enterprisesecuritymageurope

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Dr. Martens

Hybrid Working & Maturing Security under a Pandemic.

Theo Botha, Global Head of Information and Cyber Security, Dr. Martens

It has been 2 years since security professionals in the UK/EU had to start thinking of security and operational challenges while countries locked down. The COVID-19 pandemic had an unprecedented impact on our daily lives and organisation pre- COVID which meant business operations had to be supported by new technology rolled out rapidly to ensure business survival.

Suddenly the traditional ways of working (for most) had to rapidly move into Hybrid working whilst technology architecture still only supported traditional office working environments.With the change in business activities switching to Hybrid working, the cyber security risks increased across the business during the pandemic. The risk increased because the pandemic disrupted existing workflows. 

Increase in reported Security incidents under COVID-19

Attackers have always taken advantage of major global disruptions like COVID-19 to deliver their attacks. Increase in phishing mail targeting end users now working in isolation. The standard end user support network is not around them to confirm and review a strange mail just received. Email security providers reported an increase in the first 100 days of the global pandemic where COVID-themed phishing mail was used to try and hook end users into reading COVID-19 information or updates, including downloading fake applications.

Adjusting the standard security approach when an organisation has low security maturity.

The Pandemic provided limited time to implement a Cyber   Security Strategy using traditional methods. Bringing   security to the end user should be the focus treating the   home network as the threat. Reviewing and Securing the   business end user device can be done with a quick security   review using a framework focusing on the end user   security controls.

"Reviewing and Securing the business end user device can be done with a quick security review using a framework focusing on the end user security controls ."  

Here are at ahigh-level suggested areas to focus on:

User Training & Awareness:  Focus on updating    (or creating new) Remote Working Policy providing    guidelines to the end user on phishing mail, appropriate    downloading of business documents and use of remote    working technology never used before like Virtual Private    Network (VPN) tools.   

Identity Management:  Implement improved methods for users to identify themselves on the corporate network. The Rollout of M365 to take advantage of MS Teams provides an opportunity to use the Conditional Access authentication methods at application level.

Device encryption:  If not in place already, adjusting the organisational device build to include device encryption.

End User Device Management:  With end users now working remotely and unable to visit office spaces to drop or pick up business devices, the device management process had to adjust quickly. Updating gateways to ensure devices still get the appropriate antivirus, security updates and general patch management.

Security Monitoring: Monitoring had to move to an end user device focus. The implementation and rollout of End Point Detection and Response (EDR) provides the visibility and monitoring needed for the rapidly dispersed end user. Visibility can also be increased by installing EDR on Servers treating them as a standard user end point.

End User Communication & Alerts:  Improve standard incident response processes to focus on end user reach. Ensuring users are properly informed and prompted whilst working from their remote location.

Final recommendation to support increasing and managing security maturity under a pandemic.

• Choosing a Security Framework:  Select the right security framework for your organisation and board to measure your security for example NIST CSF, ISO27001:2013 etc.

• Understand your organisational risk:  Ensure you know the organisational risk appetite and scoring to set the right level of security maturity. This might have changed under a pandemic.

 • Executive reporting:  Ensure your security framework supports the right detail for your Board. Your Board needs to understand the risk especially under a pandemic where business is moving quick and focusing on survival.

• Remote work force preparation: Adjusting your security strategy focusing on bringing security to the end user.

• Internal Security Resource: The recruitment challenge will not go away, so selection of the right Managed Service Security Partner (MSSP) is critical to support a lean team.  

• The new isolated User: Develop policy and an Awareness Program that aligns to the new isolated user’s working environment.

• Security Technology Investment: Be aware of technology advances that will support the new way of working for example End Point monitoring via EDR to provide you with the monitoring visibility needed.

• Security budget Constraints: Where there is a lack of budget enhance your security fundamentals for example patch and vulnerability management by adjusting standard controls like SCCM Gateway.

 

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.