THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Tuesday, January 03, 2023
After nearly two years of pandemic-induced remote work, it would be natural to assume that organizations have streamlined their security protocols.
FREMONT, CA: After nearly two years of remote work prompted by a pandemic, firms have tightened their security processes and are operating confidently. Unfortunately, such has only sometimes been the case. In a survey conducted by my company in April 2021 of U.S. and EMEA security professionals, more than half (54 percent) reported that their organizations were still experiencing downtime and disruption from network security issues. This was an improvement from the 61 percent who reported issues in the first six months of the pandemic, but it was not as significant as anticipated.
These survey results represent a time when most enterprises still had a majority of remote workers. Today, many businesses are gradually bringing their employees back to the office, testing the waters, and supporting hybrid models to balance employee readiness and business requirements. During the past two years, people have been functioning in a borderless working environment, and businesses have been tasked with protecting hundreds or thousands of "micro-offices." With varying security standards for user connections and limited control over user behavior, the attack surface has grown dramatically. This dynamic creates many possible exploitable flaws, which is bait for would-be attackers.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
What does this imply for the IT experts responsible for keeping the sharks at bay? It has resulted in a near-total reorientation of their strategy, from defending on-site networks to protecting remote employees operating in a borderless work environment. Security professionals face new obstacles now that their mission has placed them in the middle. Their remote user population has necessitated more than just the security projects they planned to undertake. They have had to accelerate the implementation of policies and technologies to manage the distant population. Already constrained resources have been further depleted.
Determine what needs protection first
Maintaining network security is unquestionably critical; every day without an appropriate answer is another day attackers can strike gold. But before investing in security, firms must identify their assets and locations.
Maintaining and securing employee connectivity and the company's infrastructure are top considerations. This corporate infrastructure may no longer be maintained only from an on-site data center; important systems may be handled via cloud-based microservices or third-party cloud services. The once well-defined security perimeter has grown increasingly hazy, and businesses must determine whether vital borders have gaping, unprotected vulnerabilities.
Consider the many possible dangers.
Just as the complexity of business networks and infrastructure has increased, so too have attack vectors. How and where applications or systems are hosted can decide which risks are more severe or likely to arise. Web applications have been demonstrated to be a leading vector for hacking, especially content management systems, which several enterprises utilize to share information and have a digital presence. Compromising one of these systems could grant intruders access to your firm.
Domain name system (DNS) attacks are also rising, as DNS services are inherently very open and vulnerable to malicious actors. Domain hijacking, DNS cache poisoning, DNS tunneling, and botnet-based domain attacks can bring a business to its knees, resulting in brand and reputation damage that exceeds the monetary cost.
Taking advantage of the remote work environment, attackers have begun utilizing DDoS to target the virtual private networks of businesses (VPNs). These threats are only the tip of the iceberg, and security teams must design preventive solutions that account for these and other vectors.
More in News