Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Tackling The Security Challenges Of A New Remote Working Reality
Articles

Tackling The Security Challenges Of A New Remote Working Reality

ISBuzz TeamBy ISBuzz TeamSeptember 30, 2020Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
US Offers $10 Million For Russian Ransomware Operator's Capture
US Offers $10 Million For Russian Ransomware Operator's Capture
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

COVID-19 has already forced major changes to the way we live our lives. Many of these may outlast the pandemic, especially those related to the modern workforce. New working patterns may in the long-run have significant benefits to organisations and their employees, but there are also challenges; reduced IT visibility and control creates serious security gaps. As we get used to the new reality of mass remote working, IT leaders need to formulate a long-term plan to enhance cyber-resilience, by minimising these gaps and optimising controls.

Security side-lined

A return to business-as-usual once the pandemic recedes is unlikely. Indeed, a quarter (26 percent) of Fortune 500 CEOs believe the majority of their staff will end up working from home indefinitely. This might even be a conservative estimate if potential productivity and cost benefits materialise. If the prediction is true, the coming months could see another wave of digital transformation akin to the initial flurry of activity back in March. The early days of the pandemic included roll-outs of cloud-based communications software like Zoom and Teams, and productivity platforms including Office 365 to enable employees to log-in, collaborate and work from anywhere in the world. 

Some organisations also had to increase investments in cloud infrastructure to support new business models and operations. Microsoft estimated it saw two years’ worth of digital transformation in just two months, and a recent Fortune 500 poll found 75 percent of companies have seen work-from-home initiatives accelerate digital plans. Unfortunately, amidst these efforts, security has often fallen to bottom of the priority list. According to one study of global IT leaders, while 90 percent reported an increase in cyber-attacks, 93 percent also side-lined key security projects like regular patching.  

Stretched to the limit

Cyber-threats are on the rise as attackers spot new gaps to exploit in distributed workforces. Personal devices at home may not be as well secured as corporate equivalents and may be shared with users that engage in risky behaviour. Even if the IT function can locate and manage such endpoints, VPNs are increasingly overwhelmed with the load, delaying patches. Home workers may also be their own worst enemy. Trend Micro found more than half (56 percent) have used a non-work application on a corporate device, and 66 percent of them have uploaded corporate data to that app. Many more (80 percent) use their work laptops for personal browsing. On the other side, 39 percent said they often or always access corporate data from a personal device. 

At the same time, IT security teams are stretched to the limit. A recent poll of its members by industry body ISACA found less than two thirds (59 percent) feel their cybersecurity team has the right tools at home to perform their job effectively. Just 51 percent are confident teams can detect and respond to rising threat volumes. In short, organisations are more exposed than ever to the risk of ransomware, data breaches, bot attacks, and more. Trend Micro alone blocked nearly 28 billion cyber-threats in the first half of 2020 including almost nine million COVID-themed attacks — most of which were destined for remote workers’ inboxes. Cyber-criminals are even cold-calling victims with new vishing and voicemail phishing tactics.

Time for action

The global average cost of a data breach is now almost $3.9m. Remediation and clean-up, lost productivity, legal fees, regulatory fines and reputational damage can all seriously undermine growth and customer confidence at a time of tremendous business uncertainty. So, how can organisations regain the initiative?

The most essential task is to update remote working policies. The first six months of the year were characterised by a struggle to adapt to the new reality. Now it’s time to prioritise security and eliminate IT blind spots, using technology controls to support upgraded policies. The IT security function must have full visibility into all remote working endpoints, and the ability to manage patching, ensure approved AV is installed and up-to-date, and that corporate log-ins are manged securely, or even better, enhanced with multi-factor authentication.

Security must also work at the network layer, email/web gateway, and all on-premises and hybrid cloud servers. Businesses must look for providers that can offer a range of controls to stop the many threats in the modern hacker’s toolkit. IPS and file integrity monitoring are useful tools to spot suspicious behaviour early on, while virtual patching adds a layer of defence for vulnerable systems until an official security update is available.

The final piece of the puzzle is, of course, the people in the organisation. Security leaders will need to revisit and update user training and awareness programmes and communication channels to take account of the new reality of home working. Courses should be flexible enough to adapt as threats evolve. There’s no such thing as a silver bullet in security. But with budgets under scrutiny and staff in short supply, IT leaders may find that the best option is to seek a trusted partner to help them navigate their way through the current landscape. This can not only help with technical implementation of security but also on the people side of things, to assist in adapting and adopting new behaviours required to protect themselves from the security threats. If this is the new normal, it’s time to start managing cyber-risk more effectively going forward.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}