Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

4/5/2021
10:00 AM
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

7 Ways to Reduce Cyber Threats From Remote Workers

The pandemic's decline won't stop the work-from-home trend nor the implications for cybersecurity, so it's crucial to minimize the threats.

With the arrival of COVID-19 vaccines, we are (hopefully) nearing the end of the pandemic's crisis. However, its effects will long outlast its year-long reign.  The increase in the number of employees who choose to work from home (WFH) at least part of the time is among the likely permanent changes brought by COVID-19.

Many employees like the idea of WFH and, often, employers do as well. A Gartner survey shows that approximately three-quarters of employers intend to permanently implement remote work, even after the green light is given on returning to the office post-COVID. 

Related Content:

Prioritizing Application & API Security After the COVID Cloud Rush

Special Report: Building an Effective Cybersecurity Incident Response Team

New From The Edge: Cartoon Caption Winner: In Hot Water

This hybrid work model comes with advantages and disadvantages — and among the disadvantages is a sharp rise in the number of cyber threats and vulnerabilities. When employees connect to organizational servers, databases, and intranets via the Internet, they are really working at a remote endpoint of the corporate office. But unlike in office-based environments, they are not as diligently protected.

Therefore, CISOs need to view home-based devices as integral parts of IT and mandate that the devices, as well as the people using them, undergo the same level of security as they would when operating from the office. Like any other maturity improvement program, organizations must grapple with the challenges posed by their people (employees, third-party vendors, and so on), processes, and technology and implement the necessary security measures to protect them.

7 Ways to Secure WFH Employees:

  • Offer periodic awareness training: To avoid breaches, employers need to implement employee training courses with a focus on the latest threat scenarios. Management, operations, and R&D are all prime targets of social engineering, phishing, and scamming campaigns (among other threats). Employees need to be aware of the threats they face to take the necessary measures to protect themselves, their devices, and sensitive company information. 

  • Share lessons learned: Companies should implement periodic reviews of employees' and executives' experiences in dealing with phishing and other social engineering tactics. Listening to colleagues' experiences and "lessons learned" helps all personnel better identify and protect themselves from threats. As a result of these lessons, management should establish clear policies and procedures — with clear owners and defined responsibilities — to ensure home office security.

  • Harden endpoint devices: Before allowing employees to connect to the office remotely, organizations need to guide them on enforcing all related company policies and procedures with the updated threat landscape, including laptops and routers connecting from home offices and mobile devices.

  • Enforce home-based VPN connections: Given that home networks are generally easier to breach than office networks, organizations need to enforce employees' use of VPN connections when working remotely. VPNs encrypt and protect data, ensuring that the connection remains private and secure. 

  • Implement multifactor authentication (MFA): Single-factor authentication is associated with the vast majority of compromised user accounts. In fact, implementing MFA could prevent up to 99.9% of such attacks. While results may vary for different companies, there's no question that MFA — requiring two or even three levels of authentication for more sensitive assets — would greatly reduce an organization's vulnerability.

  • Separate the security organization: In many companies, cybersecurity is an IT department's responsibility and competes for attention with other IT issues. Companies should establish a security operations center (SOC) that is dedicated specifically to cyber defense and can monitor events, update security controls, and defend against attacks more effectively. The SOC can also monitor threats, scan the Dark Web for data breaches, and better protect company and employee information.

  • Establish an intelligent perimeter defense: Organizations need to take a thorough inventory of their assets, vulnerabilities, and methods of defense. IT is spread across servers, cloud installations, and now home endpoints. Organizations need to inventory these connections to locate the weak points and defend against potential threats by implementing security measures that mandate that only certain organizational assets can be accessed outside the office.

The last year has changed our lives for the foreseeable future — from our personal lives to our professional lives and how we work and conduct business. By taking necessary security precautions, organizations can ensure that employees' IT activities are as secure at home as they are when working from the office.

Reuven is a cybersecurity entrepreneur and a national cybersecurity expert. As a founding team member of the Israeli army's Red Team (Section 21) and Incident Response Team, Reuven is extremely passionate and knowledgeable in all things cybersecurity. His expertise is in ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21981
PUBLISHED: 2021-04-19
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploitation of this issue may allow attackers with local guest user account to assign privileges higher than their own permission level.
CVE-2021-20989
PUBLISHED: 2021-04-19
Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device initiated remote port-forward channel can be us...
CVE-2021-20990
PUBLISHED: 2021-04-19
In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdown, a reboot or a reboot into recovery mode.
CVE-2021-20991
PUBLISHED: 2021-04-19
In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.
CVE-2021-20992
PUBLISHED: 2021-04-19
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.