Improving the security of the WFH workforce
Working from home has quickly become the new normal for many information workers across Ireland, the UK, Europe, and beyond. Lots more people are accessing data and applications hosted on IT systems in the Cloud and in private data centres. The need to protect data and information on those systems from unauthorised access hasn’t been relaxed due to the COVID-19 pandemic. It’s still the responsibility of all organisations to protect data and report any breaches under GDPR.
Most organisations who had robust security before the forced home working will be in a good place to ensure that protections are in place for remote workers. But the sudden shift and increased demands on systems will expose any vulnerabilities that may have remained hidden before. We can be sure that cybercriminals will be looking to exploit the current crisis.
Renaissance and our security solutions partners have the expertise and the tools to enable secure remote access to data and applications for organisations of any size. We are available to help with any questions that you might have if you need to review your current remote working solutions. Contact us today to arrange a review or discussion about your current setup. Read on for an overview of some of the areas that you need to think about to deliver robust and secure remote working.
Have Experts to Call Upon
Working from home will be a new experience for many people. Office environments lend themselves to lots of informal ad-hoc knowledge exchange. If feasible, have IT experts, or designated expert staff members available to answer any questions that anyone might have. Encourage an atmosphere of openness so that no-one is embarrassed to ask about security (or any other topic!) if they are not 100% sure. Anyone providing this central contact role will likely not have time to perform another function, so don’t expect them to be able to fulfil this role as well as their regular duties.
Guidelines and Policies
Most organisations have written policies on data handling and security as a result of GDPR compliance. Make sure that these are known to everyone working remotely. Any questions they may have should be handled by the experts outlined in the previous point.
Use Strong Passwords
Make sure that all remote staff are using strong passwords on their devices at home. And that they are not sharing these passwords with family members, or writing them down on notes stored with their devices. Most corporate devices will have strong password policies enabled, but many personal devices may be in use in this crisis. Make sure that they are using strong passwords, and separate accounts if the devices are shared with other family members.
Multi-Factor Authentication
While strong passwords are a must, it is also best practice to adopt multi-factor authentication. This requires that access to systems needs additional information beyond the password, that only the authorised user will have. Renaissance and our partners can help you select and deploy a suitable multi-factor authentication solution if you don’t already have one. They can be enabled quickly via Cloud-based deployment.
Anti-Malware & Virus Protection
Make sure that all devices that can have it are running anti-malware and anti-virus software. Most work provided devices will have this already, but you should make provision for deploying it to any personal devices that may be in use. Some devices can’t have 3rd party anti-virus solutions installed - iPad for example, as the iOS operating system has Apple protections built-in and enforced application ‘sandboxing’ prevents the spread of software viruses.
Implement Phishing Protection
Phishing will be a real threat during this crisis. Malicious actors will increase their activity to try to trick staff into clicking on spoofed links in emails to steal sensitive and personal information. Make sure that all the anti-phishing options provided by email solutions are enabled. Also regularly update staff about the dangers of clicking on links in emails. Even if they think they know the sender. Think about enabling DMARC protection for your email domains if not already in use.
Secure Home WiFi
Most home workers will be using their broadband WiFi. Make sure that they have it secured with a password, and that security features are enabled. If for security reasons you don’t want a homeworker using their WiFi then consider a 4G mobile WiFi (MiFi) device from your mobile supplier. This will provide connectivity over the cellular network and can be secured with corporate policies.
Use Secured VPN Access
Make sure that any access to data and applications that are located in private data centres is done over a secured VPN (Virtual Private Network). Also, combine this with multi-factor authentication.
TLS Protect Web Applications
Web applications that are accessed on Cloud systems should all be using HTTPS and secured by TLS 1.2 or later. Data transfers over the network to and from remote devices should also be encrypted using the latest TLS 1.2 or later standard. This encryption can be enabled on the border security devices on infrastructure such as firewalls or remote access gateways.
Encrypt Everything
Try to ensure that all data used and accessed by remote workers stays in the data centre or the Cloud. If data does need to be stored on remote devices, then ensure that it is encrypted. This is easy to do on all current operating systems that will be in use. Let you IT experts guide anyone working remotely through enabling it if required for personal devices. If data needs to be stored on removable storage devices, then ensure that only hardware-encrypted USB and external hard drives are used. Our ClearCrypt storage solutions will enable this.
Mobile Device Management
A way of delivering security to remote devices is via an MDM (Mobile Device Management) solution. MDM allows security settings to be pushed to devices so that they can be secured using agreed central policies. Most MDM solutions will enable the use of personal devices and can be configured to secure work-related data and applications while leaving personal data and applications intact and untouched. MDM solutions are increasingly being delivered as part of a more comprehensive Enhanced Network Access Control (ENAC) solution that combines all device configuration and management in a single solution. You may have one in place already. Your IT team will know, or contact us for more info.
Conclusion
Data protection and security is essential, no matter where staff are accessing it. The current crisis will invite a focus on security as time goes on. The tools and solutions are available to ensure that data is protected while work is done from remote locations. Contact us today to find out more about how you can enable and protect your organisation in this challenging time.

