Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


10:00 AM
Tim Brown
Tim Brown
Connect Directly
E-Mail vvv

Patrolling the New Cybersecurity Perimeter

Remote work and other developments demand a shift to managing people rather than devices.

The consumerization of IT has eroded the traditional line between "work" and "play." Propelled by the bring-your-own-device (BYOD) era, our personal devices are commonly used for work.

This is especially true as more companies embrace the flexibility of working remotely, and as new devices and networks are used for work purposes. Personal smartphones are loaded with business email accounts, and personal computers and laptops used for remote work have business software, email, and documentation that may contain confidential information.

To top it all off, we aren't just using work devices in the office. We're using them on airplanes, at client offices, in coffee shops, and at home. All this means that the idea that protecting a perimeter is outdated. Instead, as "the workplace" becomes impossible to define as a physical location, technology professionals and IT teams must shift from managing devices to managing people, in order to stay one step ahead of such a rapidly evolving reality.

Protect the Crown Jewels
One easy way to begin implementing this new risk management strategy is to follow the Pareto principle (also known as the 80/20 rule), where companies treat 80% of the people one way while treating the riskier 20% of users with a higher level of security. Access should only be allowed via corporate devices, where multifactor authentication is mandatory, behavioral analytics is applied, and full auditing must be carried out regularly.

For example, the head of HR will be able to access data on all employees within an organization — and accessing this information from an untrusted, insecure device presents a huge risk. In this scenario, an organization's IT team will want to ensure that the device is controlled and that it hasn't been compromised.

Essentially if a person within an organization has the keys to the kingdom, it's crucial to make sure that his or her device isn't dirty, the network isn't compromised, and activity is completely monitored. There then needs to be a division between most of the staff and the VIPs, and between most data and the "crown jewels" (in other words, the most important and most sensitive parts of a business that would be most appealing to an attacker).

Zero Trust: Suspect Everyone
At the same time, by doing away with a perimeter-based security model, where those inside the perimeter are trusted, organizations now need to implement a new model that better matches the vulnerabilities inherent to today's mobile workforce. We must suspect everyone — we can't afford not to.

A Zero Trust policy assumes untrusted actors exist both inside and outside the network and, as a result, every user access request must be authorized. When implemented correctly, Zero Trust networks can improve security while also increasing productivity. What's key to true Zero Trust environments are adaptive controls that are contextually aware. Without context, we always need to put the strongest possible security in place; with context, we can adapt the level of security based on risk.

For example, there should only be a prompt for additional credentials when a user comes from an unknown machine, an unknown location, or when performing a sensitive function. Businesses need to understand their user's behavior, and if things are normal, allow for minimal authentication — if things have changed or the risk is greater, add additional checks.

Still, Zero Trust is a work in progress. Until it's mainstream, password management products that offer complete privileged management systems to password vaults will help to reduce the complexity of users remembering multiple passwords while encouraging stronger password use.

What Comes Next: Cyberhygiene
We know the modern workplace is no longer in one fixed location. At the same time, the nature of cyberattacks are shifting because of how efficiently cybercriminals get paid. From a hacker's perspective, fewer steps equals faster profitability — and all too often, organizations with remote work policies are ripe for attack. 

There are more devices to compromise, which means more machines that will likely be unpatched and not secure. Identities may be implemented in a weak fashion and allowed too much access. Similarly, the rise of collaboration tools such as Slack presents new opportunities to infiltrate networks and take advantage of liabilities. These types of accounts often do not get terminated — so when that user eventually leaves a company, their account remains active and open to infiltration or exploitation by cybercriminals. The more software there is, and the more people experiment with new ways of working, the greater the attack surface will be.

For these reasons, implementing basis cyber hygiene within your organization is critical as the workplace continues to evolve and become increasingly distributed. To meet the basic tenets of good cyber hygiene, organizations should always:

  • Understand the IT environment: Produce a comprehensive understanding of IT environments to uncover hidden data risks and help explain key elements to business leaders.
  • Educate business and IT leaders: Tell them about the risks to their data and implications of a breach — including showing data risk in financial terms.
  • Implement threat monitoring and detection: Deploy the right IT security management tools to detect and respond to potential threats.
  • Use data to show the value of IT efforts: Use data to understand an IT environment, get useful insights, solve problems faster, and demonstrate value.
  • Establish a solid security process: Ensure your organization is completing routine security updates such as managing and patching machines, ensuring a backup is in place, etc.

To stay ahead of this rapidly changing workplace paradigm, technology and security professionals alike should combine good cyberhygiene best practices in concert with additional strategies like Zero Trust and the 80/20 rule. Ultimately, employees need to be the new "endpoints," with the risk they pose to the organization assessed rather than simply determining them as safe depending on whether they are inside or outside a perimeter.

Related Content:

Tim Brown is the VP of Security for SolarWinds, with responsibility spanning internal IT security, product security, and security strategy. As a former Dell Fellow, CTO, chief product officer, chief architect, distinguished engineer, and director of security strategy, Tim ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
6/24/2019 | 3:08:12 PM
SECURITY can be learned by anyone
Case study: last year my wife, daughter and her daughter, 3 year old Cariana, came to visit my workplace.  They were given visitor badges and enjoyed the cafeteria ( Cariana loved pizza ) and met my colleagues.  Then it was time to leave and in the lobby little 3 year old Cariana said THESE HAVE TO BE RETURNED and gathered up their visitor badges and walked them TO THE SECURITY DESK on her own.  Amazing.  They wanted to adopt her on the spot.  Lesson: 3 year old got the concept of perimeter security BETTER than half the employees get it. 
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-05-06
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the...
PUBLISHED: 2021-05-06
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gai...
PUBLISHED: 2021-05-06
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
PUBLISHED: 2021-05-06
** UNSUPPORTED WHEN ASSIGNED ** The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode wh...
PUBLISHED: 2021-05-06
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.