Working from home presents unique security challenges. If you’re working from home you can improve the security of sensitive data and protect yourself against cyber security threats by following these work from home security tips for employees.
Two thirds of people in the LastPass Psychology of Passwords Report admitted to reusing passwords. Whether you are working from home or in the office you must make sure the passwords you use are unique to you and not easy to guess.
Reusing passwords increases the potential damage that a data breach could cause. If an attacker manages to gain unauthorized access to your password on one account they would then have access to all of your accounts that use the same credentials.
All of the passwords you use should be unique for each account and difficult for a potential attacker to guess. You should also never share your passwords with anyone.
Single sign-on (SSO) is a valuable tool for businesses that manage multiple users. These tools allow end-users to log in to all of their corporate applications with a single set of credentials. This is far more convenient for the end-users and reduces the cyber security risks of password insecurity.
When you’re working in the comfort of your own home it’s easy to let your guard down. This is especially true if you live with trusted loved ones.
To prevent accidental data loss or leakage you should still maintain the habit of locking your computer when you are not using it. All it takes is a moment of carelessness for a trusted family member to accidentally cause damage or see sensitive information they are not privy to.
The fastest way to lock your computer
You should have your own unique company accounts that are exclusive to you. This reduces opportunities for passwords to be leaked and makes it easier to investigate security incidents. Sharing passwords is also a liability issue as insider threats can use social engineering to gain unauthorized access to company resources they should not have access to.
Working remotely comes with its fair share of freedoms. The ability to work from anywhere is a great perk but it’s also a significant security risk. If you decide to leave home to work in a public space you should be mindful of who has a line-of-sight towards your laptop. You should also refrain from openly discussing sensitive company topics when working in public.
Phishing is a pervasive security issue. No matter where you work you will need to be vigilant about phishing, spear phishing, and social engineering. While system administrators do their best to filter out spam and phishing emails the end-user also needs to know how to spot a phishing attempt so they can report it and avoid falling victim to the attack.
Threat actors have been taking advantage of the uncertainty and stress surrounding COVID-19 to trick employees into divulging sensitive information and sending company funds to fraudsters. In fact, it has been reported that a staggering 9 out of 10 coronavirus-related domains are scams. They’ve also impersonated being representatives of the World Health Organization and Greta Thunberg to convince their victims to visit malicious links and download malware disguised as legitimate files.
Phishers will do everything they can to impersonate legitimate people and organizations. You should never open an attachment unless you are completely confident that the message is from a legitimate party. Even if everything in an email appears legitimate you should do everything you can to avoid clicking links and opening attachments wherever possible.
If you must click a link, first hover over the link and check the bottom-left corner of your browser to see where the link is actually trying to send you. Read the domain carefully to make sure that it’s not a misspelled domain trying to impersonate the legitimate website.
Email, team chat, and text are all convenient for day-to-day communication but they may not be suitably secure for sensitive data such as personally identifiable information (PII). These communication platforms typically store copies of their messages on both the senders and recipients computers, leaving the sensitive data vulnerable to exposure if those messages are later leaked. A better alternative for sending sensitive data are encrypted file sharing tools that are a part of the organization’s official tech stack.
Phishers will try to make their requests appear more legitimate by spoofing the email addresses of trusted senders. Watch for typos, the use of zeros in place of Os, added punctuation that’s not supposed to be there, and email addresses that use the correct username with the wrong domain. Some phishers may even simply set their display name to be the trusted sender they’re trying to spoof while using a generic email address.
Example: If the trusted sender is JohnDoe@CompanyTech.com a Phisher could use JohnDoe@CompanyTtech.com to pretend to be them.
This tip may sound like overkill, but it’s far better to be overly cautious than to leak sensitive information or send company funds to a fraudulent account. Taking a brief moment to verify the legitimacy of a suspicious email can very well make a significant difference if it prevents you from falling for a phishing attempt.
What is considered suspicious will depend on the context of your organization. Your workplace should have policies and procedures in place that dictate how requests are to be made, how data is to be transferred, and how processes should be undertaken. An email that asks you to do anything that falls outside of that framework should be treated with high suspicion.
Here are some general warning signs you should look out for.
If you’re working while on the road you may be tempted to use one of many publicly available Wi-Fi hotspots. These connections may be fine for low-risk personal browsing but there are dangers you should be aware of.
Ideally you will have access to your own private mobile hotspot that you can use to connect to the internet while working remotely. If this is not the case, using a VPN can reduce, but not eliminate, the security risks of public Wi-Fi.
Your home network is likely nowhere secure as the purpose-built networks provided by your employer. If your home network includes IoT devices such as Smart TVs, fridges, or security cameras, you should place these devices on a separate network. Refer to your ISP’s directions for making a guest network via your router.
The reason for this tip is that IoT devices are not equally secure. If an unsecured IoT device is compromised by an attacker they can use that device as an entrypoint to the rest of your network.
A shocking amount of routers do not force their users to reset the default admin credentials on setup. Attackers can use a list of manufacturers, devices, and known default credentials to brute force their way into your network. Changing the default credentials to a secure password helps prevent this attack.
If you are given access to sensitive data as part of your role you need to do everything you can to keep it safe. All sensitive data should be kept within pre-approved channels where it can be adequately monitored and managed. You should never save sensitive data to your desktop or unauthorized cloud storage accounts. You should also avoid sending this data over email, team chat, or personal devices.
Some workplaces let their employees use their personal devices for work. This practice is known as “Bring Your Own Device” or “BYOD”. This poses unique security risks as personal device usage is inherently more risky than work-only usage. There are also limitations to monitoring the personal devices of remote workers, which leaves a significant visibility gap.
If your workplace is BYOD-friendly you should refrain from storing sensitive data on your personal devices. You should also avoid accessing that data without a corporate-secured device unless absolutely necessary.
The portability of laptops makes them incredibly easy to steal. Whenever you work in a public location you should always have the laptop within arms reach and carry it with you. If you will be traveling you should keep your devices in your carry-on rather than storing it in your checked baggage.
This tip also applies to data storage devices such as USB flash drives and external hard drives. These devices are easy to lose or have stolen and it’s often difficult to know for certain what potentially sensitive information was on that device before it went missing.
Do not plug in USB devices that are not pre-approved by your IT department. Rogue USB devices may actually be a cleverly disguised data theft device. Even your own personal USB devices may be insufficiently secure, especially if you do not have encryption enabled.
If you are not required to use USB devices for your role you can disable data transfers through USB ports using data loss prevention software.
It can be tempting to use software, processes, and hardware that you’re already familiar with. Even if you have a tool that will improve your productivity you should refrain from using it without the knowledge and approval of your IT department. This “shadow IT” is not being adequately monitored and managed for potential security threats and could be potentially exploited by attackers.
Cyber security is not solely managed by IT personnel, it is everyone’s responsibility. Organizations must implement cyber security training for their staff to make sure that they are aware of the risks and responsibilities that correspond with their role.
If you’re working from home you need to do everything you can to reduce your cyber security risks. These work from home security tips will help you to protect sensitive data from the most common cybersecurity threats of a remote workforce.