Would you leave your front door open while you work in a room? No, they could rob him, right? But surely, you would connect to a public WiFi to send a corporate file. Both actions are risky, and even telecommuting without good cybersecurity practices could leave your company’s door wide open.
Cyberattacks are among the ten most serious threats on the planet, according to the World Economic Forum’s 2020 Risk Report . And even, cybercrime generates annual profits of 600,000 million dollars and is more profitable than drug trafficking, which moves about 400,000 million dollars a year.
These realities give great value to information as a profitable asset that must be protected, aligned with the sustainable strategy and understood as part of the corporate culture.
This is how cyberattacks affect organizations
- 40% interrupt operations.
- 39% cause loss or compromise sensitive data.
- 32% affect the quality of the product.
- 29% damage physical assets.
- 22% harm the staff.
SOURCE: Global State of Information Security 2018
“It doesn’t matter how much technology and controls you have if your human team doesn’t make good use of them,” says Lida María Montoya, IT manager at Cadena SA, a company that started remote work a week before the quarantine was decreed, with a strategy gradual for 200 employees, and that today it has 420 people who work from home.
“The crash plan required us to ensure, in record time, that all the computers had antivirus updates, VPN installations and were inventoried, at the time the company left,” explains Juan Carlos Lujan Duque, Director of Information Security in Chain SA
For their part, spokespersons for Bancolombia, which has 19,500 employees working from home, highlight that the remote work plan included a “donation” or obtaining thousands of laptops among all areas in order to send the largest number of employees to telework possible, which required setting up the security equipment to facilitate the remote monitoring of data in real time, as was done at the bank’s facilities.
Among others, untimely teleworking required companies to have signed, as part of labor contracts, commitments to good use and compliance with safety recommendations and manuals, to have technological control and monitoring attachments, and mobility supports.
The support of the internal communication and human management units has also been key to sensitizing the human team about cybersecurity situations that may arise and the possibilities of dealing with them, how to use the devices correctly and have safe behaviors.
But beyond that, understanding how cybercriminals think and act makes it possible to implement and socialize good data protection practices in terms of being thoughtful when receiving, opening, and sharing information.
Internet criminal tricks
- They build trust, create attractive relationships or contacts to access information.
- They take advantage of emotional ties to a loved one who needs help.
- They exploit fear, anguish and uncertainty at the possibility of losing access to valuable information.
- They blackmail the victims.
Corporate teleculture changed offices and business corridors for telephone chats , extranets , video calls, and virtual channels that keep people together and almost inside the office. Today, standing aside is not possible, but it is possible to share the screen, see each other talk and make decisions.
This is how a person protects himself on the internet
- Make regular backup copies on external or corporate media.
- Close work sessions and apps when you’re not using them.
- Use double or triple factor authentication to make financial transactions.
- Work in spaces where there is no risk of losing information due to equipment damage, this includes moving away from food.
- Avoid sending files with corporate information through unofficial means such as WhatsApp, Dropbox, Wetransfer or free domain emails, among others.
- Do not connect to unknown networks or USB ports.
- Do not install applications that do not come from reliable sources, from official stores or that require permissions to access confidential information (agenda, geolocation, contacts, etc.).
- Keep the operating system of the equipment up to date.
- Do not lend your company devices to your family.
This is how companies protect themselves on the network
- Activate multifactor authentication in email accounts and tools (access to systems after two or more proofs of identity).
- Before enabling services on the Internet, evaluate that contingency actions do not affect data security.
- Update the operating system on all devices with the latest security patches released by the manufacturer.
- Install and keep antivirus software from a reputable manufacturer up to date.
- Deploy storage solutions like corporate Onedrive and Google Drive to store collaborator files.
- Permanently monitor the infrastructure of the services used by employees who work from home in order to analyze possible unauthorized actions. Generate backup policies to avoid information loss.
- Implement encryption policies on computers, servers, and transactional tools to protect information.
- Use comprehensive and centralized protection tools for devices.
- In the event of device loss, configure security measures to protect corporate information (location, screen lock, remote data wipe, and monitoring of running applications).