COVID-19 security tips: Ensure you sack your staff without leaving their IT access enabled, says Secureworks
- Reference: 1602783004
- News link: https://www.theregister.co.uk/2020/10/15/secureworks_report/
- Source link:
Or so says Secureworks, which throughout 2020 has, perhaps counterintuitively, insisted there has been minimal uptick in cyber activity from malicious people, stating in its research [1]The Effect of COVID-19 on Incident Response that "data on confirmed security incidents and genuine threats to customers showed the threat level largely unchanged from before the pandemic."
Rather, reckons the company, the near-overnight shift to remote working triggered by the pandemic has created a whole set of poorly understood IT infrastructures lashed together in a hurry and therefore containing large numbers of hidden vulnerabilities – vulns that infosec bods ought to be hunting down, in Secureworks' view.
Barry Hensley, Secureworks' chief threat intelligence officer, said in a canned statement: "Against a continuing threat of enterprise-wide disruption from ransomware, business email compromise and nation-state intrusions, security teams have faced growing challenges including increasingly dispersed workforces, issues arising from the rapid implementation of remote working with insufficient consideration to security implications, and the inevitable reduced focus on security from businesses adjusting to a changing world."
Secureworks especially highlighted the use of personal devices on corporate networks, hasty adoption of cloud-based enterprise productivity suites such as Microsoft [2]Office 365 359 and the inevitable rise of COVID-19 themed phishing lures.
"Adversaries exploit natural and man-made disasters to target people’s emotions," stated the report. "Fear, sympathy, and anger are often heightened in these situations, and the COVID-19 pandemic is no exception.
"Educate employees at every level about the heightened risk of COVID-19-themed phishing attacks, show them how to identify potential phishing, and tell them where to go with any security concerns" – with the latter meaning set up an internal reporting function for suspicious emails and messages, rather than the traditional non-IT management response to suggestions of spending money on good things.
Secureworks' recommendations for securing a remote IT estate will sound wearily familiar: enable MFA; secure remote access methods; and enforce secure access controls to cloud services.
More offbeat are its other suggestions, which include strengthening "remote termination processes" to ensure emotional ex-staffers can't go on the rampage after you sack them over Zoom, and making thorough plans for remote incident response – including how to quickly kill shared folder synchronisation and identifying key process or personnel bottlenecks that will need bypassing in case of ransomware, or worse.
"The pandemic has changed the way the world works, but cybersecurity threats are largely the same," noted the firm. ®
Get our [3]Tech Resources
[1] https://www.secureworks.com/resources/rp-effect-covid19-incident-response
[2] https://www.theregister.com/2020/10/08/microsoft_support_consolidation/
[3] https://whitepapers.theregister.com/
Re: Seems reasonable
Well tell manglement not to be cheap and cough up for some Aruba APs.
Re: Seems reasonable
"but are we paranoid enough?"
If you're not your manglement will discover that the hard way. They won't blame themselves. Oh, no.
Tip for those sacked
Hope for better times for everyone including your ex-employer and remain on good terms to be at the front of the queue when they get back on their feet.
Macros
In my previous employment at BT, the IT security team created a little button on MS Outlook that would send a selected e-mail to the anti-malware team, and delete it from your inbox. All you had to do was identify a suspect e-mail, select it and click the button. It worked very well, though I don't know the code they used, sounds like a good idea others should copy. Of course the users did have to recognise suspicious e-mails first (we had a training course for that too), but it was a start to taking IT Security seriously for the whole company, rather than just words like 'Security is everyone's responsibility', and suchlike.
Re: Macros
You can do this with M365, anything you submit as junk/phishing can go to an additional mailbox.
Simples, don't use 5G for work connections and this will no longer be a problem.
Seems reasonable
We have users connecting our devices to their (poorly or not secured) home WiFi. It is enough to give you gray (or no) hair. We are often accused of being paranoid about security here, but are we paranoid enough?