{"id":2889,"date":"2020-05-03T21:52:01","date_gmt":"2020-05-03T17:52:01","guid":{"rendered":"https:\/\/techxmedia.com\/?p=2889"},"modified":"2025-04-18T00:01:32","modified_gmt":"2025-04-17T20:01:32","slug":"protect-against-cyberattacks-working-from-home","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/protect-against-cyberattacks-working-from-home\/","title":{"rendered":"How to protect against cyberattacks when working from home"},"content":{"rendered":"\n<p>As we navigate the challenges posed by\nCOVID-19 and the need to halt the spread of this deadly pandemic, many of us\nare settling into a routine of working from home. This can pose many\ndifficulties, including how to maintain focus, how to balance other priorities,\nsuch as childcare, and how to be productive without requisite tools or\ndedicated office space \u2013 not to mention the struggle to avoid raiding the whole\nsnack cupboard in one day.<\/p>\n\n\n\n<p>There are compromises to be found for many of\nthese challenges in what we hope will be a relatively short-term arrangement.\nWhat we must not compromise on is security.<\/p>\n\n\n\n<p>Many <a href=\"https:\/\/www.weforum.org\/agenda\/2020\/03\/coronavirus-pandemic-cybersecurity\/\">cybercriminals<\/a> are seeking to exploit our thirst for\ninformation as a vector for attack. Most commonly, as with other high-profile\nevents, attackers are using COVID-19-themed phishing e-mails, which purport to\ndeliver official information on the virus, to lure individuals to click\nmalicious links that download Remote Administration Tools (RATs) on their\ndevices.<\/p>\n\n\n\n<p>In addition, there have been multiple reported cases of malicious COVID-19-related Android applications that give attackers access to smartphone data or encrypt devices for ransom. The global pandemic has also led to the creation of more than 100,000 new <a href=\"https:\/\/techxmedia.com\/tag\/covid_19\/\">COVID-19<\/a> web domains, which should be treated with suspicion, even though not all of them are malicious. (Palo Alto Networks is continually updating the latest <a href=\"https:\/\/unit42.paloaltonetworks.com\/covid19-cyber-threats\/\">COVID-19 related cyber threats<\/a>.)<\/p>\n\n\n\n<p>Attackers are also taking advantage of the\nfact that many people who are working from home have not applied the same\nsecurity on their networks that would be in place in a corporate environment,\nor that enterprises haven\u2019t deployed the right technologies or corporate\nsecurity policies to ensure that all corporate-owned or corporate-managed\ndevices have the exact same security protections, regardless of whether they\u2019re\nconnected to an enterprise network or an open home WiFi network.<\/p>\n\n\n\n<p>Both business leaders and individual employees\nhave critical roles and responsibilities in securing their organization and in\nensuring that cyberattacks do not further compound the already disrupted work\nenvironment.<\/p>\n\n\n\n<p><strong>How Businesses Can Respond<\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"289\" height=\"465\" src=\"https:\/\/techxmedia.com\/wp-content\/uploads\/2020\/05\/image.png\" alt=\"\" class=\"wp-image-2890\" srcset=\"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/05\/image.png 289w, https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/05\/image-186x300.png 186w\" sizes=\"auto, (max-width: 289px) 100vw, 289px\" \/><\/figure><\/div>\n\n\n\n<p>In this critical time, business leaders have a\nheightened responsibility to set clear expectations about how their\norganizations are managing security risk in the new work environments,\nleveraging new policies and technologies and empowering their employees. It\u2019s\nimportant that messages on security come from the very top of an organization,\nand that good examples are set from the start. Here are three recommendations\nfor business leaders.<\/p>\n\n\n\n<p>Understand the threats to your organization.\nBusiness leaders should work with their security teams to identify likely\nattack vectors as a result of more employees working from home and prioritize\nthe protection of their most sensitive information and business-critical\napplications.<\/p>\n\n\n\n<p>Provide clear guidance and encourage communication.\nThey must ensure that home-working policies are clear and include\neasy-to-follow steps that empower employees to make their home-working\nenvironment secure. This should include instructing employees to communicate\nwith internal security teams about any suspicious activities.<\/p>\n\n\n\n<p>Provide the right security capabilities.\nLeaders should ensure all corporately owned or managed devices are equipped\nwith essential security capabilities, extending the same network security best\npractices that exist within the enterprise to all remote environments. These\ncritical capabilities include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>An ability to securely connect users to their business-critical cloud and on-premise applications, such as video teleconferencing applications increasingly relevant for remote work environments<\/li><li>Endpoint protection on all laptops and mobile devices, including VPN tools with encryption<\/li><li>An ability to enforce multi-factor authentication (MFA)<\/li><li>An ability to block exploits, malware and command-and-control (C2) traffic using real-time, automated threat intelligence<\/li><li>An ability to filter malicious domain URLs and perform DNS sinkholing to thwart common phishing attacks<\/li><\/ul>\n\n\n\n<p><strong>How Individuals Can Respond<\/strong><\/p>\n\n\n\n<p>Individual users must be empowered to follow\nthe guidance provided to them by organizations and take preventative measures.<\/p>\n\n\n\n<p>Maintain good password hygiene. Employees\nshould use complex passwords and multifactor authentication where possible and\nchange these passwords frequently.<\/p>\n\n\n\n<p>Update systems and software. Individuals\nshould install updates and patches in a timely manner, including on mobile\ndevices and any other non-corporate devices they might use for work.<\/p>\n\n\n\n<p>Secure your WiFi access point. People should\nchange their default settings and passwords in order to reduce the potential\nimpact on their work of an attack via other connected devices.<\/p>\n\n\n\n<p>Use a virtual private network (VPN). VPNs can\nhelp create a trusted connection between employees and their organizations and\nensure ongoing access to corporate tools. Corporate VPNs provide additional\nprotection against phishing and malware attacks, the same way corporate\nfirewalls do in the office.<\/p>\n\n\n\n<p>Be wary of COVID-19 scams. We\u2019ve seen phishing\ne-mails, malicious domains and <a href=\"https:\/\/www.usatoday.com\/story\/tech\/2020\/03\/18\/spyware-apps-mobile-phones-could-spread-amid-coronavirus-pandemic\/2865792001\/\">fake apps<\/a> out in the wild already. Threat actors <a href=\"https:\/\/unit42.paloaltonetworks.com\/covid19-cyber-threats\/\">love to exploit real-world tragedies<\/a>,\nand COVID-19 is no different.<\/p>\n\n\n\n<p>Don\u2019t mix personal and work. Employees should\nuse their work devices to do work and their personal devices for personal\nmatters. If you wouldn\u2019t install or use a service while you\u2019re at the office,\ndon\u2019t do it while at home on your work device.<\/p>\n\n\n\n<p>Taking these relatively straightforward steps\nat both an enterprise and individual level should help address some of the most\ncommon security risks facing our home-working environments. We should also\nrecognize that our threat environment is not static, which means it\u2019s important\nto keep a close eye on evolving threats to avoid unnecessary additional costs\nand disruptions in a time when we can least afford them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this critical time, business leaders have a heightened responsibility to set clear expectations about how their organizations are managing security risk in the new work environments, leveraging new policies and technologies and empowering their employees.<\/p>\n","protected":false},"author":8,"featured_media":8050,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1595,9621],"tags":[1315,724,1139,686,518,523,838,1320],"contributor":[],"class_list":["post-2889","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-emerging-technologies","tag-businesses","tag-covid_19","tag-covid-19","tag-cyber_attack","tag-cyber_security","tag-palo_alto_networks","tag-remote_working","tag-working_from_home"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/05\/Ryan-Olson-home-techxmedia.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/2889","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=2889"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/2889\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/8050"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=2889"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=2889"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=2889"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=2889"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}