Cyberattacks: New Security Vulnerabilities Emerge from Remote Work
The coronavirus crisis is forcing more and more people to work from home. Early consequences of this lightning-fast digital transformation are already apparent – cybercriminals are having a field day. Here are four practical tips to help you stay protected.
Almost everyone is affected by the COVID-19 pandemic – and cybercriminals are cashing in with COVID-19 spam and coronavirus-themed phishing scams, making the deal of a lifetime. This works for three reasons: First, many people are afraid. Second, many want to help – and are therefore more likely to open attachments or click links they’d normally distrust. And third, of course, millions of employees across Germany are now working remotely.
Few people have received formal training on how to work securely from home – after all, most had to switch workplaces overnight. Even the Bavarian government appears to have fallen behind: Developers from the magazine c’t were able to join a video conference with the state’s interior minister because the system wasn’t secured.
Here are four tips to keep hackers away from your company’s sensitive data:
1. Keep Work and Personal Activities Separate
Many of us use a single device for both work and private life – and buying a second laptop simply isn’t an option for most. In such cases, using two separate browsers can already help significantly. Creating a dedicated user account on the device – without administrator rights – adds another layer of protection. Avoid using your partner’s or a friend’s laptop for work-related tasks. After all, you can’t tell just by looking whether a device is infected with malware or spyware.
2. Use Secure Communication Channels
Information previously discussed only in the office now needs to be shared digitally. Unencrypted emails, Skype calls, and many chat services are essentially free tickets for hackers to access sensitive data.
Messaging apps like Signal and Threema offer robust security. Surprisingly, WhatsApp also uses end-to-end encryption – just like Facebook Messenger. While the social media giant can see when and with whom someone communicates, it cannot read the content of those messages.
3. Use Strong, Unique Passwords…
…everywhere. Attackers can rapidly test massive numbers of password combinations using so-called brute-force attacks. Don’t forget to change default passwords for your Wi-Fi network and router as well.
Best practices include:
- At least 12 characters for standard accounts; 16 or more for critical accounts (mix uppercase and lowercase letters, numbers, and symbols).
- A unique password for every account (reusing passwords – or slight variations thereof – is an open invitation to hackers).
- Using a reputable password manager (e.g., 1Password, LastPass, or KeePass)
4. Think Before You Click
Attackers lure victims with urgent-sounding information and advice, sneak fake coronavirus-related apps into Google Play and Apple’s App Store, or impersonate public health authorities.
Ultimately, responsibility lies with the employee. Strong passwords won’t help if you recklessly open email attachments, download files, or install software without scrutiny. If you don’t trust a sender 100%, pick up the phone and verify.
That’s harder to do while working remotely – but all the more essential.
Related Articles
- How decision-makers can prevent attacks on mail servers
- Cybersecurity vs. network security – what’s the difference?
- Auth0 launches new bot-detection solution for enhanced protection
More from the MBF Media Network
TL;DR
- Almost everyone is affected by the COVID-19 pandemic – and cybercriminals are cashing in with COVID-19 spam and coronavirus-themed phishing scams, making the deal of a lifetime.
- We give you four tips to keep hackers away from your company’s sensitive data:
- If you don’t trust a sender 100%, call them to verify.
- And third, of course: millions of employees across Germany are now working remotely.
Key Facts
Phishing volume: Over 3.4 billion phishing emails are sent globally every day.
Detection rate: Only 3 percent of employees report suspicious emails to their IT department.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What’s the difference between data protection and information security?
Data protection governs the lawful handling of personal data – including legal basis, purpose limitation, and data subject rights. Information security encompasses the technical and organizational measures designed to protect all data against loss, manipulation, or unauthorized access.
Does every company need a Data Protection Officer?
In Germany, appointing a Data Protection Officer is mandatory if at least 20 people regularly process personal data using automated systems – or if special categories of data (e.g., health data) are processed.
What rights do data subjects have under the GDPR?
The right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection. Companies must respond to such requests within one month.