THREAT BRIEFING · 24.09.2026 DEENFRES

Practice & Implementation

Cyberattacks: New Security Vulnerabilities Emerge from Remote Work

By Tobias Massow · April 7, 2020 · 5 min read

The coronavirus crisis is forcing more and more people to work from home. Early consequences of this lightning-fast digital transformation are already apparent – cybercriminals are having a field day. Here are four practical tips to help you stay protected.

Almost everyone is affected by the COVID-19 pandemic – and cybercriminals are cashing in with COVID-19 spam and coronavirus-themed phishing scams, making the deal of a lifetime. This works for three reasons: First, many people are afraid. Second, many want to help – and are therefore more likely to open attachments or click links they’d normally distrust. And third, of course, millions of employees across Germany are now working remotely.

Few people have received formal training on how to work securely from home – after all, most had to switch workplaces overnight. Even the Bavarian government appears to have fallen behind: Developers from the magazine c’t were able to join a video conference with the state’s interior minister because the system wasn’t secured.

Here are four tips to keep hackers away from your company’s sensitive data:

1. Keep Work and Personal Activities Separate

Many of us use a single device for both work and private life – and buying a second laptop simply isn’t an option for most. In such cases, using two separate browsers can already help significantly. Creating a dedicated user account on the device – without administrator rights – adds another layer of protection. Avoid using your partner’s or a friend’s laptop for work-related tasks. After all, you can’t tell just by looking whether a device is infected with malware or spyware.

2. Use Secure Communication Channels

Information previously discussed only in the office now needs to be shared digitally. Unencrypted emails, Skype calls, and many chat services are essentially free tickets for hackers to access sensitive data.

Messaging apps like Signal and Threema offer robust security. Surprisingly, WhatsApp also uses end-to-end encryption – just like Facebook Messenger. While the social media giant can see when and with whom someone communicates, it cannot read the content of those messages.

3. Use Strong, Unique Passwords…

…everywhere. Attackers can rapidly test massive numbers of password combinations using so-called brute-force attacks. Don’t forget to change default passwords for your Wi-Fi network and router as well.

Best practices include:

4. Think Before You Click

Attackers lure victims with urgent-sounding information and advice, sneak fake coronavirus-related apps into Google Play and Apple’s App Store, or impersonate public health authorities.

Ultimately, responsibility lies with the employee. Strong passwords won’t help if you recklessly open email attachments, download files, or install software without scrutiny. If you don’t trust a sender 100%, pick up the phone and verify.

That’s harder to do while working remotely – but all the more essential.

 

Related Articles

More from the MBF Media Network

MyBusinessFutureDigitalization in SMEs: Best PracticescloudmagazinCloud as an Enabler of Digital Transformation

TL;DR

Key Facts

Phishing volume: Over 3.4 billion phishing emails are sent globally every day.

Detection rate: Only 3 percent of employees report suspicious emails to their IT department.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What’s the difference between data protection and information security?

Data protection governs the lawful handling of personal data – including legal basis, purpose limitation, and data subject rights. Information security encompasses the technical and organizational measures designed to protect all data against loss, manipulation, or unauthorized access.

Does every company need a Data Protection Officer?

In Germany, appointing a Data Protection Officer is mandatory if at least 20 people regularly process personal data using automated systems – or if special categories of data (e.g., health data) are processed.

What rights do data subjects have under the GDPR?

The right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection. Companies must respond to such requests within one month.

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH