Cybersecurity breaches skyrocketed last year, and the post-pandemic boom of remote work is largely to blame, according to a new report from Proxyrack's.
The proxy provider used IBM's "Cost of a Data Breach Report 2021" to stratify the average cost of a data breach based on the percentage of remote employees. The highest tier – companies with between 81% and 100% remote employees – clocked in at just over $5.5 million in average costs. The least costly tier was those companies with between 41% and 60% of its workers remote and averaged $3.1 million in costs.
Using the same research, Proxyrack found the U.S. is currently the most targeted country in the world, weathering 2.4 billion total data breaches, including 452 million in the last three years and 30 million last year alone.
“When company systems are connected remotely to give remote workers access, the IT department cannot closely monitor the system for attacks. As a result, ransomware and phishing scams have boomed since the rise of remote working,” Ariana Bago, a fraud analyst from Proxyrack, explained to SDxCentral via email.
Cybercriminals target employees with pop-up messages or email links that when clicked enable them to steal passwords and information, or preventing users from accessing the computer system. At least two of every five remote employees also move unsecured data from a company system to personal email accounts, according to Bago, which further enables fraudulent access.
“Remote work has resulted in businesses introducing or altering their network structure; however unsecured networks have been a key factor in the rise of data breaches," Bago explained. "Weak passwords, outdated software, and unsecured emails has meant hackers have been able to attack companies' remote work systems, resulting in data breaches.”
Companies have responded to theses issues with a growing value placed on security and control within enterprise network modernization as well as an increasingly vital role played by chief information security officers (CISOs).
Keeping Up With the CriminalsWhile industry moves have indicated a shift away from the dominant VPN access method and a pivot toward zero trust – such as Amazon Web Services (AWS) announcing its latest Verified Access security service – Bago backs VPNs as “the most effective way for employees to protect their network at home." Ultimately, she says multi-factor authentication (MFA) is the key protection against this type of vulnerability.
Since 2020, bring-your-own-device (BYOD) models have increased 58%, according to Proxyrack, yet companies have not responded with sufficient BYOD policies or monitoring, leaving individual employees as a high-cost vulnerability in data security.
“With more devices handling company data, there is an increased attack surface for cybercriminals to target, resulting in increasingly costly data breaches,” she explained. “In order to reduce this risk, multi-factor authentication should be installed on any device handling company information.”
Bago also warns that companies should stay away from allowing employees to use their personal devices when working remotely; spreading enterprise data across multiple home devices “vastly increases the attack surface available to hackers.”
She added that it's important for businesses to invest in biannual training for employees to stay up to date on how to identify the increasingly difficult to detect cyberattacks.
Comments