The requirement for organisations to hastily migrate their workforce to home working is resulting in many workers spending long periods online, using work equipment that is connected to their domestic broadband, usually via Wi-Fi. The speed of this migration has led to staff using their work equipment for both work and leisure activities. This is being done without the appropriate IT infrastructure, available expertise, data governance, risk management strategies and general preparation needed to support this form of working. At the same time, cyber criminals are using this opportunity to take advantage of the lack of effective security and peoples’ fear of, or curiosity about, the coronavirus. Their aim is to convince employees to click on malicious sites, related to the virus, leading to increased risk of successful malicious phishing campaigns or breaches in security. Reports show that more than 4,000 coronavirus related domain names were registered in the last few weeks. Many of these are malicious, including one site that lures victims by persuading them to click onto a coronavirus tracking app that downloads a virus or trojan onto the computer, that then goes on to infect the organisation’s system the next time the employee logs on. The sheer volume of phishing emails and other security threats related to coronavirus includes international gangs sending over 1.2 million malicious emails at a time. Many organisations are discovering too late that the human factor is the weakest element in their cyber security chain. Poor training and ineffective enforcement of remote work policies are leading to their IT security being compromised. To have any chance of surviving a cyber-attack during the coronavirus lock down, it is essential that organisations implement fundamental safeguards to ensure company data and networks remains secure such as:
- advice and information to employees setting up security on their home wi-fi ¡ guidance / rules on using public wi-fi networks, or preferably mandating employee use of private Wi-Fi networks
- ensuring employees only use work e-mail accounts for business and limiting devices or equipment they can use
- ensuring that staff are adequately trained, restricting work equipment to business-related tasks only.
- requiring multifactor authentication for business apps and networks ¡ implementing robust VPN infrastructure.
- reminding employees to be vigilant for possible increases in phishing attempts.
- having a communication plan for reporting suspected breaches or phishing attack
If you would like to discuss a cyber insurance policy or what insurance packages are available for your business, or personal use please contact Andy Rolph at 07944 306 203
