{"id":45641,"date":"2021-09-29T09:28:19","date_gmt":"2021-09-29T01:28:19","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=45641"},"modified":"2021-10-03T23:48:40","modified_gmt":"2021-10-03T15:48:40","slug":"unmasking-the-human-element-in-cybersecurity-in-a-pandemic-time","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/09\/29\/unmasking-the-human-element-in-cybersecurity-in-a-pandemic-time\/","title":{"rendered":"Unmasking the human element in cybersecurity in a pandemic time"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Chris Connell<\/em><br><em>Managing Director for Asia Pacific at Kaspersky&nbsp;<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Imagine this: your company has a precious treasure to protect, the defenses with the latest technology were set up. However, the guards on duty were not informed of the treasure, neither were they provided the knowledge of how to navigate the defense systems. Worse still, the guards did not recognize the treasure as something to be protected. When the enemy came, they easily bypassed the guards, disabled the security systems, and stole the treasure, demanding a large sum of money in return for it. In the context of cybersecurity for businesses, it is not difficult to guess which elements of the story represent the company data, cyber defenses, employees and ransom, in the instance of ransomware.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While one might dismiss this scenario as silly or implausible, it is an increasingly pertinent issue many companies are facing. Just earlier this year, over the span of just three months, six cyberattack incidents were reported in Singapore and around the region \u2013 a rising and certainly worrying trend. While it is natural instinct for IT personnel to respond by fortifying their <a href=\"https:\/\/online.maryville.edu\/blog\/cyber-crime-investigation\/\">cybersecurity infrastructure<\/a> in an attempt to contain the breach, this is not the end of it all.\u00a0 When it comes to cybersecurity, non-IT personnel have been found to be a company\u2019s weakest link. Unfortunately, more needs to be done to ensure employees do not end up becoming a company\u2019s Achilles\u2019 heel.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The risk from within<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the first time ever last year, companies across the world rushed to pivot online as the pandemic spread across the world. In a span of a few days, employees brought home their work, and as the weeks turned to months, employees got used to working from home \u2013 setting up conducive office spaces as a sense of normalcy returned. However, in the midst of setting up office spaces, an important aspect of telecommuting was missed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a survey we conducted, around<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2020\/05\/03191550\/6471_COVID-19_WFH_Report_WEB.pdf\"> half of respondents had never worked from home before<\/a>, and<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2020_homeworkers-wait-for-protection-73-of-employees\"> almost three-quarters<\/a> of them had not received any guidance or training when it came to cybersecurity awareness. Over time, the physical workstation was all set, but there were gaps in how organizations provided employees with the basic IT knowhow and refresher on basic cyber hygiene practices. While social distancing measures proved to stem the spread of the coronavirus among co-workers, somewhere in the cybersphere, these same employees \u2013 uninformed or plain careless \u2013 were potentially allowing malware and viruses to spread.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It might come as a surprise to some that employees are one of businesses\u2019 largest vulnerabilities. However,<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/the-human-factor-in-it-security\/\"> more than half of businesses<\/a> believe their cyber risk stems from within. The top three cybersecurity worries of a business are often<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/the-human-factor-in-it-security\/\"> related to employees or human error<\/a> \u2013 sharing inappropriate data via mobile devices (47%); physical loss of mobile devices exposing the organization to risk (46%); and use of inappropriate IT resources by employees (44%). While one may point fingers at security systems which should be able to guard devices from potential malware especially in the event of a misuse of corporate devices, the reality is that many employees use devices with outdated patches. And threat actors know how to exploit these vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2021_escalating-work-privileges-64-of-employees-who-argued-with-the-it-department\">64% of employees<\/a> who had argued with their IT department were allowed to skip updates or select what aspects of their corporate security systems to update, and<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2021_escalating-work-privileges-64-of-employees-who-argued-with-the-it-department\"> 44% of employees were less concerned<\/a> about updating their work devices than personal ones. This suggests a gap where employees do not view maintaining cybersecurity as being of high priority. As if not concerning enough, the action \u2013 or lack thereof \u2013 of senior businesses leaders in the company could potentially further exacerbate the issue of lapsed security systems. Senior executives are<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/theonebrief.com\/when-the-top-is-targeted-protecting-the-c-suite-from-cyber-risk\/\"> 12 times more likely to be targets of cyber threats<\/a> than other employees. Aside from the fact that they have greater access to privileged information, they might also \u201cenjoy\u201d more lax security concerns than other employees.<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/it-security-economics-2020-part-2\/?utm_source=press-release&amp;utm_medium=partner&amp;utm_campaign=gl_economics-report_kk0084&amp;utm_content=link&amp;utm_term=gl_press-release_organic_nepblhe84a87xs6\"> 45% of the surveyed organizations exclude C-suites<\/a> from their update plans, which increases their exposure and vulnerabilities to cyberthreats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>BYOD \u2013 Bring Your Own Dangers?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As employees continue adjusting to their homework environments, the divide between home and work blurs \u2013<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2020_half-of-employees-watch-adult-content\"> more than half<\/a> of those working from home admitted to watching adult content on the same devices they use for work purposes. While not all employees might exhibit such behavior to this extent,<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2020_half-of-employees-watch-adult-content\"> 49% of employees<\/a> have admitted to using personal email accounts for work-related matters since working from home, and<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2020_half-of-employees-watch-adult-content\"> 38% use personal messengers<\/a> that have not been approved by their IT departments. This is the perfect recipe for cybercriminals to breach corporate data and devices. Moreover, in some instances, simply being connected to the same network could even put the most careful worker\u2019s device at risk. Some malwares, such as worms do not require human help to infect, self-replicate or propagate, but infect their entry point and spread through devices that connects to the same network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It may be seemingly innocent for employees to cross use between personal and work devices while working from home. However, with<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2020_homeworkers-wait-for-protection-73-of-employees\"> 73% of employees not receiving any IT security awareness training<\/a> from their employer since transitioning to working from home \u2013 this alludes to almost three quarters of remote employees blissfully unaware of the dangers lurking online. Of cybersecurity incidents faced by businesses in the past 12 months,<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/the-human-factor-in-it-security\/\"> 11% of them involved careless employees<\/a> and falling prey to phishing or social engineering attacks. The simple action of clicking on the \u201cwrong\u201d email actually sent by threat actors could lead to disastrous effects of putting their company\u2019s data or systems at risk. This could be avoided had there been proper training on how to behave appropriately and awareness of protecting the business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During these times of remote working, when employees are spread across various locations in the country or even world, it is indeed a challenging task for IT personnel to ensure they continue carrying out their jobs well. Ensuring the continued safety of a company will indeed take the combined efforts of all employees. One of my favorite analogies regarding the prevention of potential cyber threats, and to demonstrate the importance of businesses shoring up their cyber defenses is simple: If you would never leave the front door of your house open all day with the possibility of someone walking in, think of your computers and cyber defenses the same way. Keep your network access and your systems tightly secured, and do not leave any opportunity for a cybercriminal to get in through open windows or doors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">No one is immune to cyber threats, nor can we prevent the instance of it from happening. However, good cybersecurity system can mitigate its impact or minimize any disruptions faced.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For the first time ever last year, companies across the world rushed to pivot online as the pandemic spread across the world. In a span of a few days, employees brought home their work, and as the weeks turned to months, employees got used to working from home \u2013 setting up conducive office spaces as a sense of normalcy returned.<\/p>\n","protected":false},"author":7,"featured_media":45642,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[101,117,54,2103,53,4100],"class_list":["post-45641","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-kaspersky","tag-kaspersky-lab","tag-security","tag-security-breach","tag-security-risk-management","tag-security-solutions"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/45641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=45641"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/45641\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/45642"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=45641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=45641"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=45641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}