{"id":1964,"date":"2020-03-26T12:23:21","date_gmt":"2020-03-26T08:23:21","guid":{"rendered":"https:\/\/www.techxmedia.com\/?p=1964"},"modified":"2025-04-18T02:26:46","modified_gmt":"2025-04-17T22:26:46","slug":"cybersecurity-covid-19-driven-organizational-change","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/cybersecurity-covid-19-driven-organizational-change\/","title":{"rendered":"Cybersecurity despite COVID-19-driven organizational change"},"content":{"rendered":"\n<p>By Barry Hensley<\/p>\n\n\n\n<p>It is a sad reality, but both hostile state\nactors and opportunistic cybercriminals are already leveraging COVID-19 themed\ncampaigns to conduct phishing and deliver malware. Secureworks Counter Threat\nUnit researchers have observed that, as is common with all topical news\nstories, criminal actors making cynical use of the current crisis to promote\nmisinformation and products with the intent to harm organizations and\nindividuals.<\/p>\n\n\n\n<p>By following key good cybersecurity hygiene\npractices, organizations can protect themselves and their employees against\nthese attacks.<\/p>\n\n\n\n<p>At Secureworks, we exist to secure the human\nprogress that technology enables. In this new COVID-19 corporate landscape, our\ncustomers are dealing with the competing challenges of protecting employees and\nbusiness systems, while also rapidly making business and technology changes,\nincluding adopting new temporary remote working practices.<\/p>\n\n\n\n<p>If you are one of the many companies rapidly\nadopting these new working practices, including encouraging remote work from\nhome, I want to give you our best advice for maintaining business continuity\nwhile not increasing your organization&#8217;s cybersecurity risk:<\/p>\n\n\n\n<p>Remote access services are now business\ncritical. Services that facilitate communication, collaboration and delivery of\ncore business services for a remote workforce will now become vital systems,\nwhere previously they were a flexible convenience. Organizations may need to\nopen up additional access and reconfigure services in order to enable full\nremote functionality. There will be pressure to do this rapidly and bypass\nnormal change control processes. I want to challenge you to balance the need\nfor speed of delivery with diligence in ensuring that proper controls and\nsecurity practices are maintained to keep data and systems safe. You don&#8217;t want\nto be left vulnerable in what is now a mission-critical situation.<\/p>\n\n\n\n<p>Multi-Factor Authentication (MFA) is a\nmust-have. Credentials abuse is at the root of most intrusions involving remote\naccess services. Where possible, make sure your organization is making use of\nproper Multi-Factor Authentication (MFA), Virtual Private Networking (VPN)\ntechnology, and secure cloud web services like web mail, collaboration portals\nand enterprise business applications. Exceptions to this will be your Achilles\nHeel, as the adversary only has to find one hole in your defenses, and multiple\nthreat groups actively target these services on a near-continuous basis.<\/p>\n\n\n\n<p>Organizations currently in the midst of\nresponding to a cyber intrusion may encounter the additional challenge of being\nunable to respond with the implementation of new controls such as MFA because\nthe potential for disrupting remote workers is deemed too high. There may also\nbe a reluctance to patch Internet-facing systems and remote access services\nthat the business is now even more reliant on, even when those are the very\nsystems that may be most at risk from attack. The answer is to enhance your\nvisibility to spot threats early.<\/p>\n\n\n\n<p>Increase your monitoring and visibility across\nthis new environment including endpoint, network, and cloud services and task\ncyber defenders with actively hunting for threats and re-entry attempts. In\ncombination, this can provide a temporary mitigating control while the\nenterprise works through the challenge of responding to the incident.<\/p>\n\n\n\n<p><strong>Contingency Planning in the New Virtual World<\/strong><\/p>\n\n\n\n<p>You are undoubtedly talking about contingency\nplanning as part of your business continuity plans right now. I want to\nencourage you to also include cybersecurity contingencies in that discussion.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Do you have a cybersecurity\ncrisis communication, management and response plan?<\/li><li>Do changes to working\npractices stemming from the COVID-19 pandemic alter that plan?<\/li><li>Can you correlate multiple\nstages of an attack that could lead to a catastrophic event (e.g. ransomware)\nand neutralize the problem early, before it becomes a disaster.<\/li><li>Are you prepared to rapidly\nrespond and recover based on various degrees of business impact?<\/li><\/ul>\n\n\n\n<p>We know our Secureworks customers depend on us.\nOur teams around the world are committed to being your cybersecurity partner in\nthis digitally connected world\u2014the larger WE simply cannot allow threat actors\nto exploit this crisis. Our communities are already fragile, so we cannot\ntolerate anything that results in additional financial burden, business\ndisruption or patient care risk.<\/p>\n\n\n\n<p>Good cybersecurity practices will carry you through. We will be alongside you every step of the way, protecting the progress of our customers so you can stay focused on being there for your employees and customers.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Secureworks Counter Threat Unit researchers have observed that, as is common with all topical news stories, criminal actors making cynical use of the current crisis to promote misinformation and products with the intent to harm organizations and individuals.<\/p>\n","protected":false},"author":8,"featured_media":1966,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1595,9621,54,9624],"tags":[723,724,518,771,963,990,801,882],"contributor":[],"class_list":["post-1964","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-emerging-technologies","category-health-tech","category-smart-sectors","tag-coronavirus","tag-covid_19","tag-cyber_security","tag-malware","tag-mfa","tag-phishing","tag-ransomware","tag-vpn"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/03\/Barry-Hensley_Secureworks-e1585210968966.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=1964"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1964\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/1966"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=1964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=1964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=1964"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=1964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}