be given all they need in order to do their jobs effectively, but also avoid putting others at risk.

As well as technology they can trust, communications are essential to protecting employees and their employers. Whenever there is a new security risk, the whole organisation needs to know exactly what it entails and what action is required so that everybody can act in concert. This means sharing a clear message and plan, while also ensuring every employee has the connectivity they need to receive and act on them.

Organisations and employees also must trust that their colleagues not only know how to keep each other safe; but also that they will take the right actions when under pressure. This makes training paramount – especially when employees working remotely will both have greater freedom to act, and will be more isolated from support networks that can advise them and prevent them from making mistakes. Training should combine both knowledge so employees better understand the threats they face, and best practice so that they are drilled in the right ways to act in order to minimise risk.

No “new normal”?

Finally, adaptability is crucial. Organisations need to be constantly learning – both keeping up with new and evolving threats and understanding their employees’ habits to identify training requirements. At the same time, we don’t yet know what the world will look like in a year’s time: there may be further upheavals and new risks as industries and governments continue to adapt to changing circumstances. Those organisations that can make themselves more adaptable now will be much better placed to keep themselves secure in the future.

Steve Beeching

Managing Director

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    New Phishing Kit Starkiller Defeats Multi-Factor Authentication

    February 23, 20264 Mins Read

    ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

    January 22, 20266 Mins Read

    What Happens after a Phishing Email Lands in Your Inbox?

    January 5, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}