As the COVID-19 pandemic sees millions of employees shift to a work-from-home model, collaboration tools like Zoom and Slack have never been more critical or popular. Zoom is currently experiencing a 378% year-over-year growth in its daily active user count and was downloaded 2.13 million times in a single day as lockdowns went into effect worldwide.
However, while these work-from-home tools connect us in our isolation, they also expose users and organizations to new cybersecurity risks. Indeed, reports of security and privacy concerns associated with the Zoom app have given rise to the phenomenon of “Zoombombing.” In these scenarios, pranksters and threat actors exploit software vulnerabilities to hijack virtual meetings to obtain sensitive information, eavesdrop on conference calls, or conduct other malicious activities, warned the FBI in an April 1 public service announcement.
Zoom CEO Eric Yuan acknowledged that security problems had emerged as a result of its platform being used in new and unexpected ways — and announced several steps the company is taking to address them. But the responsibility for securing teams and data during these unprecedented times doesn’t lie solely with service providers. Corporate security teams that find themselves exposed to increased cyber risk associated with this dramatic shift to the remote office must also act now.
Proactive third-party risk management is essential
The uptick in telework is challenging security teams in many ways. Notably, it’s redefining what technologies are defined as critical. Just a few weeks ago, the term “critical” was reserved for the cloud or other major IT infrastructures; but in an age of remote work, collaboration tools are now being redefined as “critical” digital assets.
As such, security teams must ask tough questions about the security posture of the software they bring onboard — and prioritize these vendors for a closer level of scrutiny. Areas to focus on may now include the vendor’s privacy policies, how your data is handled and used, what encryption protocols are in place, in addition to vital info like their patching cadence, and how they manage their own third-party and supply chain risk.