Remote working creates higher risk of online attacks for firms: specialists
Singapore
REMOTE working can expand the attack surface that threat actors can target, making businesses more susceptible to cyber attacks, say industry specialists.
Organisations' exposure to hacking attempts has increased through their employees who are working from home, given that home networks are usually less secure than corporate networks, said the Cyber Security Agency (CSA) of Singapore in its recent report.
Working from home may also result in occasional lapses in one's security consciousness, CSA added.
"Employees may show greater willingness to take on calculated security risks and trade-offs in order to get work done, when they are under pressure to meet work targets amidst the challenges of working from home."
Additionally, when faced with hard-to-use collaboration tools, employees might also resort to discussing sensitive client work with colleagues over unsecured video conference calls, said specialists.
"Most companies would have inadequate data protection for remote working environments," said Lee Heng Yu, co-founder of cybersecurity firm Polaris Infosec. "Smaller companies might not equip their employees with the right tools intended for enterprise grade collaboration when they work from home."
This heightened cybersecurity risk appetite could increase the individual's exposure to hacking attempts, CSA added.
According to cybersecurity firm Carbon Black, ransomware attacks have increased by 148 per cent between February and April this year, as the number of telecommuters increased by 70 per cent during the same period.
According to the report on the state of data loss protection from security firm Tessian, 48 per cent of employees say they are less likely to follow safe data practices when working from home. Yet, up to 91 per cent of IT leaders have to rely on employees to follow such security policies when they work from home.
Many SMEs are now struggling with cyber protection and cybersecurity, said Stanislav Protassov, co-founder and president at cyberprotection firm Acronis. "Right now, this situation favours cyber criminals as many who are working from home are not protected by corporate IT networks or company firewalls."
Even if they are protected, employees might choose not to turn on company's firewalls or virtual private networks (VPN) at all times, especially if there isn't a strict cybersecurity policy or training to ensure that employees uphold these cybersecurity protocols, Mr Protassov added.
It is during these downtimes - and when employees click on malicious links - that cyber attackers can have the opportunity to infiltrate a company's system, encrypting or wiping their data completely.
Companies need to assess the risks and impact to their systems, data and customers when deciding on a cybersecurity strategy, said David N. Alfred, co-head and programme director for the Drew Data Protection & Cybersecurity Academy.
"SMEs that are not required to implement specific measures under the applicable laws and regulations might see cybersecurity as less of a priority. However, they should consider the potential financial cost and reputational damage if a data breach were to happen. Beside mitigating the effect of a data breach, a good cybersecurity strategy can help the company build consumer trust and gain a competitive advantage."
READ MORE: SMEs appear ill-prepared for greater risks of cyberattacks as online workforce rises
TRENDING NOW
Three ex-employees of Envy group join Ng Yu Zhi in bankruptcy
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
Incidence of civil servants buying property near unannounced MRT stations ‘a concern’, but may not establish misconduct: PSD