The Impact Of The Pandemic On Business Cyber Security

The Covid-19 pandemic has fundamentally changed the way the world operates. In addition to placing unparalleled pressures on healthcare systems across the globe and introducing significant limitations to our daily lives. Arguably, the cyber security industry has never had a more important role to play than keeping mission-critical organisations and agencies safe from cyber-attacks during the COVID-19 pandemic.

A successful cyber-attack can cause major damage to your business. It can affect your bottom line, as well as your business' standing and consumer trust. The impact of a security breach can be broadly divided into three categories: financial, reputational and legal.

One of the key challenges financial services firms faced was the need to rapidly facilitate a shift to a near 100% remote workforce, leaving some organisations exposed to increased cyber security threats. While most large financial firms previously had implemented robust and secure remote working processes, they were not designed to support the entire workforce.

The need to rapidly move to a new working model drove some firms to quickly modify existing technology. As is often the case, such makeshift approaches may create cyber security gaps while also expanding the number of entry points for cyber criminals to exploit.

As Covid-19 spread, cyber criminals started shifting efforts from focusing on corporate entities to home-based attacks. Established strategies such as phishing and business email compromise (BEC) were successfully adapted and continue to be leveraged during the pandemic, albeit on a much larger scale.

In the US, it has also been observed that phishing and BEC attempts that historically focused on tax related matters at this time of the year, have become increasingly focused on Covid-19 as a key “lure”. The industry-wide switch to remote working also revealed new challenges related to the physical infrastructure at employees’ homes, such as secure printing and wireless networks.

The remote working environment also uncovered new insider threats, as employees started to connect to established infrastructure using devices that do not always have the requisite security parameters in place.

As a result, the industry has seen new risks emerge due to well-intentioned individual employees who, operating under significant constraints, have found new and often creative ways to address technical challenges in order to get their job done, such as using their personal devices and email accounts.

Some firms are already addressing these issues by increasing employee training around cyber security best practices related to home working environments as well as rolling out the most up-to-date protocols for their workforce. So far, the industry has adjusted remarkably well. Firms that were historically slower to augment their cyber security practices have reacted quickly to the increased cyber risks brought forth by Covid-19.

Basic cyber hygiene tools, such two-factor identification, have become much more ubiquitous, while many firms have also enabled secure remote administration of functions that were not previously available off-site. The global crisis has highlighted the impressive computing power of existing systems, which handled the global shift to working in isolation.

Given the interconnectedness of markets and the potential for a single cyber-attack to spread quickly and globally, the financial services industry is arguably more exposed than others, and the contagion effect creates further challenges when it comes to containing attacks and resuming business services.

The full impact of Covid-19 remains unknown, so firms must continue to prioritise their cyber security risk management controls while collaborating with peers across the industry on emerging threats, best practices and sector resiliency. While your employees may pose a security risk, with the right training you can reduce the risk of falling victim to cyber-crime. The important thing is to assess your business, uncover any weak points and communicate the best processes to all staff.

Staff awareness training is the single most important thing you can do to reduce the risk of employee error.

IT Goverenance:        CSHub:        CBR Online:      NI Business Info

All businesses needs cyber security training and we at Cyber Security Intelligence recommend GoCyber training for all employees and management. 

You Might Also Read: 

Some Employees Think They Can Dodge Cyber Security:

 

« Blockchain - A Simple Idea With Complications
Coronvirus Phishing Campaign Targets Six Nations »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

European Internet Forum (EIF)

European Internet Forum (EIF)

EIF’s mission is to help provide European political leadership for the political, economic and social challenges of the worldwide digital transformation.

ClearedJobs.Net

ClearedJobs.Net

ClearedJobs.Net is a career site and job fair company for professionals seeking careers in the defense, intelligence and cyber security communities.

Ixia

Ixia

Ixia provides testing, visibility, and security solutions to strengthen applications across physical and virtual networks.

TechInsurance

TechInsurance

TechInsurance is America's top technology insurance company offering a range of technology related products including Cyber Liability insurance.

Datiphy

Datiphy

Datiphy's data-centric security platform uses behavioral analytics, and data-centric auditing and protection capabilities to mitigate risk.

K&D Insurance Brokers

K&D Insurance Brokers

K&D provide insurance for all sectors of industry and commerce including cyber risk cover.

Protection Group International (PGI)

Protection Group International (PGI)

PGI helps organisations and governments to manage digital risk. From cyber security services to business intelligence, we help reduce the risks to your finances, reputation, assets and people.

Trinity Cyber

Trinity Cyber

Trinity Cyber’s patent-pending technology stops attacks before they reach internal networks,reducing risk and increasing cost to adversaries.

BetaDen

BetaDen

BetaDen provides a revolutionary platform for businesses to develop next-generation technology, such as the internet of things and industry 4.0.

MSPAlliance

MSPAlliance

MSPAlliance is the world’s largest industry association and certification body for cloud computing and managed service professionals.

Syber Technology

Syber Technology

Syber Technology is an IT project implementer empowering IT systems of Small to Medium Enterprises in the Middle East.

Etonwood

Etonwood

Etonwood specialises in infrastructure and vendor technology recruitment in areas including cloud platforms, cyber security and service management.

Opticks Security

Opticks Security

Opticks provides fraud detection and monitoring solutions for leading brands. agencies and networks. Our relentless mission is to deliver reliable and innovative software to beat digital fraud.

Network Contagion Research Institute (NCRI)

Network Contagion Research Institute (NCRI)

NCRI provides pioneering technology, research, and analysis to identify and forecast cyber-social threats targeting individuals, organizations, and communities.

Professional Labs

Professional Labs

Professional Labs specialize in simplifying complex problems for our customers with Cloud Services, Managed Services and Cyber Security.

Securitribe

Securitribe

Securitribe provides cybersecurity and compliance solutions, including vCISO services, ISO27001, and ASD Essential 8 advisory, helping businesses and government strengthen security & compliance.