Navigation

Set your main menu in Appearance > Menus

Software Asia Limited
MENUMENU
MENUMENU
  • ABOUT US
    • COMPANY OVERVIEW
    • OUR PARTNERS
    • PARTNERSHIP WITH LOGON
    • CAREER WITH LOGON
    • CONTACT US
  • INFORMATION SECURITY
    • Vulnerability Management
    • Multifactor Authentication
    • Threat Intelligence
    • Network Management Solutions
    • Security Information and Event Management
    • Remote Access Software
    • Systems Administration Tools
    • Robotic Process Automation
    • Data Loss Prevention
    • Data / Password Recovery
    • Asset Management Solutions
    • Identity and Access Management
    • Antivirus
    • Activity Monitoring and Surveillance
    • Forensic Solutions
  • SOFTWARE DEVELOPMENT
    • Integrated Development Environments
    • Development Components
      • UI Components
      • Networking Components
      • Office Components
      • Barcode Components
      • Communication
    • Imaging Solutions
    • Software Localization
    • Release Automation & Management
    • eLearning Authoring Solutions
    • Charting Solutions
    • PDF Solutions
    • Reporting Solutions
    • Testing & QA
    • Text Retrieval/Enterprise Search
    • Database
  • Services
    • TRAINING SERVICES
    • IMPLEMENTATION SERVICES
    • AFTER-SALES SERVICES
    • BEST PRACTICES CONSULTING
  • WHAT'S NEW
    • EVENTS
    • LATEST UPDATES
    • SPECIAL OFFERS
  • SEARCH

Set your main menu in Appearance > Menus

Email Us Service Hotline: +852 25128491
Software Asia Limited
MENUMENU
MENUMENU
  • ABOUT US
    • COMPANY OVERVIEW
    • OUR PARTNERS
    • PARTNERSHIP WITH LOGON
    • CAREER WITH LOGON
    • CONTACT US
  • INFORMATION SECURITY
    • Vulnerability Management
    • Multifactor Authentication
    • Threat Intelligence
    • Network Management Solutions
    • Security Information and Event Management
    • Remote Access Software
    • Systems Administration Tools
    • Robotic Process Automation
    • Data Loss Prevention
    • Data / Password Recovery
    • Asset Management Solutions
    • Identity and Access Management
    • Antivirus
    • Activity Monitoring and Surveillance
    • Forensic Solutions
  • SOFTWARE DEVELOPMENT
    • Integrated Development Environments
    • Development Components
      • UI Components
      • Networking Components
      • Office Components
      • Barcode Components
      • Communication
    • Imaging Solutions
    • Software Localization
    • Release Automation & Management
    • eLearning Authoring Solutions
    • Charting Solutions
    • PDF Solutions
    • Reporting Solutions
    • Testing & QA
    • Text Retrieval/Enterprise Search
    • Database
  • Services
    • TRAINING SERVICES
    • IMPLEMENTATION SERVICES
    • AFTER-SALES SERVICES
    • BEST PRACTICES CONSULTING
  • WHAT'S NEW
    • EVENTS
    • LATEST UPDATES
    • SPECIAL OFFERS
  • SEARCH
View large
holm security-news, news

Security risks working from home | Holm Security

Posted on at by logon

Security risks working from home

This article was originally published by LOGON’s partner Holm Security. Click here to view the original article.

Remote work has increased drastically and at the same time, there are clear indications that hackers, foreign powers, and other cybercriminals are increasing their activities. Working from home poses an increased challenge for IT departments, now required to offer flexible and secure solutions. This is a great challenge, not least because secure solutions are often more tedious for the end-user. While working from home is not something new for many organizations, the large number of people working from home is, which also increases exposure to a variety of security risks.

 

1. Implement a clear policy

First and foremost, your organization should have an easy to understand written policy concerning remote working. Avoid long documents that no one will really read, instead go with one page covering the essentials. This policy should include guidelines for what you can do on your company’s computers and how to connect securely. What happens, for example, when an employee uses their work computer for private browsing and streams through VPN and occupies bandwidth both in and out of the organization.

 

2. Use VPN

Connection to your organization’s system should be done with a VPN, but it’s important that authentication is still required for various services and systems, such as Microsoft Remote Desktop and SSH. You should also avoid exposing services that use SSH and RDP directly to the Internet. Take advantage of available certificate-based login along with two-factor authentication.

 

3. Copying of information

Working remotely allows malicious users the opportunity to copy, save and spread sensitive information. Therefore, your policy should also contain guidelines on how documents should be handled and what type of USB equipment may be connected. If a user can easily copy all documents from the document server to a USB flash drive? Malicious code could do the same.

 

4. Video conference

Many video conference systems offer a wide variety of possibilities and settings. Using the wrong settings can drastically increase the risk of espionage. Make sure users are using secure settings, which means using secure passwords, and locked conferences. Also, make sure the software is always up to date. Many video conferencing companies are continuously discovering ongoing vulnerabilities, in these times when their systems are being put to the test.

 

5. Train & keep users aware

Educate your users continuously and do awareness training. It can, for example, be done through various simulations of social engineering, like the simulation of phishing campaigns. Keeping users safe can be compared to keeping a system secure. It is not a one-off effort but requires continuous work overtime.

 

6. Assume that the home network is already hacked

Do not give the user too much freedom to install own software just because he works from home. A home network can consist of many different types of components and systems that can be hacked or compromised. A good starting point is to work based on the principle that the home network is already hacked.

 

7. Monitor continuously

Monitor events such as unsuccessful login attempts. Work proactively to detect vulnerabilities in protocols and services used. Maybe it is time to review an external service that monitors events 24/7, such as a Security Operations Center (SOC) service.

 

Risk behaviors

Working from home involves increased risk behaviors. Here are a few.

  • Connections are made via unsecured Wi-Fi networks at home and when the user is in motion.
  • Increased risk of lost and stolen computers.
  • Increased private activity, which gives increased exposure to various risks, not least websites that spread viruses.
  • Reduced resistance to social engineering such as phishing and ransomware.
  • Increased risk of non-compliance with the company’s security policy.
  • Increased risk of computers and systems not being updated.
  • Increased risk of copying and dissemination of sensitive information.

 

Checklist for increased security

 

Clear policy

Have a clear and simple user policy – what the user can and cannot do. Educate your users on what allowed on the company’s computer.

 

Use disk encryption

Use hard disk encryption. So even if a computer is lost, it is very difficult to access the information in it.

 

Backup

Have a solution for backup and recovery of files and data.

 

Update software

Make sure to keep computers and systems up to date. Not the least the software used for teleworking.

 

Two-factor authentication

Enable two-factor authentication where possible.

 

Log events

Make sure that relevant events are logged on the client and that you receive alarms on suspicious activity.

 

Clear contact paths

Ensure that the user knows whom to contact in the event of a suspected or identified incident.

 

Restrict & control

Make sure you have control over users’ computers. Restrict permissions and what software can be installed.

We are Distributors of Holm Security in  Hong Kong,   Macau, andIndia

Holm Security is a global challenger within automated and continuous vulnerability management.

Book a Free Assessment for Holm Security
was last modified: May 4th, 2021 by logon
Share Post
Previous
Spam: what kinds of it are there and how to understand that it is fraudulent? | Falcongaze
Next
Protecting Active Directory logins for remote working | IS Decisions

About Author

logon

COMPANY

Company Overview
Career with LOGON
Contact Us

JOIN US TODAY

Resellers
Software Publishers
Procurement Managers

WE ARE AVAILABLE ON

SAP Ariba   coupa

gem

SERVICES

Training Services
Implemetation Services
After-sales Services
Best Practices Consulting

WHAT'S NEW

Events
Latest Updates
Special Offers

FOLLOW US ON

GET IN TOUCH

Phone:+852 25128491
Email: [email protected]

Legal   |   Privacy Policy

Important Links

  • Call me
  • Legal
  • Privacy Policy

Search engine

Use this form to find things you need on this site
Search

Results for {phrase} ({results_count} of {results_count_total})

Displaying {results_count} results of {results_count_total}

Dont see what you were looking for ? Retry the search with a different phrase ? If unsuccessful, please click here

Generic filters
Exact matches only
Search in title
Search in content
Search in excerpt
Newsletter
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Request for Training Quote
  • Please enter a number from 1 to 20.
Contact Us Today
Book a Demo with us


Book a Demo with us


Free Website Risk Detection Request

    Request a Demo !

      Search

      Results for {phrase} ({results_count} of {results_count_total})

      Displaying {results_count} results of {results_count_total}

      Dont see what you were looking for ? Retry the search with a different phrase ? If unsuccessful, please click here

      Generic filters
      Exact matches only
      Search in title
      Search in content
      Search in excerpt
      UserLock Video