Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Security From Home: Protecting A Self-isolated Workforce
Articles

Security From Home: Protecting A Self-isolated Workforce

Fiona BoydBy Fiona BoydJune 23, 2020Updated:March 9, 20234 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The global coronavirus pandemic has proven to be the biggest test of how modern and flexible working practices are enabling employees to stay productive, working anytime, anywhere, on any device. Today’s enterprise mobility technologies enable employees to remotely connect to the data and resources they need, whenever they need them and on whatever devices they choose.

This is even more important in view of the current global events. And with governments around the world mandating social distancing on their citizens, including reducing social and professional gatherings, remote working has become an organisational business continuity measure rather than a debatable perk.

But despite these virtues, remote access to organisational data and systems, via various mobile devices across multiple networks, has a dark side that keeps chief information security officers (CISOs) awake at night. Accessing data outside the secure network perimeter opens up unprecedented “attack surfaces” for cyber criminals and creates a huge amount of additional vulnerability for organisations. 

With this in mind, what are the risks that CISOs and IT decision makers need to look out for when they deploy remote working practices, and how can they be mitigated?

Capacity issues

Capacity might sound like a simple consideration, but it is a tangible one too. Mobile workers use virtual private networks (VPNs) to access corporate servers, but VPNs put considerable strain on organisational resources, necessitating having enough licenses for secure remote access. 

Additionally, IT decision-makers need to consider how their secure access solutions would prioritise who gets priority bandwidth. One cause of low connectivity is when users try to upload or download large files that are non-business critical, as these files exhaust the bandwidth dedicated to the operation of critical corporate IT systems. 

During business continuity and disaster recovery planning, organisations should carefully consider capacity factors, including licensing and bandwidth availability so that they are prepared for any unexpected surge in demand. To securely allocate web traffic to cloud applications, IT decision-makers should consider using Cloud Access Security Broker (CASB) solutions to manage the demands, while maintaining security monitoring and security policies to ensure that users and applications are properly protected. Enterprises may also wish to leverage the security functions they already have available to them through the existing services that they already consume, such as Microsoft Azure, as some of these may help to quickly alleviate challenges.

Unsecured devices

Today’s frequency of mobile security software updates requires devices to be regularly patched to maintain enterprise-wide security. This is especially relevant in bring your own device (BYOD) scenarios, where native mobile device security software might not live up to organisational standards. Patches and updates address known security problems, which means that ignoring them opens new attack vectors for cyber criminals. 

IT decision-makers need to make sure proper patching processes are put in place to ensure devices are kept secure. This requires visibility of what is connecting to the network and a view into the state of health of those devices, including how recently they were last updated. Aligned to this, the process needs to have visibility of new updates coming from the hardware and software vendors to ensure these are applied as soon as they become available.

This is particularly important given that cyber attackers are trying to take advantage of the fragmented workforce. According to recent research, 42% of workers have received suspicious emails since they started working from home. Cyber criminals are opportunists and will take advantage of any chance they get to breach an organisation’s defence. Therefore, more than ever, security teams need to be on top of their game. 

The new normal

As a large proportion of the global workforce adapts to our new normal, cyber security needs to be front of mind. There are huge infrastructural challenges that organisations have had to tackle almost overnight. As the workforce settles into new work from home habits, cyber security teams are also dealing with new challenges.

There’s no doubt that enabling remote access to corporate resources while safeguarding the integrity of organisational systems is a tough balancing act for most IT decision-makers. But with the tools available today, enterprise IT and security teams are in as good a position as any to protect the business without negatively impacting the work of the isolated workforce. 

Fiona Boyd

Head of Enterprise Cyber Security

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    The Real Cost of Inconsistent Third-Party Access

    December 18, 20255 Mins Read

    What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

    August 7, 20256 Mins Read

    The Evolving Importance of Identity Governance in FinTech

    July 10, 20258 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}