Share this article
We are all now probably familiar with the concept that, when it comes to technology in general and cyber security in particular, humans are the weakest link. But this need not be the case. Well prepared and fully trained employees who understand the requirements of data security and know how and when to act (or not) are an invaluable asset to any organisation. With the right support they can actually be the strongest link.
And after an 18-month period like no other, they need to be. Hackers have profited immensely from a perfect storm of cyber challenges created by the Covid crisis. As we all know, the pandemic has accelerated the transition to remote working, leaving lone employees easy prey for targeted Covid-related emails and phishing attacks. In fact, a recent survey found that 75 per cent of organisations around the world experienced some sort of phishing attack in 2020.
In many instances a trained user is more adept at spotting a new phishing attack than any automated technology. People can detect tiny flaws in written English, suspicious links or content with unnecessary demands for urgent attention which an automated tool might not spot.
Provide your remote staff with thorough training and give them clear guidance about what steps to take if they detect suspicious activity. A no-blame culture will provide reassurance and will allow your employees to use their own judgement and take responsibility for identifying and reporting potential threats.
Of course, employees alone cannot be your only line of defence. A robust remote security policy is essential, which includes the use of secured networks, limits access and employs effective automated security tools. These will weed out many threats so that employees are not overwhelmed. Regular social engineering testing and penetration testing will then ensure that the users, systems, policies and tools stay one step ahead.
With all tools and software, priority must be given to the routine implementation of updates and patches. After all, statistics reveal that 60 per cent of breaches involved vulnerabilities for which a patch was available but not applied.
Good practice measures will also improve the resilience of remote worker security. For example, insisting on a clear desk policy at the end of each day and ensuring that email addresses for key employees are not readily available. It is estimated that 75 per cent of email addresses used in spear phishing attacks, targeted at key team members with higher-level access, are easily found through web searches or using common email formats.
Security frameworks like Cyber Essentials and ISO 27001 have evolved to keep pace with the transition to remote working. Whether undertaking certification, or simply following the guidance, these will provide a clear direction for best practice. While knowing how to deploy resources in the most cost-effective manner for accreditations like ISO27001 can present a challenge to organisations, the support of an SRM ISO27001 consultant will help to streamline the process by identifying the most efficient and cost-effective solutions.
No one is an expert in everything. Business managers will know a lot about their products and services, partners, supply chains and customers but few are also experts in cyber security. Even IT teams and CISOs are finding themselves stretched with the change to remote working and the additional complexities this involves. Engaging professional support when shoring up a remote-working cyber security strategy represents a cost-effective solution to the problem. That is because the exercise will be correctly scoped at the outset and, using a combination of high-level qualifications and wide experience, a professional consultancy will ensure you get it right first time and will deliver value because they will save unnecessary expense on products or services you do not need.
The other benefit is risk assessment. One of the most common reason cited for not taking a proactive approach to data security is that robust security may undermine efficiency. A professionally-conducted risk assessment will provide guidance on where the key vulnerabilities lie and will help you rank your risk so that you can establish a balance between efficiency and effectiveness.
There is no automated tool that can safeguard an organisation from itself. The recent case of a Californian water treatment plant which was hacked using the username and password for a former employee’s TeamViewer account highlights the need for robust security policies which take account of small incremental changes. These can be new threats, new work practices or the updating of access controls.
Providing training that is both engaging and effective is critical for any organization looking to ensure that remote workers (and indeed on-site staff) are resourced and supported in their crucial role on the front-line against threat actors.
To find out more about how SRM can work with your organisation to turn your workers into your strongest asset, contact us.