×

Message

Failed loading XML... Document is empty

iTWire TV 705x108notfunny

Friday, 04 August 2023 10:41

How Remote Work Increases Insider Risk

By Vina Nguyen

GUEST OPINION:  The choice to hire remote can bring in the best of the best. But even the best slip up sometimes. When remote work increases the cost of a data breach by $1 million, exposure comes with the territory. No perfect solution exists, but being aware of the trade-offs will help you prepare for the worst. Read on to understand how remote work can put your business at increased insider risk.

Video is personal until it isn’t

Remote work can get pretty close to working on-site. There’s a plethora of digital tools for brainstorming, project management, document storage, meetings, and even water cooler talk. There’s text and there’s phone and there’s video.

Even with all these technologies, apart from some instances, the bond a team forms in-person is hard to match online. A study from MIT’s Human Dynamics Laboratory found that the best indicators of highly productive teams is their “energy and engagement outside formal meetings.” Remote work often means team interactions are defined by formal meetings. Building opportunities to connect outside of formal meetings takes much more effort and initiative online than when on-site.

If a team lacks the resources and commitment to build this camaraderie, workers may feel less personal connection to the company, which affects their outlook and loyalty to the company. Gallup research shows that those who have a best friend at work are twice more likely to recommend their place of work. Insider risk can become a threat when workers stop feeling accountable for the entire organization and start looking out for only themselves.

Life, liberty, and less visibility

One of the most effective ways to reduce insider threat is to watch out for behavioral indicators like working overtime, high stress, and frequent disregard of information technology policies. While some behaviors can be detected by data loss prevention solutions, many are best detected through human interaction. In the absence of informal check-ins and presence of peers, employees may fly under the radar, leaving the risk of personal problems turning into serious risks for the company.

Keep in mind that this risk applies to both well-intentioned and malicious insiders. Employees who started out lonely may start to act out of desperation or hostility, and stealing data is much easier from a home vs. a work office.

Bad habits become negligence

Managers of remote teams lack the ability to physically walk the halls to encourage (and enforce) standards of behavior. When employees have much more autonomy in how they work, the lack of oversight provides more opportunities for negligence, both intentional and not.

The ability to work from home or cafe or beach means a wide range of exposure beyond an office building with rigorous standards and 24/7 security. Passing strangers might catch a view of the screen, or overhear a phone conversation that shouldn’t have happened in public. Distractions or attempts at multi-tasking could result in slip ups to protect company data. Even a cyber-aware professional may forget to lock their laptop in a rush or throw documents in the trash without shredding.

Negligence also happens working isolated, when employees blur the lines between work and home, passing information between unsecured (or poorly secured) networks and personal devices for reasons like convenience. A recent study by the Ponemon Institute reported that 63% of data breaches are attributed to negligence. Expect the risk of a data breach to go up when remote work is the main mode of operation. When the working environment is left to the individual to secure, a business accepts a higher probability of exposure.

More technology, more attack vectors

When nearly 100% of the communication happens online and remote, the natural result is a larger attack surface. This attack surface increases when employees use their personal devices to login to corporate VPN, a common setup for companies as a cost-saving decision. VPN, however, was not architected for Bring Your Own Device; VPN allows full network access to anyone connected. If the personal laptop is compromised or the employee is seeking to commit fraud, your entire infrastructure is accessible.

Additionally, the increasing use of cloud applications makes data breaches much easier, especially with improperly configured identity management and security settings, leaving some data repositories exposed to the public with the right URL. Employees may also create accounts and drop sensitive company data on brainstorming or note-taking web services, which may be unsanctioned by your organization.

What to consider from here

The advantages of remote work often outweigh returning to working 100% on-site, but being aware of the risks will help you understand what steps to take to protect your business. Once you reach an acceptable level of risk, you will be able to remain competitive by recruiting the best staff and protecting your most critical data.

Read 1590 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




EXL AI IN ACTION VIRTUAL EVENT 20 MARCH 2025

Industry leaders are looking to transform their businesses and achieve measurable outcomes with AI.

As organisations across APAC navigate the complexities of AI adoption, this must-attend event brings together industry leaders, real-world demonstrations, and visionary panel discussions to bridge the gap between proof-of-concepts and enterprise-wide AI implementation.

Learn how to overcome common challenges in deploying AI at scale.​

Unlock cost savings, efficiency, and better customer experiences with AI.

Discover how industry expertise and data intelligence enable practical AI deployment.

Register for the event now!

REGISTER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Share News tips for the iTWire Journalists? Your tip will be anonymous

Subscribe to Newsletter

*  Enter the security code shown: img0

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments