
October 1, 2019 • Garrett Garitano
In cybersecurity, there’s no such thing as “done.” You need to be on the lookout for new threats and opportunities. In the past, you tightened physical security and created a password policy. Now, you need to tackle the challenge of remote employee security. The Remote Employee Security Challenge Is Growing Years ago, you could prevent […]
In cybersecurity, there’s no such thing as “done.” You need to be on the lookout for new threats and opportunities. In the past, you tightened physical security and created a password policy. Now, you need to tackle the challenge of remote employee security.
The Remote Employee Security Challenge Is Growing
Years ago, you could prevent remote employee security risk by forbidding remote work. That option is no longer on the table for most organizations today. Many employees, especially in highly competitive talent markets, demand remote work from employers. Failing to offer this option to new hires will make you less competitive. It’ll also undermine employee morale. According to CNBC, 70% of the global workforce work remotely at least one day per week.
If remote employee work is a reality, you need to look for ways to make it possible. Your human resources department probably has ideas to help managers and employees make remote work productive. However, that still leaves the question of security. Let’s address closing the security gap for remote work so that your workforce can thrive.
Defining the Remote Employee Security Challenge
Before we can solve this security problem, we need to understand it. With a traditional employee working at your office, it’s relatively easy to reduce risk. You can require ID badges so that intruders will find it more difficult to gain access. You can issue each employee a corporate computer. You can route all network traffic through your hardware. If you notice an employee engaged in unsafe practices such as downloading an unknown application, you can provide guidance. In contrast, a remote employee doesn’t have the same protections and security opportunities.
Your employees may work from home, which should be relatively safe. However, they might work at a hotel, conference center, or on a plane. In these environments, security may not be a priority, which creates added risk. For example, in these environments, you face increased risk of “shoulder surfing,” meaning an intruder watching your employee enter passwords. In a conference location, an employee might leave his or her PC open on a table when visiting the restroom. How do you enable secure remote working without losing all your employees?
The Three Solutions to Eliminate Remote Employee Security Risk
To support your remote employees and keep your organization safe, we recommend using three interlocking systems.
1. Enhance Technology for Secure Remote Working
Using FIDO2, your employees can authenticate themselves using their phones and a password. With this two-factor authentication process in place, simply observing an employee enter a password in a public place isn’t enough to gain access to your systems. You can bring this security enhancement to your organization with Password Management.
Beyond using FIDO2, there are other ways to enhance security for remote employees. For instance, let’s say a senior executive is traveling and wants to access his or her corporate account. If that access fell into the wrong hands, you could be exposed to considerable risk. To reduce the likelihood of a problem, we recommend adding biometric authentication. Here’s the good news: you don’t have to issue fingerprint readers to your entire staff! Low-impact alternatives such as facial recognition and voice recognition are available.
2. Enhance Oversight Processes for Remote Working
Without oversight processes, it’s nearly impossible to tell if your security technology is being used effectively. Here are some of the methods we recommend to improve remote employee security quickly.
3. Provide Proper People Training
Providing training and coaching to your people is an essential way to improve remote employee security.