Remote employees carrying out work tasks on their own equipment often unintentionally make it easier for cybercriminals to access the company network. Fortinet experts have observed that – in connection with the rapid shift to the remote working model – cybercriminals have changed their narrative in social engineering attacks using phishing.

How can the threat be minimised?

The scale of internal security breaches

Employees often unknowingly expose themselves to the risk of a cyberattack. Research shows that 68% of enterprises are helpless in the face of attacks originating from inside the network. These include both unintentional and deliberate actions. The former account for 38% of all security breach cases, while the latter are responsible for 21% of them. Among the other sources of cyberattacks are the use of weak passwords (16%) and browsing suspicious websites (7%). Meanwhile, a single ill-considered click on a suspicious link or downloading and opening a malicious file can contribute to the leak of confidential data.

The role of education in the remote model

Employee carelessness can have long-term consequences for a company's interests. Moreover, when faced with phishing, remote employees have limited opportunities to contact colleagues from the office and verify doubts about the content of a received email, which increases the chances of success for social engineering attacks. With this in mind, those responsible for IT security should make every effort to educate staff on cyber hygiene, thereby reducing the risk of internal security breaches.

A culture of cybersecurity in the fight against hackers

– Employees can be the first and most effective line of defence against threats. It is therefore important that training is embedded in companies' cybersecurity strategies. This allows staff to be properly prepared to face online threats – says Jolanta Malak, Fortinet director in Poland.

Cybersecurity culture in a company

Above all, employees should understand the consequences of a security breach and be aware of how it can affect the company and themselves. The importance of such a strategic approach across the entire enterprise was highlighted in the Forbes Insights 2019 survey conducted among more than 200 people in the position of CISO (Chief Information Security Officer). Asked about the security measures they planned to implement over the next five years, 16% pointed to creating a “security culture”.

This is a step in the right direction, and all processes related to cyber hygiene should take CISO actions into account. Their role is to make employees aware of the need to act thoughtfully online. This can be achieved in various ways.

1. Make the real threat tangible

Practical steps to implement

Social engineering attacks are still very effective. According to a report by Verizon, one third of confidential data theft cases occur mainly through phishing and smishing (i.e. using phishing SMS messages). Employee training should include elements such as recognising phishing messages.

2. Encourage cross-team collaboration

IT employees are not able to take care of security in a company on their own, especially as cyberthreats are becoming increasingly difficult to detect. Collaboration between the security team and other employees would be beneficial for the enterprise. While IT experts will provide professional knowledge, other departments will play a key role, for example in developing cyber hygiene rules. The results of their collaboration will help remote and on-site employees better understand the principles of cyber protection.

– As part of a team, employees can pay greater attention to behaviours that create a potential threat to the company's security. The more employees feel this responsibility, the greater the chance of avoiding threats – says Jolanta Malak.

3. Apply basic cyber hygiene rules

How can the threat of a cyberattack in a company be minimised?

Individual training sessions will bring results, but inexperienced employees will need further support in the fight against cyberattacks. Phishing is often difficult to detect, so if in doubt, the recipient of a message should ask themselves several control questions that will help identify an attempted fraud. Do I know the sender? Was I expecting it? Does this email evoke strong emotions in me, such as excitement or fear? Does it call for urgent action?

Fortinet experts also recommend hovering the cursor over a link in a suspicious message to check whether the address really leads where the recipient expects. In addition, attachments whose authenticity is uncertain should not be opened, attempted frauds should be reported to the IT department, and the sender should be contacted by another means to confirm that they sent the message. – A passive attitude towards cyberthreats can no longer be accepted in companies. Employees are often unaware that their actions or omissions can give cybercriminals direct access to critical data – summarises the Fortinet director. – Appropriate training and collaboration between company departments can create strong foundations for an internal “security culture”.

Terms from the article

Phishing — data extraction. A message or website impersonating a trusted institution in order to extract a password, card details or persuade someone to install something.

Why it matters: It is the most common start of an incident in a company. Security is not broken; instead, the employee is asked to open it.

When it is used: When implementing email security, in training, after every report of a suspicious message.

What neglecting it risks: Without DMARC and team training, a single click is enough for an attacker to get the administrator password — and then no server security will help.

Summary

The greatest threat to companies switching to remote work turns out to be people — 68% of enterprises are helpless against attacks from inside the network, and phishing remains the most common attack vector. Fortinet experts advise that instead of relying solely on technical security measures, organisations should build a “security culture” based on systematic training.

Collaboration between the IT department and the rest of the staff is also crucial — employees should know how to verify a suspicious message and whom to report it to. Interestingly, in the 2019 Forbes Insights survey, only 16% of IT security officers planned to implement measures related to creating a security culture over a five-year horizon.