The new world of work has become something of a free-for-all, with some people staying fully remote while others are back in the office full-time, or sometimes — it’s enough to drive security teams crazy.
With all of these variables to contend with, today, the most challenging aspect of cybersecurity is identity, according to Jack Poller, senior analyst at ESG Group. Companies have been practicing network security for many years, starting with firewalls and moving to zero trust network access (ZTNA), secure access service edge (SASE) and security service edge (SSE).
Likewise, they have been addressing insider risks through data leak/loss prevention (DLP) and insider risk management (IRM) for quite a while, he said. So network security, DLP and IRM are relatively mature practices with mature vendors, tools and workflows.
“However, it’s only been in the past six months to a year that we’ve begun to recognize the importance of identity to cybersecurity,’’ Poller said. “Because we’ve only recently begun to focus on securing identities and the identity infrastructure — what we’re now calling identity security. We lack a mature identity security practice with well-established tools and workflows.”
The ongoing identity security challengeIdentity remains one of the biggest challenges for organizations with 43% saying that more than 20% of their workforce identities are insufficiently secured, according to Poller’s latest research. A whopping 77% of organizations think or know they’ve experienced credential compromise in the past year, and 76% of those experience multiple compromises And, account compromise leads to cybersecurity attacks more than 70% of the time.
Verizon’s latest Data Breach Investigation Report substantiates that, indicating that more than 85% of data breaches involve the human element and more than half involve stolen or compromised credentials.
“Phishing, social engineering and compromise of credentials due to data dumps are the most common causes of credential compromise,’’ Poller said. “Unfortunately, my research shows that even though we know that multifactor authentication (MFA), makes credential compromise significantly harder, 38% of organizations don’t make MFA mandatory for their entire workforce.”
When MFA is used it is most often the most insecure, most phishable forms of MFA — SMS, email one-time codes and push notification apps, Poller said.
“Return to the office and additional training will not prevent humans from being human, and thus being susceptible to manipulation and social engineering,’’ he added.
Return to the office could disrupt personal cybersecurity habitsAnother newer issue is that “the transition from a fully remote to a partially on-site work environment creates substantive cybersecurity concerns based on the ongoing mental health crisis,’’ said IEEE senior member Kayne McGladrey.
As some businesses attempt to mandate a return to the office, they should be aware of the mental health challenges employees are facing, he said. “Research shows a significant decline in workers' mental well-being, resulting in stress and anxiety. These mental states can negatively affect decision-making and lead to cybersecurity lapses.”
For example, a stressed employee may be more prone to falling for phishing attempts or neglecting to secure sensitive data properly, McGladrey said.
“The transition back to the office could disrupt the personal cybersecurity habits that remote workers have established,’’ he added. “Employees may experience cognitive overload if they must adapt to different security controls in different work settings.”
The situation is exacerbated by a decrease in available mental health support, according to McGladrey. Without adequate resources, employees are even more susceptible to stress and anxiety, which can lead to further lapses in cybersecurity.
“Therefore, as businesses transition to hybrid work models, it is critical to maintain a strong focus on both mental health resources and robust cybersecurity controls. By addressing these interconnected issues, companies can ensure a secure and productive workforce,’’ he said.
Squeamish about Wi-FiOne change some organizations are making is to require employees who are staying remote or hybrid to use business-owned laptops that they are not only managing but also embedding with 5G connectivity, said Jack Gold, founder and principal analyst at J.Gold Associates.
This way, they don’t have to worry about the security of home Wi-Fi, he said. “This is important because 5G is inherently more secure than public Wi-Fi,’’ which also comes in handy when employees travel. “It’s not a huge number of companies that are doing that,’’ Gold noted, “but it’s growing and we’ll see more of that going forward.”
The nuts and bolts of securing all workersThere are no new controls companies can buy to mitigate the business risks of requiring a full return to the office, McGladrey said. “Instead, the emphasis should shift to adapting existing traditional controls for the unique challenges of transitioning from remote to in-office work.”
He recommended several measures including the following:
- Security training: Employees may face unfamiliar types of threats as they transition back to the office. Companies should conduct targeted training that addresses both remote and on-site work risks.
- Role-based access: The risk of access-related breaches increases in a mixed work environment. Companies should revise and update role-based access settings to suit both remote and in-office conditions.
- Mental health support: Cybersecurity teams will experience increased stress due to the change in work environments. Companies should provide mental health resources designed specifically for the cybersecurity team as well as their colleagues.
- Multi-factor authentication: Phishing risks may vary when employees are working from multiple locations. Companies should adopt FIDO2 keys and educate employees on their use to enhance phishing resistance.
- Outsourcing to a managed security service provider (MSSP): Managing a hybrid workforce can lead to further stress and inefficiencies for internal cybersecurity teams. Companies should delegate initial event triage to an MSSP, which will free up the internal team to focus on high-priority tasks.
Supporting an always-on workforce using any device and any network at any time changes how IT and security teams network architecture, and effectively destroys the traditional castle-and-moat perimeter cybersecurity strategy, said Poller. This is one of the many reasons organizations are shifting to zero-trust cybersecurity strategies.
Zero trust means applying the principle of least-privilege access and giving employees only the access they need to do their jobs.
“With zero trust, we can’t decide to trust someone — or something —without first authenticating they are who they claim to be,’’ he said. “Thus, we must authenticate users and the systems they connect to which requires a robust and mature identity security.” This consists of strong authentication, identity federation across the entire environment, and consistent application of authorization policies.
“And, as has recently been exemplified by the MGM and Caeser’s breaches, we also need to protect our identity security infrastructure. With zero trust and strong identity security, we can support local and remote users with our existing network security solutions,” Poller said.
When least-privilege access is applied, it “reduces the blast radius when an identity gets compromised and reduces the exposure from insider threats,’’ Poller said. He notes that “insider” refers to someone within the organization who has access to sensitive data rather than inside the castle-and-moat perimeter. Thus, the insider threat exists regardless of whether the worker is on-site or remote.
In addition to applying zero trust, arguably the most important step is for organizations to change their cybersecurity strategy, Poller stressed.
“Organizations also need to make identity security the core of their cybersecurity stack,’’ he said, “as everything in cybersecurity is all about controlling local and remote access to resources and data based on identities.”
Comments