{"id":46222,"date":"2020-03-16T09:54:16","date_gmt":"2020-03-16T09:54:16","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=46222"},"modified":"2020-03-16T12:20:03","modified_gmt":"2020-03-16T12:20:03","slug":"remote-working-due-to-coronavirus-heres-how-to-do-it-securely","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/16\/remote-working-due-to-coronavirus-heres-how-to-do-it-securely\/","title":{"rendered":"Remote working due to coronavirus? Here\u2019s how to do it securely"},"content":{"rendered":"\n<p><strong><em>With concerns over the current coronavirus (Covid-19) outbreak, and the need to keep at-risk staff away from the office has brought working from home to the top of everyone\u2019s mind. As many organisations are enabling and exploring this opportunity, it is important for users and companies to stay secure while protecting everyone\u2019s physical health. Paul Ducklin, Principal Research Scientist, Sophos, has listed a few tips to keep your users safe while they are working from home.<\/em><\/strong><\/p>\n\n\n\n<p>Many if not most organisations\nhave already crossed the \u2018working from home\u2019, or at least the \u2018working while on\nthe road\u2019 bridge.<\/p>\n\n\n\n<p>If you\u2019re on the IT team, you\u2019re\nprobably used to preparing laptops for staff to use remotely, and setting up\nmobile phones with access to company data.<\/p>\n\n\n\n<p>But global concerns over the\ncurrent coronavirus (Covid-19) outbreak, and the need to keep at-risk staff\naway from the office, means that lots of companies may soon and suddenly end up\nwith lots more staff working from home and it\u2019s vital not to let the precautions\nintended to protect the physical health of your staff turn into a threat to\ntheir cybersecurity health at the same time.<\/p>\n\n\n\n<p>Importantly, if you have a\ncolleague who needs to work from home specifically to stay away from the office\nthen you can no longer use the tried-and-tested approach of getting them to\ncome in once to collect their new laptop and phone, and to receive the on-site\ntraining that you hope will make them a safer teleworker.<\/p>\n\n\n\n<p>You may end up needing to set\nremote users up from scratch, entirely remotely and that might be something\nyou\u2019ve not done a lot of in the past.<\/p>\n\n\n\n<p>So here are our five tips for working from home safely:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Make sure it\u2019s easy for your users to get started<\/h4>\n\n\n\n<p>Look for security products that\noffer what\u2019s called an SSP, short for Self-Service Portal.<\/p>\n\n\n\n<p>What you are looking for is a\nservice to which a remote user can connect, perhaps with a brand new laptop\nthey ordered themselves, and set it up safely and easily without needing to\nhand it over to the IT department first.<\/p>\n\n\n\n<p>Many SSPs also allow the user to\nchoose between different levels of access, so they can safely connect up either\na personal device (albeit with less access to fewer company systems than they\u2019d\nget with a dedicated device) or a device that will be used only for company\nwork.<\/p>\n\n\n\n<p>The three key things you want to\nbe able to set up easily and correctly are: encryption, protection and\npatching.<\/p>\n\n\n\n<p>Encryption means making sure that\nfull-device encryption is turned on and activated, which protects any data on\nthe device if it gets stolen; protection means that you start off with known\nsecurity software, such as anti-virus, configured in the way you want; and\npatching means making sure that the user gets as many security updates as\npossible automatically, so they don\u2019t get forgotten.<\/p>\n\n\n\n<p>Remember that if you do suffer a\ndata breach, such as a lost laptop, you may well need to disclose the fact to\nthe data protection regulator in your country.<\/p>\n\n\n\n<p>If you want to be able to claim\nthat you took the right precautions, and thus that the breach can be\ndisregarded, you\u2019ll need to produce evidence \u2013 the regulator won\u2019t just take\nyour word for it!<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Make sure your users can do what they need<\/h4>\n\n\n\n<p>If users genuinely can\u2019t do their\njob without access to server X or to system Y, then there\u2019s no point in sending\nthem off to work from home without access to X and Y.<\/p>\n\n\n\n<p>Make sure you have got your chosen\nremote access solution working reliably first \u2013 force it on yourself! \u2013 before\nexpecting your users to adopt it.<\/p>\n\n\n\n<p>If there are any differences\nbetween what they might be used to and what they are going to get, explain the\ndifference clearly \u2013 for example, if the emails they receive on their phone\nwill be stripped of attachments, don\u2019t leave them to find that out on their\nown.<\/p>\n\n\n\n<p>They\u2019ll not only be annoyed, but\nwill probably also try to make up their own tricks for bypassing the problem,\nsuch as asking colleagues to upload the files to private accounts instead.<\/p>\n\n\n\n<p>If you\u2019re the user, try to be\nunderstanding if there are things you used to be able do in the office that you\nhave to manage without at home.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Make sure you can see what your users are doing<\/h4>\n\n\n\n<p>Don\u2019t just leave your users to\ntheir own devices (literally or figuratively).<\/p>\n\n\n\n<p>If you\u2019ve set up automatic\nupdating for them, make sure you also have a way to check that it\u2019s working,\nand be prepared to spend time online helping them fix things if they go wrong.<\/p>\n\n\n\n<p>If their security software\nproduces warnings that you know they will have seen, make sure you review those\nwarnings too, and let your users know what they mean and what you expect them\nto do about any issues that may arise.<\/p>\n\n\n\n<p>Don\u2019t patronise your users,\nbecause no one likes that; but don\u2019t leave them to fend for themselves, either\n\u2013 show them a bit of cybersecurity love and you are very likely to find that\nthey repay it.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Make sure they have somewhere to report security issues<\/h4>\n\n\n\n<p>If you haven\u2019t already, set up an\neasily remembered email address, such as security911 @ yourcompany DOT example,\nwhere users can report security issues quickly and easily.<\/p>\n\n\n\n<p>Remember that a lot of\ncyberattacks succeed because the crooks try over and over again until one user\nmakes an innocent mistake \u2013 so if the first person to see a new threat has\nsomewhere to report it where they know they won\u2019t be judged or criticised (or,\nworse still, ignored), they\u2019ll end up helping everyone else.<\/p>\n\n\n\n<p>Teach your users \u2013 in fact, this\ngoes for office-based staff as well as teleworkers \u2013 only to reach out to you\nfor cybersecurity assistance by using the email address or phone number you\ngave them. (Consider snail-mailing them a card or a sticker with the details\nprinted on it.)<\/p>\n\n\n\n<p>If they never make contact using\nlinks or phone numbers supplied by email, they they are very much less likely\nto get scammed or phished.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Make sure you know about \u2018shadow IT\u2019 solutions<\/h4>\n\n\n\n<p>Shadow IT is where non-IT staff\nfind their own ways of solving technical problems, for convenience or speed.<\/p>\n\n\n\n<p>If you have a bunch of colleagues\nwho are used to working together in the office, but who end up flung apart and\nunable to meet up, it\u2019s quite likely that they might come up with their own\nways of collaborating online \u2013 using tools they\u2019ve never tried before.<\/p>\n\n\n\n<p>Sometimes, you might even be happy\nfor them to do this, if it\u2019s a cheap and happy way of boosting team dynamics.<\/p>\n\n\n\n<p>For example, they might open an\naccount with an online whiteboarding service \u2013 perhaps even one you trust\nperfectly well \u2013 on their own credit card and plan to claim it back later.<\/p>\n\n\n\n<p>The first risk everyone thinks\nabout in cases like this is: \u201cWhat if they make a security blunder or leak data\nthey shouldn\u2019t?\u201d<\/p>\n\n\n\n<p>But there\u2019s another problem that\nlots of companies forget about, namely: what if, instead of being a security\ndisaster, it\u2019s a conspicuous success?<\/p>\n\n\n\n<p>A temporary solution put in place\nto deal with a public health issue might turn into a vibrant and important part\nof the company\u2019s online presence.<\/p>\n\n\n\n<p>So, make sure you know whose\ncredit card it\u2019s charged to, and make sure you can get access to the account if\nthe person who originally created it forgets the password, or cancels their\ncard.<\/p>\n\n\n\n<p>So-called\u2019 \u2018shadow IT\u2019 isn\u2019t just\na risk if it goes wrong \u2013 it can turn into a complicated liability if it goes\nright!<\/p>\n\n\n\n<p>Most of all, if you and your users\nsuddenly need to get into teleworking, be prepared to meet each other half way.<\/p>\n\n\n\n<p>For example, if you\u2019re the user,\nand your IT team suddenly insists that you start using a password manager and\n2FA (those second-factor login codes you have to type in every time)\u2026<\/p>\n\n\n\n<p>\u2026then just say \u201cSure,\u201d even if you\nhate 2FA and have avoided it in your personal life because you find it\ninconvenient.<\/p>\n\n\n\n<p>And if you\u2019re the sysadmin, don\u2019t\nignore your users, even if they ask questions you think they should know the\nanswer to by now, or if they ask for something you\u2019ve already said \u201cNo\u201d to\u2026<\/p>\n\n\n\n<p>\u2026because it might very well be that\nthey\u2019re asking because you didn\u2019t explain clearly the first time, or because\nthe feature they need really is important to doing their job properly.<\/p>\n\n\n\n<p>We\u2019re living in tricky times, so try not to let matters of public health cause the sort of friction that gets in the way of doing cybersecurity properly!<\/p>\n\n\n\n<p>The original article can be found <a href=\"https:\/\/nakedsecurity.sophos.com\/2020\/03\/06\/5-tips-for-working-safely-from-home\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"here (opens in a new tab)\">here<\/a>.   <\/p>\n\n\n\n<p><br> <\/p>\n\n\n\n<p><br> <\/p>\n\n\n\n<p><br> <br><\/p>\n\n\n\n<p><br> <\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With concerns over the current coronavirus (Covid-19) outbreak, and the need to keep at-risk staff away from the office has brought working from home to the top of everyone\u2019s mind. As many organisations are enabling and exploring this opportunity, it is important for users and companies to stay secure while protecting everyone\u2019s physical health. Paul [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":46223,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5307,5,36,809,9961,13],"tags":[11246,11474,1530,11477,2456,11475,186,11476],"class_list":["post-46222","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-enterprise-security","category-intelligent-technology","category-more-news","category-thought-leadership","category-top-stories","tag-coronavirus","tag-covid","tag-cybersecurity","tag-paul-ducklin","tag-remote-working","tag-self-service-portal","tag-sophos","tag-ssp"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=46222"}],"version-history":[{"count":12,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46222\/revisions"}],"predecessor-version":[{"id":46239,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46222\/revisions\/46239"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/46223"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=46222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=46222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=46222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}