Subscribe
  • Home
  • /
  • TechForum
  • /
  • Navigating a hybrid work environment – how can businesses remain secure?

Navigating a hybrid work environment – how can businesses remain secure?

By Quentyn Taylor, Director of Information Security at Canon for Europe, Middle East and Africa

Johannesburg, 18 Nov 2021
Quentyn Taylor, Director of Information Security at Canon for Europe, Middle East and Africa.
Quentyn Taylor, Director of Information Security at Canon for Europe, Middle East and Africa.

A central office has typically been most businesses default working location, but the role of the office has significantly changed over the last year. Today, over 90% of organisations say they’ll allow employees to work remotely, at least part of the time, going forward. Changes that were brought about in haste to deal with the pandemic are crystallising into permanent fixtures. The expectation is that employees will have the freedom to move between multiple working environments and connect to a company’s network from each one.

But this shift to a hybrid working model poses potential security risks for your organisation and employees. Your business’s network perimeter has evolved to not only encompass a core office location, but each employee’s home too. As such, it’s not surprising that companies have reported feeling less confident in the resilience of their security measures, according to NCC Group insight.

With hybrid working here to stay, security professionals need to work quickly to secure a flexible work environment that your business can trust. To do so, they must take a holistic approach. This means ensuring the business’s security infrastructure is watertight, while at the same time investing in education and training for employees. Only then can you comfortably facilitate collaboration across a distributed workforce, or expect to build resilience against the modern threat landscape.

The modern threat landscape

Organisations need to address the changes we’re seeing to the modern threat landscape amid a shift to hybrid working and assess how they impact our new working reality.

  1. First of all, employees now communicate and collaborate with each other beyond the periphery of the usual security firewalls, sharing corporate data throughout the working day.
  2. Secondly, employees are likely to be accessing company servers over public networks, which offers attackers more opportunities to break through. According to NCC Group, 66% of organisations that increased their use of remote working during 2020 saw an increase in phishing and malware attacks. Notably, 39% of all those surveyed reported that accidental, malicious or inadvertent insider threats had increased in the second half of the year.
  3. Finally, we are seeing an increase in the use of personal IOT devices, such as printers and phones, that are configured with default security settings used for work alongside company devices, such as laptops. Mobile working and remote system access through trends such as bring your own device (BYOD) offer great benefits to the productivity of both staff and employers; however, they open up new potential threat vectors and present new challenges in relation to device management. The technology and user policies businesses previously had set up to protect a central office are no longer applicable in a hybrid working set-up.

Cyber attacks have evolved – moving away from trying to infect as many devices as possible, to looking for one weak link through which they can hold corporate systems to ransom or steal data. Now, if one employee is hacked while connected to their home network, the whole system could come down. The digital and cloud-based solutions that have become pivotal to business’s operations throughout the pandemic, to maintain collaboration and productivity, have also made businesses more vulnerable.

Making your hybrid workspace safer

Companies have an opportunity now – and buy-in from senior decision-makers – to make significant improvements internally. While businesses are never able to completely eradicate risk, there are steps that you can take to build resilience as you prepare for hybrid work.

  1. First, it’s important to carry out a security assessment of your internal and external IT infrastructure to understand the infrastructure perimeter you actually have, rather than the one you think you have.
  2. This will reveal the strengths and weaknesses of your security across the board. Only then can you identify security gaps and know which improvements need to occur to secure your network. It’s like securing a home; if one entry point is left vulnerable and an attacker gets in, it doesn’t matter that all of the others were secure. Finding every possible vulnerability is an essential step to securing them.
  3. Security vulnerability assessments can be carried out at any time – before you introduce new systems or endpoints into the IT infrastructure, or on an ongoing basis. After all, what was secure yesterday may not be secure today. Canon’s Office Health Check service offers businesses a comprehensive assessment of their internal and external IT infrastructure, including recommendations ranked by risk, to help mitigate any potential security vulnerabilities. By catching malicious attacks before they’ve had a chance to take hold, Canon can help your business prevent potential data loss.

Investing in people

One of the most common mistakes that companies make is focusing solely on the technical aspect of cyber security. If you were to carry out a network perimeter assessment and invest in the best network security solutions, you might be confident in the resilience of your security measures and go about business as usual. However, you could still find yourself caught up in a security breach. Why? Because you’ve failed to provide training for your employees. After all, it only takes one errant click on a fraudulent link to open up the company to risk. Educating and training all employees on the concepts of cyber security and how to handle sensitive information correctly is an important element of any security strategy.

As we enter an era of hybrid work, it is important to foster a culture of openness around security breaches and encourage employees to come forward and share their mistakes. Your defence strategy is only effective if breaches are being reported. Firstly, this helps mitigate the damage as issues often snowball if employees hide errors. If an error is out in the open, it can be fixed. Secondly, breaches can be used to help further education on security, while pooled learnings from attacks can speed up progress in crafting new defences.

The good news is that businesses are willing to invest in upskilling their employees: A recent NCC Group survey found that 36% of decision-makers would outsource cyber security awareness training in the next 12 months, while 39% said education of security owners on cyber best practice as the area their organisation would most benefit from.

By taking control of your information, and the necessary steps to educate employees, you can keep one step ahead of cyber attacks and have the confidence to operate business as usual.

Share

Canon South Africa

Canon South Africa (Pty) Ltd, a wholly owned subsidiary of Canon Europe, came into being on January 4, 2000. Canon Europe is the regional sales and marketing operation for Canon Inc., represented in 120 countries and employing over 11,000 people across Europe, the Middle East and Africa (EMEA). Canon Europe invested in South Africa with a view to growing and expanding its market share in the country.

In South Africa, the Canon brand is today synonymous with consistency, driven by the company’s passion, imagination, knowledge and importantly, loyalty to its customers. Canon SA offers a wide range of consumer imaging products and business solutions as well as a variety of large format printers.

Canon technologies are durable, innovative, intuitive, and feature smart and environmentally sustainable designs. Canon invests heavily in R & D and will continue to deliver new and technologically advanced products that cater for a variety of requirements.

In South Africa Canon will continue to support environmental sustainability by operating responsibly, minimizing the impact of its business on the environment and also encouraging a culture of environmental awareness and accountability amongst their staff, business associates and partners. Canon has also maintained its ISO 14001 environmental accreditation since 2007.

For more information about Canon South Africa visit www.canon.co.za or follow us on Facebook, Twitter, Instagram or LinkedIn.

Editorial contacts

Arethur Molefe
Canon South Africa
(+27) 012 675 4900
arethur.molefe@canon.co.za
Monica Braganca van der Spuy or Boitumelo Mogano
PR Agency – Flume
(+27) 087 701 5516
monica@flume.co.za or boitumelo@flume.co.za