The COVID-19 outbreak has seen the roles of many cybersecurity professionals change — and many worry what it will mean for protecting their organizations from attacks.
A survey by the International Information System Security Certification Consortium (ISC)2 examined how the pandemic has affected the work of cybersecurity professionals and found that, because of the sudden widespread shift to telework, 47% of respondents have been reassigned to general IT support. This in spite of the fact that in this new remote work environment, the value that security managers bring to the table has become even more apparent.
Worryingly, 30% of those who have been reassigned say there has been a rise in security incidents since work-from-home policies started taking effect. They also expressed concern that management is prioritizing other parts of the business over security or that security is a “best-effort scenario.”
Cybersecurity teams are under immense pressure as they work tirelessly to keep critical operations running while ensuring their own health and wellbeing. Yet even as these workers are shifted to other roles, organizations can’t afford to lower their defenses. With resources spread increasingly thin, the risk of a cybersecurity incident slipping through the cracks is high.
To reduce this threat, let’s explore a few key measures that security leaders can implement to help them do more with less and ensure that security performance doesn’t suffer during this unprecedented time.
Gain a comprehensive picture of risk
Now, more than ever, it’s critical that security leaders find ways to optimize their security programs — before threat actors establish a foothold. This means continuously assessing the organization’s security posture and identifying areas of unknown risk, such as misconfigurations, vulnerabilities, and unpatched systems.
With tools like Bitsight for Security Performance Management, security teams can achieve unprecedented visibility into cyber risk across all digital assets — on-premise, in the cloud, across geographies, and in remote/home offices. The solution monitors the ecosystem for security posture changes and issues alerts based on preferences and the organization’s risk tolerance.
To avoid overwhelming overstretched security teams, the Bitsight platform also ranks areas that pose disproportionate risk so managers can prioritize remediation and allocate limited resources for the greatest impact and return.
Get one step ahead of remote workforce cyber risk
An important finding in the (ISC)2 survey indicates a high degree of concern among respondents, especially those workers pulled away from their normal cybersecurity duties, that expediency in setting up the connectivity for remote workers may be overriding security concerns.
They have a right to be concerned. Bitsight research found that home network IP addresses account for more than 90% of all observed malware infections and compromised systems. That means that while employees must remain home to stay safe, the shift to home networks potentially filled with malware traffic has increased cyber risk.