Menu

Call us on 03450 21 21 51

One year on: has the UK mastered the art of remote working?
The SRM Blog

One year on: has the UK mastered the art of remote working?

Claire Greathead

Written by Claire Greathead

31st March 2021

Share this article

remote working 2021

It is a year since the imposition of the first UK lockdown and remote working is still considered to be the new normal for an estimated 60 per cent of the adult population. This equates to nearly 24 million people, a huge increase from just 1.5 million in the early months of 2020. Such a dramatic shift to the lives of workers has not only tested the resilience and flexibility of families; it has also required agility and investment from companies.

But how are we doing? Has the UK mastered the art of remote working?

It depends on who you talk to. From a human perspective, there has been a mixed reaction. Some have relished giving up their daily commute and found they were more productive than ever. Yet, others have felt that isolation, lack of support, separation from the camaraderie of the office environment and the lack of demarcation between home and work has affected their mental health. As a result, some will be rushing back to the office at the first opportunity while others who are being offered the opportunity are unlikely to return to a full week in an office ever again.

Meanwhile many organisations have found their staff to be extremely productive and are considering ways to reduce the investment in office space. When it comes to the extension of working, some may be forgiven for thinking that they can simply continue as they are. But here is the rub.

 

As businesses look to establish a long-term working model, should some of those savings on office overheads be reinvested in cybersecurity?

The answer is, in most cases, yes. Because remote working was pushed through at an accelerated pace back in March 2020, practices, policies and training have taken time to catch up. One of the most significant areas for concern has been how to safeguard data security. After all, most employees have been working away from the supervision of their in-house IT or information security teams for the many months.

Meanwhile, throughout last year, cybercriminals have waged a concerted campaign of social engineering attacks, trying in particular to exploit common home devices that could be used to compromise an individual, allowing for lateral access into a business. Without regular training and efforts to improve risk posture, remote working has the potential to leave glaring holes in an organisation’s defences.

How well have UK businesses done to date?

There’s no doubt that thousands of companies around the UK have done a fantastic job of maintaining business as usual. After the initial shock of having to roll out a what would have been a decade’s worth of digital transformation in just a few weeks or months, they adapted swiftly.

Many have improved processes, increased training, established Virtual Private Networks (VPNs), used encryption and storage tools. They have consolidated their Business Continuity Plans to include specific provision for the remote working model; they have tested regularly and built-in procedures for identifying and reporting suspicious activity. In short, they have invested time and resource in taking proactive steps to re-focus their data security posture to take account of the changes to work practices.

But for every organisation that has been rigorous and diligent in their approach to improving information security, there are many more that have simply been focused on immediate survival. This is entirely understandable and businesses do not deserve to be criticised for this short-sighted outlook in such unprecedented times.

Nevertheless, now that we are all contemplating our roadmap to a life beyond Coronavirus, businesses are strongly advised to make a concerted effort to improve their resilience and enhance their security systems and strategies.

Given the data showing us how cyberattacks have increased dramatically over the course of 2020, no business can claim to be exempt from danger as we progress through 2021. For example, it is estimated that 70% of the UK Finance sector was hit with a cyberattack in 2020. Certainly, all businesses that routinely handled customer, client or third-party data were found to be key targets due to the value of the data they held.

Just some of the dangers facing remote workers include the vulnerabilities of home networks, accessed by DSL or cable. Some systems still in operation rely on consumer modems and switches that are, in many cases, not configured at all or still have default settings.

Similarly, many companies still do not have effective Incident Response Plans in place for a remote workforce and have provided little in the way of training or support to those working tens or even hundreds of miles from their old workplace. These organisations need to take steps now to prioritise the improvement of their cyber security posture, pursuing the goal of Best Practice, or face the very real risk of being irretrievably damaged by a breach.

What is the optimum way to build in Best Practice?

Depending on the size of the business, following a prescribed standard like Cyber Essentials or ISO 27001 provides a clear roadmap to Best Practice, improving data security and going some way to reducing the extent of the threat landscape and minimising the impact of any breach. Professional guidance will ensure the compliance process is not too onerous and is completed in a targeted and cost-effective manner. By scoping accurately at the out-set any investment will not be wasted on unnecessary tools or tests; only on the products and services which will deliver value and enhance security, but without compromising the system’s efficiency.

The crucial thing going forward is to accept that few will be returning to the pure office-based working model. In a recent survey, 26 per cent of Britons say they plan to continue to work from home on either full or partial basis, once lockdown is lifted. Whatever people’s personal preferences, many businesses accept the fact that they need to offer the full or partial remote-working model and those who are lagging behind need to act now to ensure that this can be achieved without compromising security.

Looking to get your business in good shape for a bright future of remote or hybrid working? Get in touch with the team here at SRM today.