The race to secure flexible working

The move to remote and hybrid working is often reliant on cloud technology. Since March last year, in response to the pandemic, many businesses have had to make rapid shifts to the cloud without the time to fully consider the security implications. When the pandemic hit, the pressure was on to get the job done as quickly as possible, and this involved lots of workarounds and compromises. They didn’t have the time to do impact assessments, sometimes even having to relax or even remove security controls to address capacity constraints brought on by the break-neck shift to remote working.

Businesses that would normally only allow access to a cloud service via a company laptop suddenly had to allow access via personal devices, because all the company hardware was stuck in the office. And businesses that only wanted employees to access the corporate network through a VPN had to allow access via the cloud because they just didn’t have enough VPN capacity.2

“What keeps me up at night is first of all what am I missing?” says David Kosorok - Dynamic Senior Director of Application and Product Security at DocuSign, a software company specialising in electronic signatures and helping organisations manage contracts and documents. “You know, am I finding the things that are most critical? And are we fixing them fast enough?”

David Kosorok − speaking in a personal capacity and not on behalf of DocuSign − adds that organisations should do more than the bare minimum of, say, annual cyber-security training for its employees. “If you just do that, there is proven evidence that that is guaranteed failure, right?” Quarterly security training is more useful, he says.

Other technology and cyber-security executives we interviewed said that they were worried about growing security threats of “ransomware” − malicious software designed to block access to a computer system until money is paid to the cyber criminal – and attacks on suppliers in their supply chain.

In 2021 alone, six ransomware groups compromised 292 organisations in different industries around the world between January 1 and April 30, and potentially reaped just over $45 million, according to the eSentire Ransomware Report. In June, JBS, the world’s largest meat processor was forced to temporarily close its US meatpacking plants after it fell victim to a ransomware attack.

“The one thing that keeps me up at night is a complete wipeout scenario, the ultimate cyber crisis scenario is some sort of ransomware that takes everything down,” says Jon Winbow - Director of Information Security at GlaxoSmithKline, one of the world’s biggest pharmaceutical companies. “And we have to recover from a point where we have to bring everything back. And we’ve never been in that situation before.”

Ophir Zilbiger, Global Head of Cyber Security Advisory, at accounting firm BDO, is also concerned about the growing threat from ransomware. It underscores the importance of an organisation having a resilient information security infrastructure, he says.

“In the last 15 years, cyber security protection has been king. Organisations have invested in checking firewalls and anti-virus software, in addition to different kinds of sophisticated mechanisms to prevent this or that. They’ve invested less on detection and response, and on resilience. They feel protected, because they bought security, or they invested in security. In reality, their organisations have some big gaps in their armour, such as protection from ransomware.”

Some industries have become more lucrative targets for hackers during the pandemic. In the past year to eighteen months, the likelihood of a cyber-attack on the pharmaceutical industry has increased, especially on suppliers in pharma companies’ supply chain, Jon Winbow adds. “One of our third-party suppliers was hacked about six months ago, and then we had to scramble around. Okay, what does that mean to us? What have they got? What do they do for us? Are we impacted? It’s a huge issue and a massive concern for us.”

Our conversations with business leaders about cyber security and new post-pandemic working patterns highlighted three key challenges.

Ophir Zilbiger,

Global Head of Cyber

Security Advisory | BDO

In the last 15 years, cyber security protection has been king. Organisations have invested in checking firewalls and anti-virus software, in addition to different kinds of sophisticated mechanisms to prevent this or that. They’ve invested less on detection and response, and on resilience. They feel protected, because they bought security, or they invested in security. In reality, their organisations have some big gaps in their armour, such as protection from ransomware.

Next: The race to secure flexible working

Challenge 1: Secure your business from network to cloud

Keep reading →

Share this page