The coronavirus pandemic changed the way many organisations work, with employees moving quickly from office-based working to working from home.
When you work remotely, the security controls around you can be different from those in the office. These are the main IT security points you need to consider when working from home.
Passwords are as important as ever when working remotely. Strong, individual passwords help protect your accounts and reduce the damage that can be caused if one account is compromised.
Using the same password, or very similar passwords, across several accounts increases your risk. If a criminal obtains one password, they may try the same details against other services, including email, company systems and online banking.
To improve password security:
Working remotely can increase the amount of sensitive information you need to send electronically to colleagues or clients. Encryption helps protect that information while it is being stored or transmitted.
Check whether your organisation provides an approved method for communicating and sharing information securely. Some mainstream messaging services use end-to-end encryption, but business information should still be handled in line with your organisation's policies.
Software and device updates can be inconvenient, but they are an important part of keeping your systems secure. Updates frequently contain fixes for security vulnerabilities discovered since the previous version was released.
If you are concerned about disruption, many updates can be scheduled to install outside working hours. This allows devices to remain protected without interrupting your working day.
Phishing emails, text messages and even voicemails are used by cyber criminals to obtain passwords and other sensitive information. Remote workers can be particularly attractive targets because they may be less likely to check a suspicious message with the colleague sitting next to them.
Warning signs include:
If you are unsure about a message, do not click the link. Contact the sender using a telephone number, email address or website you already know to be genuine rather than the contact details contained in the suspicious message.
A website can look convincing while still being fraudulent. Check the domain carefully and do not enter passwords or sensitive information simply because the page looks legitimate.
Data protection requirements still apply when staff move from office-based working to remote working. Sensitive information must continue to be handled, stored and shared appropriately.
Follow your organisation's privacy, data handling and storage policies when processing personal or sensitive information.
Take particular care when documents are being shared between employees, colleagues and clients. Only share information with people who are authorised to receive it and use the approved systems provided by your organisation.
The organisation should provide employees with clear policies covering how information should be accessed, stored and shared while working remotely.
Businesses should also provide suitable systems and secure methods for handling company information so staff are not forced to rely on inappropriate personal services or applications.
Extended remote working may mean using new programmes and applications for communication, collaboration or project work.
Check the security credentials of any new software before downloading it to your device. If you are unsure about an application, research the provider, check independent reviews and speak to your IT team before installing it.
If you are concerned about the security of your remote working setup, Remedian can review your devices, accounts and remote access arrangements and identify where security needs to be tightened.