Working from home presents unique security challenges. If you’re working from home you can improve the security of sensitive data and protect yourself against cyber security threats by following these work from home security tips for employees.
- Cybersecurity Risks of Remote Workers (& How To Mitigate Them) single sign-on tool
- How to Monitor Employees Working From Home
- Terrifying Cybersecurity Statistics You Need to Know
Authentication Security Tips
1) Never reuse passwords
Two thirds of people in the LastPass Psychology of Passwords Report admitted to reusing passwords. Whether you are working from home or in the office you must make sure the passwords you use are unique to you and not easy to guess.
Reusing passwords increases the potential damage that a data breach could cause. If an attacker manages to gain unauthorized access to your password on one account they would then have access to all of your accounts that use the same credentials.
2) Create strong passwords
All of the passwords you use should be unique for each account and difficult for a potential attacker to guess. You should also never share your passwords with anyone.
- Use Passphrases. A strong password doesn’t have to be hard for you to remember. Simply memorize a series of unrelated words and combine them together into a passphrase.
- Easy to remember, hard to guess. If you have an easy to remember password you will not have to write it down, reducing the opportunity that someone will find your written password. Ideally the password you make should not contain any personal details about you such as birthdays or the names of children/pets.
3) Use a single sign-on tool
Single sign-on (SSO) is a valuable tool for businesses that manage multiple users. These tools allow end-users to log in to all of their corporate applications with a single set of credentials. This is far more convenient for the end-users and reduces the cyber security risks of password insecurity.
There are a variety of SSO tools available, so you need to evaluate your options to choose the right SSO provider or SSO tool for your needs.
Choosing the right Single Sign-On (SSO) solution is crucial for simplifying access management and bolstering security. Here are some key factors to consider when evaluating potential providers:
- Supported identity protocols: Ensure the provider supports protocols like SAML, OpenID Connect, and OAuth 2.0, aligning with your current and future needs.
- Deployment options: Evaluate on-premises, cloud-based, or hybrid solutions based on your infrastructure and preferences.
- Scalability and performance: Consider the provider’s ability to handle your user base and projected growth without performance degradation.
- Integrations: Ensure the SSO integrates seamlessly with your existing directory services, applications, and security tools.
- API availability: Assess the provider’s API capabilities for custom integrations and automation.
Security and compliance:
- Authentication methods: Evaluate the available methods (2FA, MFA, passwordless) and their compliance with your security standards.
- Data encryption: Verify the provider uses strong encryption standards for data at rest and in transit.
- Access control: Ensure the provider offers granular access control mechanisms to manage user permissions effectively.
- Compliance certifications: Check if the provider adheres to relevant industry standards and regulations (e.g., HIPAA, PCI DSS, GDPR).
- Security audits and penetration testing: Inquire about the provider’s security practices and their commitment to regular audits and penetration testing.
Usability and administration:
- User interface: Evaluate the user interface for ease of use and intuitiveness for both end-users and administrators.
- Reporting and analytics: Assess the provider’s reporting and analytics tools to track user activity, identify potential security issues, and monitor system performance.
- Self-service capabilities: Consider features like password resets and user profile management, allowing users to manage their accounts independently.
- Technical support: Evaluate the provider’s support options, including response times, service level agreements (SLAs), and available support channels.
Cost and licensing:
- Pricing model: Understand the provider’s pricing structure (per user, per feature, etc.) and how it aligns with your budget and needs.
- Licensing options: Evaluate different licensing models (e.g., perpetual, subscription) and their impact on long-term costs.
- Hidden fees: Be aware of any additional fees or charges that may not be readily apparent in the base pricing.
- Vendor reputation and track record: Research the provider’s reputation, experience, and customer reviews.
- Future roadmap: Understand the provider’s future development plans and commitment to innovation.
- Free trial or proof of concept: Consider requesting a free trial or proof of concept to evaluate the SSO solution firsthand.
By carefully considering these factors, you can make an informed decision and choose an SSO provider that meets your specific security, usability, and budgetary needs.
4) Lock your workstation when you are not using it
When you’re working in the comfort of your own home it’s easy to let your guard down. This is especially true if you live with trusted loved ones.
To prevent accidental data loss or leakage you should still maintain the habit of locking your computer when you are not using it. All it takes is a moment of carelessness for a trusted family member to accidentally cause damage or see sensitive information they are not privy to.
The fastest way to lock your computer
- Windows: Press the Windows Key and L.
- New Macs: Press Control-Shift-Power
- Old Macs: Press Control-Shift-Eject
5) Avoid sharing your accounts with coworkers
You should have your own unique company accounts that are exclusive to you. This reduces opportunities for passwords to be leaked and makes it easier to investigate security incidents. Sharing passwords is also a liability issue as insider threats can use social engineering to gain unauthorized access to company resources they should not have access to.
6) Beware of eavesdropping and shoulder surfing
Working remotely comes with its fair share of freedoms. The ability to work from anywhere is a great perk but it’s also a significant security risk. If you decide to leave home to work in a public space you should be mindful of who has a line-of-sight towards your laptop. You should also refrain from openly discussing sensitive company topics when working in public.
Phishing Awareness Tips
Phishing is a pervasive security issue. No matter where you work you will need to be vigilant about phishing, spear phishing, and social engineering. While system administrators do their best to filter out spam and phishing emails the end-user also needs to know how to spot a phishing attempt so they can report it and avoid falling victim to the attack.
Threat actors have been taking advantage of the uncertainty and stress surrounding COVID-19 to trick employees into divulging sensitive information and sending company funds to fraudsters. In fact, it has been reported that a staggering 9 out of 10 coronavirus-related domains are scams. They’ve also impersonated being representatives of the World Health Organization and Greta Thunberg to convince their victims to visit malicious links and download malware disguised as legitimate files.
7) Be wary of links and attachments in emails
Phishers will do everything they can to impersonate legitimate people and organizations. You should never open an attachment unless you are completely confident that the message is from a legitimate party. Even if everything in an email appears legitimate you should do everything you can to avoid clicking links and opening attachments wherever possible.
If you must click a link, first hover over the link and check the bottom-left corner of your browser to see where the link is actually trying to send you. Read the domain carefully to make sure that it’s not a misspelled domain trying to impersonate the legitimate website.
As a further precaution you can use a URL inspector tool such as VirusTotal to analyze suspicious files and URLs to detect malware
8) Do not send sensitive information over email or text
Email, team chat, and text are all convenient for day-to-day communication but they may not be suitably secure for sensitive data such as personally identifiable information (PII). These communication platforms typically store copies of their messages on both the senders and recipients computers, leaving the sensitive data vulnerable to exposure if those messages are later leaked. A better alternative for sending sensitive data are encrypted file sharing tools that are a part of the organization’s official tech stack.
9) Verify that the sender is legitimate
Phishers will try to make their requests appear more legitimate by spoofing the email addresses of trusted senders. Watch for typos, the use of zeros in place of Os, added punctuation that’s not supposed to be there, and email addresses that use the correct username with the wrong domain. Some phishers may even simply set their display name to be the trusted sender they’re trying to spoof while using a generic email address.
Example: If the trusted sender is JohnDoe@CompanyTech.com, a Phisher could use JohnDoe@CompanyTtech.com to pretend to be them.
Note: Even if an email appears to be coming from a legitimate email address, attackers can still spoof an email address or compromise an account. Not every email received from (what appears to be) a trusted sender is guaranteed to be safe.
10) If a request sent to you by email sounds suspicious, call the sender directly to verify its legitimacy
This tip may sound like overkill, but it’s far better to be overly cautious than to leak sensitive information or send company funds to a fraudulent account. Taking a brief moment to verify the legitimacy of a suspicious email can very well make a significant difference if it prevents you from falling for a phishing attempt.
What is considered suspicious will depend on the context of your organization. Your workplace should have policies and procedures in place that dictate how requests are to be made, how data is to be transferred, and how processes should be undertaken. An email that asks you to do anything that falls outside of that framework should be treated with high suspicion.
Here are some general warning signs you should look out for.
- The message attempts to create a sense of urgency
- The email is poorly written
- The message is sent from an unknown email address
- It includes suspicious attachments or links
Internet Security Tips
11) Beware of public Wi-Fi
If you’re working while on the road you may be tempted to use one of many publicly available Wi-Fi hotspots. These connections may be fine for low-risk personal browsing but there are dangers you should be aware of.
- Honeypots. Attackers could make a “honeypot” where they spoof an existing hotspot. Once you connect to their hotspot they can perform a man-in-the-middle (MITM) attack to intercept your connection with a fake domain that looks like the one you were trying to visit. Once you login to the fake domain they now have your login credentials.
- Traffic Sniffing. Other users of the hotspot could potentially see your traffic on unencrypted websites if the provider of the public Wi-Fi does not have adequate security controls in place.
Ideally you will have access to your own private mobile hotspot that you can use to connect to the internet while working remotely. If this is not the case, using a VPN can reduce, but not eliminate, the security risks of public Wi-Fi.
12) Use an internet connection that is separate from internet-of-things (IoT) devices
Your home network is likely nowhere secure as the purpose-built networks provided by your employer. If your home network includes consumer-grade IoT devices such as Smart TVs, fridges, or security cameras, you should place these devices on a separate network. Refer to your ISP’s directions for making a guest network via your router.
The reason for this tip is that IoT devices are not equally secure. If an unsecured IoT device is compromised by an attacker they can use that device as an entry point to the rest of your network; this is precisely why endpoint security is so critical for protecting your network as a whole.
13) Do not use your home router’s default credentials
A shocking amount of routers do not force their users to reset the default admin credentials on setup. Attackers can use a list of manufacturers, devices, and known default credentials to brute force their way into your network. Changing the default credentials to a secure password helps prevent this attack.
Data Loss Prevention Tips
14) Keep sensitive data within pre-approved channels
If you are given access to sensitive data as part of your role you need to do everything you can to keep it safe. All sensitive data should be kept within pre-approved channels where it can be adequately monitored and managed. You should never save sensitive data to your desktop or unauthorized cloud storage accounts. You should also avoid sending this data over email, team chat, or personal devices.
15) Avoid mixing personal and corporate devices
Some workplaces let their employees use their personal devices for work. This practice is known as “Bring Your Own Device” or “BYOD”. This poses unique security risks as personal device usage is inherently more risky than work-only usage. There are also limitations to monitoring the personal devices of remote workers, which leaves a significant visibility gap.
If your workplace is BYOD-friendly you should refrain from storing sensitive data on your personal devices. You should also avoid accessing that data without a corporate-secured device unless absolutely necessary.
16) Be mindful of the physical security risks of working remotely
The portability of laptops makes them incredibly easy to steal. Whenever you work in a public location you should always have the laptop within arms reach and carry it with you. If you will be traveling you should keep your devices in your carry-on rather than storing it in your checked baggage.
This tip also applies to data storage devices such as USB flash drives and external hard drives. These devices are easy to lose or have stolen and it’s often difficult to know for certain what potentially sensitive information was on that device before it went missing.
17) Do not use unauthorized USB devices
Do not plug in USB devices that are not pre-approved by your IT department. Rogue USB devices may actually be a cleverly disguised data theft device. Even your own personal USB devices may be insufficiently secure, especially if you do not have encryption enabled.
If you are not required to use USB devices for your role you can disable data transfers through USB ports using data loss prevention software.
- Set data security standards for portable storage
- Define the acceptable use of removable media
- Inform your users about their security responsibilities
Get started today—Download the FREE template and customize it to fit the needs of your organization.
18) Only used company-approved software and hardware
It can be tempting to use software, processes, and hardware that you’re already familiar with. Even if you have a tool that will improve your productivity you should refrain from using it without the knowledge and approval of your IT department. This “shadow IT” is not being adequately monitored and managed for potential security threats and could be potentially exploited by attackers.
19) Make sure everyone is aware of their cyber security responsibilities
Cyber security is not solely managed by IT personnel, it is everyone’s responsibility. Organizations must implement cyber security training for their staff to make sure that they are aware of the risks and responsibilities that correspond with their role.
If you’re working from home you need to do everything you can to reduce your cyber security risks. These work from home security tips will help you to protect sensitive data from the most common cybersecurity threats of a remote workforce.