{"id":86385,"date":"2023-02-27T15:52:32","date_gmt":"2023-02-27T15:52:32","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=86385"},"modified":"2023-05-25T11:22:32","modified_gmt":"2023-05-25T10:22:32","slug":"distributed-workforces-mean-distributed-cybersecurity-risks","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2023\/02\/27\/distributed-workforces-mean-distributed-cybersecurity-risks\/","title":{"rendered":"Distributed workforces mean distributed cybersecurity risks"},"content":{"rendered":"\n<p><em>David Steele, MD of SecuriCentrix and a Principal Security Consultant, says there\u2019s nothing personal in adopting security solutions for scattered staff.<\/em><\/p>\n\n\n\n<p>Overnight, companies were forced to open their workforce to a distributed model, as Covid shook the world.<\/p>\n\n\n\n<p>From localised access to systems and networks, employees were suddenly accessing everything remotely through the cloud on a range of devices &#8211; sometimes personal ones.<\/p>\n\n\n\n<p>In the process, organisations opened themselves up to greater risks, as cybercriminals opportunistically took advantage of the situation.<\/p>\n\n\n\n<p>Many companies geared themselves up quickly, but it\u2019s an on-going battle as threats become more and more sophisticated, using employees to get the necessary access information. Or use them to access data directly through the sneaky installation of malware, for example.<\/p>\n\n\n\n<p>According to a KcKinsey survey from March 2022, companies are accelerating their adoption of cloud technologies.<\/p>\n\n\n\n<p>The range of benefits is immense \u2013 from creating a more flexible infrastructure to getting digital products to market faster. But the risk to data is greater, without a doubt. The report says that 36% of companies accelerated their move to the cloud during the pandemic and 86% of them expect to continue the trend post-pandemic.<\/p>\n\n\n\n<p><strong>Staff training is essential to mitigate cybersecurity risk<\/strong><\/p>\n\n\n\n<p>Unfortunately, staff will always be the biggest target of cyber-criminals.<\/p>\n\n\n\n<p>Humans are much easier to manipulate than computers because we\u2019re emotionally driven. And even if we are sharp when it comes to IT security, there\u2019s still the possibility that we\u2019ll inadvertently click something in our hurried and distracted busyness.<\/p>\n\n\n\n<p>Security training is therefore critical to keeping the business safe.<\/p>\n\n\n\n<p>This should be on-going, as the threats change and evolve with constant new variants on the prowl.<\/p>\n\n\n\n<p>From good password practices and being able to spot a fake email, to handling the event of a data breach, staff should be taught to be constantly on the look-out. It\u2019s also a good idea to run simulations or provide real-life examples rather than purely theoretical approaches. This is something that really needs regular attention.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2023\/02\/9-2.png\" alt=\"\" class=\"wp-image-86386\" width=\"390\" height=\"390\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2023\/02\/9-2.png 500w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2023\/02\/9-2-300x300.png 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2023\/02\/9-2-150x150.png 150w\" sizes=\"auto, (max-width: 390px) 100vw, 390px\" \/><figcaption class=\"wp-element-caption\">David Steele, MD, SecuriCentrix<\/figcaption><\/figure><\/div>\n\n\n<p><strong>Have a VPN<\/strong><\/p>\n\n\n\n<p>A Virtual Private Network acts as a buffer between end-user and the network, by extending a secure private network across a public one via tunnelling protocols.<\/p>\n\n\n\n<p>Access to infrastructure through a VPN is seamless and it allows for secure remote access, increases functionality and security and makes management of the network easier.<\/p>\n\n\n\n<p>Users will be able to access the organisation\u2019s network resources from home or over a public Wi-Fi point. In both of those examples, the company\u2019s IT security team has no control over the level of security and accessibility, or network setup, but a VPN can bypass all of that.<\/p>\n\n\n\n<p>This reduces the risk of an attack and allows staff to safely work in a distributed geography.<\/p>\n\n\n\n<p><strong>Control users\u2019 access<\/strong><\/p>\n\n\n\n<p>Not all users need access to all systems.<\/p>\n\n\n\n<p>Role-based access control (or RBAC) means that if a hacker does get into the network through a user\u2019s credentials, they\u2019ll be limited to the amount of damage they can do.<\/p>\n\n\n\n<p>Every single member of staff \u2013 from CEO to admin \u2013 should have RBAC, even the network teams.<\/p>\n\n\n\n<p>You don\u2019t want one person to end up as the company\u2019s point of failure. Temporary access with expiring credentials can be granted to users should they need access to systems outside of their usual sphere.<\/p>\n\n\n\n<p><strong>Monitor that network constantly<\/strong><\/p>\n\n\n\n<p>With a workforce in one location, it\u2019s relatively easy to monitor the network.<\/p>\n\n\n\n<p>But with employees based all over the show, it becomes a little more complex, with monitoring having to spread across all of those points.<\/p>\n\n\n\n<p>An enhanced security program is therefore a must.<\/p>\n\n\n\n<p>Monitoring allows for a proactive response rather than a reactive one, which, with a distributed workforce is more complicated. Communicating with staff when they\u2019re all on-site is much easier than when they\u2019re dotted about on a range of devices.<\/p>\n\n\n\n<p>So ideally, you want someone watching that network every hour of every day to ensure immediate and proactive action can be taken in the case of a data breach.<\/p>\n\n\n\n<p>Many organisations use a managed security solutions provider to monitor their network.<\/p>\n\n\n\n<p><strong>Physical security<\/strong><\/p>\n\n\n\n<p>While staff members are in the office, maintaining physical security is relatively easy.<\/p>\n\n\n\n<p>However, an organisation cannot control the security measures in place at their employees\u2019 homes, for example.<\/p>\n\n\n\n<p>It\u2019s important to educate staff on the importance of keeping their device safe.<\/p>\n\n\n\n<p>Leaving laptops unattended in a coffee shop, or even having a work screen open in a public place, creates opportunities for data thieves. Privacy screens, locks and general conscientious behaviour to lock screens, should be incorporated into staff security training.<\/p>\n\n\n\n<p><strong>In case of policies<\/strong><\/p>\n\n\n\n<p>A Disaster Recovery (DR) strategy, including a protocol in case of a data breach, is critical.<\/p>\n\n\n\n<p>It helps for all stakeholders to know their role in an emergency to ensure the least damage is incurred. Backups should form part of this strategy, to get everything back up and running as soon as possible and to minimise damage.<\/p>\n\n\n\n<p>A DR strategy would have a large IT component, but it may also cover natural disaster events, if you\u2019re in an area prone to them.<\/p>\n\n\n\n<p><strong>Keep work for work and private for private<\/strong><\/p>\n\n\n\n<p>While not always possible, ideally, employees should have separate devices for work.<\/p>\n\n\n\n<p>Allowing the use of personal devices for work can place an organisation at risk \u2013 you don\u2019t want users accessing company resources through their own devices.<\/p>\n\n\n\n<p>However, it\u2019s not always possible to provide devices, in which case, it\u2019s key to have a good mobile device management plan in place and to focus on user training.<\/p>\n\n\n\n<p>This would involve the ability to remotely wipe a device clean of all data in case it\u2019s stolen or lost.<\/p>\n\n\n\n<p>Remote work opportunities come with many advantages, for both the employer and employee. But it comes with added cybersecurity risks too. Be aware of these and proactively respond accordingly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>David Steele, MD of SecuriCentrix and a Principal Security Consultant, says there\u2019s nothing personal in adopting security solutions for scattered staff. Overnight, companies were forced to open their workforce to a distributed model, as Covid shook the world. From localised access to systems and networks, employees were suddenly accessing everything remotely through the cloud on [&hellip;]<\/p>\n","protected":false},"author":58,"featured_media":86387,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[51,17482,1489,93,24],"tags":[564,17268,18318],"class_list":["post-86385","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-study-newsletter","category-cybersecurity","category-insights","category-top-stories","category-used","tag-cybersecurity","tag-insights","tag-securicentrix"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/86385","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=86385"}],"version-history":[{"count":9,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/86385\/revisions"}],"predecessor-version":[{"id":86962,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/86385\/revisions\/86962"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/86387"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=86385"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=86385"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=86385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}