Remote work due to coronavirus? Here are 3 tips on how to do it safely
One of the unexpected consequences of the coronavirus outbreak is the sudden shift of many employees to home office mode (working from home). However, such changes, especially implemented in haste, can generate serious risks to company security. What should you do to avoid bringing trouble upon your organization? Practical guidance is provided by Justyna Puchała from the Authorized Training Center DAGMA, which trains employees in IT security on a daily basis.
1. Remember that you are at work
Remember that you are at work
For many people, especially those without prior experience with home office, working from home feels more like “home” than “work.” Because of this attitude and the lack of supervision, they allow themselves to ignore some procedures, including those related to security. This is one of the biggest mistakes made by remote workers, and one you should avoid.
- The basic security rules don't suddenly stop applying just because we're working while sitting on the couch with a cat on our lap, rather than in an office with the boss in the next room. That's the first thing to remember when switching to home office. If we can't do something at work, e.g. visit certain websites or open attachments from unknown senders, then we shouldn't do it when working from home either – explains Justyna Puchała from the Authorized Training Center DAGMA.
2. Don't trust anyone
Don't trust anyone
When working remotely, you may not meet as many people as in the office, but when you do encounter someone, they will mostly be people from outside your company: your wife, roommate, courier with a package, etc. Remember that they should not have access to company data, let alone company equipment. Sometimes even ordinary carelessness on the part of those close to us can lead to a dangerous leak that puts the entire organization at risk.
- It's worth having a designated workspace that unauthorized persons won't have access to. If we're not at our workstation, all documents should be put away, preferably in a lockable drawer, and the computer locked and encrypted - advises Justyna Puchała.
3. Avoid public networks
Avoid public networks
By design, corporate networks are secure – an entire team of people works on that. Public networks don't guarantee such security; anyone can connect to them, and they either aren't password-protected or the password is easily available. Criminals readily use them to carry out so-called man-in-the-middle attacks, which involve intercepting data transmitted by other network users and stealing sensitive information that way, e.g. login credentials for company email.
- When working remotely, it's best to connect to the Internet only from your home network, making sure beforehand that it's properly configured and protected with a strong password. If we additionally use a VPN tunnel to connect to the company, the risk of falling victim to criminals is relatively low. However, if we absolutely must work in a public place, the best solution is to use the Wi-Fi router function on a smartphone and create your own password-protected network – explains Justyna Puchała.
Following the above rules should significantly raise the level of remote work security, but by no means does it exhaust the subject entirely.
Summary
The sudden switch to remote work during the coronavirus epidemic requires extra caution. Expert Justyna Puchała from the Authorized Training Center DAGMA reminds us that the security rules in force at the office don't lose their validity in the comfort of home. It's crucial to designate a workspace, protect company data from unauthorized persons, and avoid public Wi-Fi networks, which are vulnerable to man-in-the-middle attacks. Instead, she recommends using a secured home network or a VPN tunnel. Following these three tips significantly raises the level of security, but – as the expert notes – it doesn't exhaust the entire subject.