Share this article
Anyone who has ever tried to crack a joke on a video conferencing call or by email knows that communicating with colleagues via the Internet is very different to being in an office together. Something gets lost in translation. It may be disappointing when your humour is not appreciated, but it’s not potentially catastrophic.
However, when it comes to dealing with a cyber security incident, the reality is that remote-working adds a layer of distance between colleagues and their ability to communicate with one another effectively and this can have serious consequences.
When everyone worked within the controlled environment of an office, making plans in the event of a disruption or breach was relatively straightforward. An Incident Response (IR) plan could be rolled out almost immediately, with a nominated central point of contact on hand to adapt and adjust the plan depending on the particular circumstances.
But with the hybrid working model, the workforce is disparate, relying on remote communication to activate a response. If the breach involves the office network, affecting email and online communication, then serious problems can arise. This is a particular issue when employees lack the relevant training and do not have a secure line of communication which is separate from the IT infrastructure.
What is more, in many cases, employees are using their own home networks which may lack the heightened security levels of the corporate environment. There is also the additional risk presented by other devices which use the home network.
Yet, for many good reasons, there is little prospect of going back as it seems certain that remote working in some shape or form will continue for many organisations. So, Incident Response plans need to be adapted to take account of the shift to a hybrid workforce. And adapt quickly. Because hackers are not shy of exploiting the opportunities created by delays in tackling a breach or any lack of co-ordinated response.
So, how can you ensure your Incident Response plan takes account of today’s hybrid working environment?
Review the minimal acceptable standard for remote workforce IT systems
Putting in place a review process for the minimum acceptable standard for home-based IT system configuration will reduce risk presented by employees working on their own networks. It may also be advisable to consider a Virtual Private Network (VPN) and to add remote worker IT system logs to collect and analyse data to identify any activity which may compromise security.
Provide alternative secure communication
Provide those with response responsibilities with a secure form of communication, separate from the office network. This could be done through the provision of an alternative VPN or work smart phones. In most instances, getting remote workers in touch with each other in a secure manner and getting them back online as quickly as possible will facilitate the recovery process.
Widen the scope
Although one central contact is still advisable to ensure a proportionate and effective response is enacted, it is now important to widen the scope. Educating and empowering anyone with a response role will mean they will know what to do if they spot suspicious activity. In addition, everyone within the organisation should be familiar with the IR plan, who they should contact and how they should proceed. This does not, however, mean that anyone should have access levels which are not required.
Beware elevated privileges
In the past, incidents would have been managed by an office-based Incident Response team. But when staff started to work from home during the pandemic, many organisations found it necessary to grant elevated admin privileges to individuals who would not have previously had them. However, if an account with elevated privileges is compromised it provides hackers with a higher level of access to a corporate network, making it easier for them to cause disruption and compromise business continuity.
Conduct tabletop disaster recovery exercises
Some educational exercises and scenario planning can be conducted in person but, given that the response will probably need to be co-ordinated remotely, conducting tabletop disaster recovery exercises online is also advisable. Once these remote exercises are concluded, identify any gaps or weaknesses exposed in your hybrid workforce and take remedial action.
Seek professional advice
Every organisation is different so there is no one-size-fits-all solution to updating your Incident Response plan. However, professional advice will help you to establish what steps need to be taken, tailored to your particular circumstances, providing you with a strategy that is focused and therefore cost-effective.
At SRM our Retained Forensics and Incident Response team is made up of individuals who are retained by the Payment Card Industry to carry out forensic investigations. Using this expertise, our service enables businesses to build in resilience to their remote or hybrid workforce model, advising on an effective Incident Response plan and facilitating a bespoke strategy to reduce the impact of a breach if one occurs.
Understanding that communication is essential, a single telephone number contact provides immediate access to a member of our specialist team, and is available to nominated representatives within an organisation out of hours in the event of an incident.