Is security one of your top priorities for a hybrid working environment? Chances are, up to this point, you’ve been focused on the logistics of creating a hybrid model; what guidance do you give people, how can you ensure everyone feels connection. But information security needs to be a major consideration.
Many office staff will have worked completely remotely for 18 months. In many ways this has made security relatively simple – if everyone is working from home, or indeed if everyone is in the office, the threats you face are more predictable and more straight forward to mitigate against. But it looks increasingly likely that for most of us, the future is hybrid – with a mix of some home working and some office working. The more contagious delta variant and surging COVID-19 cases might be complicating the issue but now is still a good time to remind staff that security is everyone’s responsibility and not just an IT problem or a problem for the security team. Here are my top tips on where to start…
Physical security
There is a whole raft of physical information security issues quite apart from the myriad issues with electronic devices. First and foremost is the need to remind staff of the need to collectively protect their working space. At home they didn’t have to worry as much about shared working areas or physical security – they would be answering the door themselves and not letting strangers into their home. Back in the office, they need to remember not to hold doors open for unauthorised staff and not allow tailgating. Switching from the home to office environment on an almost daily basis will make it even more important to remind them of the importance of good physical security.
There is a chance that new staff may have joined the organisation and never visited the office, but this is not a reason to stop challenging people you do not know. In fact, it may be a good excuse to get to know your new colleagues better. Also remind staff about not working on (or speaking about) sensitive assignments on public transport. The business environment has never been more competitive and the drive to get a march on competitors may result in more direct means of trying to obtain information about that next deal, pricing or mergers and acquisitions.
In the office you may have had a clear desk policy – not something that you can check on in somebody’s home. But what about all the documents that staff felt they had to print out on their home printer?
Secure destruction
Now is the time to remind staff to shred sensitive documents once they have finished with them whether at home or at the office. If there has there been a build-up of sensitive documents to shred at home, arrange for these to be brought safely into the office. Staff should not use domestic straight shredders for sensitive documents – straight shredded paper can be reconstructed (it might take several hours, but I have seen it done). Either use the services of a reputable shredding company (some will shred documents in their vehicle outside your office) or use a cross shredder.
Office equipment
Things may have changed since you were last in the office, but you should be wary of any physical changes and if you see any new equipment, find out where it has come from and why. If you still have fixed desktop computers, check the back to see if there is anything out of the ordinary – key logging devices (that can capture passwords etc.) are easy to attach.
Find out from your IT provider/IT team to see if there are any changes to the WiFi network and adjust user logon and password details as appropriate.
Re-enforce the importance of the security of laptop and tablet devices and remind users to lock their screen when away from their device and lock away laptops when not being used. These good habits are not ones that will have been necessary in most home environments but are essential to reduce the risk of insider threats and the threats from external parties. With all the changes of location going on, it is also a good time to remind staff not to write down passwords.
Finally, check any inhouse servers within your communications rooms (if you haven’t moved completely to the cloud) for log files and CCTV to see if there is any unusual activity.
With many offices being unoccupied for the past 18 months, there may have been opportunities for adversaries to place listening devices ready for the resumption of sensitive face to face conversations.
Personal devices
In the rush to ensure all staff were able to carry on working remotely, some employers allowed staff to use personal devices for work. Unfortunately, these staff were much more likely to take risks with company data, like connecting to unsecured networks or sharing confidential files via email. Understandably, many firms adapted security policies or were less stringent in enforcing them with remote working. Now is the time to take back some control and examine company security measures to ensure they are not too complex or hindering productivity. Look to roll out business devices where personal devices have been used.
Returning laptops to corporate networks after they have been attached to unprotected home WiFi for so long is a risk. Malware (malicious unapproved software) could have been downloaded onto laptops and be currently dormant but be brought back to life once attached to the corporate network.
To check this is not the case, your IT team or provider should:
Step 1 – Carry out an audit of what staff want to bring back into the office
Step 2 – Quarantine devices
Step 3 – Check to see all (personal and corporate) devices are patched up to date
Step 4 – Review and re-write your BYOD (Bring Your Own Device) policies
Step 5 – Review and consider the use of encryption on mobile devices
Step 6 – Review/audit your security controls. Those with corporate devices may have had security controls altered during the pandemic to accommodate home working – e.g. having Bluetooth or USB enabled. These could present a risk if left unchecked as staff gradually return to the office.
With a return to commuting and people not being used to having their work overlooked, privacy screens for use on public transport will help mitigate the risk.