Safeguarding Your Mobile Devices in the Age of Remote Work

By: Yashin Manraj, CEO of Pvotal Technologies

The remote office model has brought many advantages to the business world. Businesses have gained greater flexibility and mobility by allowing employees to work remotely. Remote work also has the potential to lower a business’s overhead while reducing its environmental impact.

However, remote work can also have disadvantages. Among the most impactful are the added challenges to cybersecurity that remote work models present. For many businesses, safeguarding the digital tools workers typically employ for remote work has become a chief security concern.

The Rise of the Pocket Office

The pocket office is a subset of the remote work environment. It is a type of home office, but smaller. For remote workers, the pocket office provides the opportunity to establish a work-from-home environment without taking up significant space in the home.

Outfitting a pocket office often involves smaller-than-average digital devices. For example, a desktop computer complete with a tower and monitor is swapped out for a laptop or tablet that can be stowed away when not in use. This shift, which introduces greater flexibility for the worker, has the potential to introduce a variety of new challenges for the security team tasked with safeguarding systems that facilitate remote work.

Studies have shown that remote work models introduce unique vulnerabilities to network security that bad actors are quick to target. A recent report found that at least 20 percent of businesses have been victims of data breaches resulting from vulnerabilities unique to the remote work model. The findings are all the more disturbing when considering those breaches are potentially more costly and may take longer to identify than those resulting from on-site vulnerabilities.

The Cybersecurity Challenges Caused by Mobile Devices

The primary challenge remote work brings to cybersecurity is an increased attack surface area. Every new device on a remote work network adds a new potential entry point for cyber attackers, creating a virtually limitless surface area for cybersecurity teams to defend. To make matters worse, remote workers may use many mobile devices connected to work networks through unsecured home WiFi or mobile data connections.

Cybersecurity teams have little to no visibility of or control over those devices, and new devices can be added without warning. Even with known devices subject to security protocols, modifications such as installing new applications or operating system updates can introduce new threats.

Remote work environments also increase the workflow complexity needed to conduct security updates, meaning a wider variety of operating systems and device capabilities must be considered. Security teams must develop systems that assess each device’s security level, obtain needed updates, and ensure they have been properly deployed.

Safeguarding remote work environments also requires enhanced protection against social engineering attacks. Noting that remote workers often rely more heavily on text messages and mobile apps for communications than their in-office counterparts, cyber attackers have retargeted their social engineering schemes to focus on them. A recent study found that 67 percent of attacks impacting business operations have involved off-site workers.

The Primary Components of a Mobile-Ready Security Strategy

Security teams can take several steps to harden systems that facilitate access to mobile devices. Employing network access controls like secure VPNs, firewall rules, and network segmentation helps repel attacks and contain the damage when attacks are successful. Identity and access management, which includes multi-factor authentication, also makes it more challenging for attacks to succeed.

Developing and enforcing comprehensive “Bring Your Own Device” policies is another important component of an effective strategy. This strategy should include providing remote workers with a list of permitted devices. It should also explain the security controls that must be present on those devices and the compliance responsibilities employees will have to keep security on those devices up to date.

Endpoint detection and response (EDR) is an emerging approach to remote office security that enhances the effectiveness of other safeguards by adding remote device monitoring to existing security protocols to detect suspicious activity as it occurs. EDR aims to give security teams advance warnings of attacks, thereby increasing their capability to repel or contain them.

The sensors utilized by EDR systems monitor and analyze activity in several key places on the network to identify intrusions or activities that could be malicious. When EDR systems detect the execution of unknown programs, unexpected or unusual changes to file systems or registries, or connections from suspicious IP addresses, they notify security teams or trigger automated defense measures. EDR systems are also vigilant for any activity that may indicate malware has been introduced to a network.

Providing ongoing training to remote employees is another important component of securing mobile devices. Human error has been shown to play a role in 74 percent of security breaches. Employees must be aware of the threat of attacks, the damage they can cause, and how they might unwittingly allow them to succeed.

Remote work, which gained ground as a temporary fix during the COVID-19 pandemic, has become a permanent strategy for many organizations. Consequently, corporate cybersecurity must evolve to address the variety of threats that mobile devices wielded by remote workers introduce. Confronting the new vulnerabilities requires strategies that blend education, extended monitoring, and enhanced endpoint protections.

Yashin Manraj, CEO of Pvotal Technologies, has served as a computational chemist in academia, an engineer working on novel challenges at the nanoscale, and a thought leader building more secure systems at the world’s reputable engineering firms. His deep technical knowledge from product development, design, business insights, and coding provides a unique nexus to identify and solve gaps in the product pipeline. The Pvotal mission is to build sophisticated enterprises with no limits that are built for rapid change, seamless communication, high-quality security, and scalability.

Published by: Martin De Juan

Voyage NY

This article features branded content from a third party. Opinions in this article do not reflect the opinions and beliefs of Voyage New York.