Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


05:50 PM

Cyberattacks Up, But Companies (Mostly) Succeed in Securing Remote Workforce

Despite fears that the burgeoning population of remote workers would lead to breaches, companies have held their own, a survey of threat analysts finds.

Since the onset of the pandemic, more than half of firms say they have detected at least a "moderate increase" in cyberattacks, while one in10 firms have encountered a drastic increase, according to a survey of more than 520 security professionals.  

Yet the increase in attacks has not led to an increase in breaches, with 16% of firms experiencing a breach in the past 12 months compared with 15% for the same period in 2019, according to a report by threat-hunting tools provider DomainTools. More than half of the surveyed companies (56%) stated they are prepared to support a fully remote workforce, with about a third tightening security policies and settings.

Related Content:

As Remote Work Becomes the Norm, Security Fight Moves to Cloud, Endpoints

2020 State of Cybersecurity Operations and Incident Response

New on The Edge: Open Source Threat Intelligence Searches for Sustainable Communities

Overall, fears that the chaos of the coronavirus pandemic and the massive shift to remote work would lead to more frequent security incidents and breaches have failed to be realized, says Tim Helming, security evangelist at DomainTools.

"In general, organizations held their own pretty well," he says. "Obviously, COVID represented a dual problem for security shops — the shift to remote work encompasses all kinds of complexities — but on top of that, you had a bunch of attackers seizing on the moment and preying on the hunger for information on COVID."

Concerns over the spread of the novel coronavirus have resulted in most companies shifting employees to work from home. In June, more than three-quarters of companies had the majority of their employees working outside of the office, according to consultancy PwC. Looking toward the future, almost 90% of companies expect at least 30% or more of employees not to work from the office at least part of the time. 

The DomainTools survey gave companies a chance to rate their security programs. The share of respondents that gave their program an "A" declined to 24% in 2020, from 30% in 2019, while the number of "B" grades rose to 49% in 2020, from 45% in 2019.

"COVID-19 served as an inflection point for over a quarter of security teams to reassess their perceived cybersecurity posture," DomainTools stated in its report. "Twelve percent of respondents would have given their organization a lower grade prior to the pandemic, showing surprise in how well they were able to cope." 

Companies that had good training programs successfully transitioned to a secure workforce. About 60% of companies surveyed have a program for training IT staff in cybersecurity subjects, and of those respondents who gave their company's security efforts an A, 86% had a training program.

Almost half of security professionals (46%) — and three-quarters (74%) of professionals who rated their company's security an A — believe the training helped the organization respond to the security challenges posed by the pandemic. 

"Training and preparation paid off," Helming says. "We had this big Black Swan event that happened, and it put organizations to the test, and the ones that felt like they had successfully risen to the occasion are the ones who did training and preparation ahead of time." 

Looking to the future, about 62% of companies said they will not change their security budgets. Of the nearly one-quarter of companies that will increase their budgets, nearly half will focus on hiring more cybersecurity professionals and slightly less than half will focus on team training, the survey found. Adding new threat intelligence sources claimed a distant third position, with 36% of security professionals indicating that more budget would be spent on that capability.

Overall, companies saw more attacks but mainly common vectors, such as spear phishing, malware, and business e-mail compromise. More than a third of companies saw active or suspected cyberattacks every day, the survey found. 

"The number of attacks moderately increased, so if you hold that up against the increases in the number of breaches that were attempted, companies, in general, are doing a good job," Helming says. "To me, that was one of the bright spots."

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Threaded  |  Newest First  |  Oldest First
User Rank: Apprentice
10/9/2020 | 10:59:34 AM
remote work
attacks from cyber criminals are becoming more frequent due to the remote working mode that this pandemic has forced organizations to implement, this is another negative consequence of covid-19 in addition to the infected and the decline in the economy, the truth is a pity. you can read more about this in the following <a href=»https://demyo.com/the-importance-of-safety-in-remote-work/" >article</a>
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-05-06
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the...
PUBLISHED: 2021-05-06
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gai...
PUBLISHED: 2021-05-06
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
PUBLISHED: 2021-05-06
** UNSUPPORTED WHEN ASSIGNED ** The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in &quot;interactive&quot; mode wh...
PUBLISHED: 2021-05-06
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.