As the world recalibrates to the new normal, we’re giving back to the community by releasing our most popular assessment tools for free. Starting today, anyone can have...
A number of our clients have asked us how to leverage the NIST Cybersecurity Framework (NIST CSF) to address work-from-home cyber risk. Considering the global prevalence of remote work well into 2021, the concern deserves attention and can easily be addressed in the Axio360 platform. With these continued and dramatic changes in the work environment, it’s more important than ever to be prepared for a complex and expanded cyber-attack surface.
As the pandemic surfaced last year, there was a hurried initiative by organizations to shift work operations from onsite to work from home. In an effort to maintain the continuity of business operations in the frenzy caused by COVID19, security took a backseat. There was no other choice as organizations were caught in an unprecedented situation. IT and security teams were pressed to deploy mechanisms that gave employees urgent remote access to the company’s systems and processes.
However, there’s no denying the fact that the shift in the working mode has introduced risks to an organization’s physical, personnel, and systems’ security.
As employees use their personal devices – which they use for varied other purposes outside of work such as entertainment, gaming, and shopping – for work and connect to personal internet networks to send confidential organizational and client data, the vulnerability of an organization to cyber attacks and thefts exponentially increases. And so does the potential for expensive lawsuits, fines, and penalties for breach of sensitive data.
The hybrid work arrangement, where some employees work from home and others work onsite, introduces further risks as on-premises workers connect and collaborate and exchange information and documents with remote workers who may be using rogue or outdated devices, vulnerable home networks, and/or weak passwords.
But that’s not all. Data accessed, processed, transferred, and uploaded to the cloud over poorly managed home networks and weak security protocols exposes an organization’s susceptibility to attacks. All in all, given the umpteen types of risks from disparate sources and the nature of the gigantic internet, there is no defined or finite parameter of the attacks to prepare against. The surface for attacks has expanded with no set boundaries. The question is: how to address such undefined remote work cybersecurity risk?
This blog post highlights 50 considerations for enhancing your remote work cybersecurity that are mapped to NIST CSF. Keep these considerations in mind as you complete your NIST CSF assessments in the Axio360 Platform. NIST CSF contains 5 Functions, 23 Categories, and 108 Subcategories; the considerations are organized by the NIST CSF Functions: Identify, Protect, Detect, Respond, and Recover and grouped by the 23 NIST CSF Categories.
The first NIST CSF Function, Identify, drives home the importance of understanding what remote work cybersecurity risks the organization is susceptible to before going about putting protections in place. With more and more endpoints and with many of those now being on employee-provided networks, the risks of data leakage are becoming exponentially higher.
Axio’s Top 50 NIST CSF Tips to Address Remote Work Cybersecurity Risk
Once the organization has a grasp of the systems, assets, data, and capabilities in its environment and their associated risks, the next Function, Protect, guides actions for deciding what specific steps to take to protect them.
During the pandemic and lockdown, users have had fewer options for “off-work” hours. This has resulted in an increased engagement across devices and more opportunities for exploitation.
Axio’s Top 50 NIST CSF Tips to Address Remote Work Cybersecurity Risk
The third NIST CSF Function focuses on the need to be able to effectively Detect when a cybersecurity event may be occurring and know what to look for. The FBI has reported a 400% increase in cyber incidents since March 2020.
Axio’s Top 50 NIST CSF Tips to Address Remote Work Cybersecurity Risk
The fourth NIST CSF Function is based on the fact that no organization is immune from a cybersecurity event, no matter how proactive it has been; so it is important to prepare to Respond to remote work cybersecurity events.
In the times of COVID 19, ransomware’s latest tactic is a conversion to doxware. The attacker infiltrates your data and threatens to notify your customers that you have been hacked and that sensitive customer data is being held. So even if you have backups and don’t pay the hackers, your reputation is still at risk. How do you respond properly?
Axio’s Top 50 NIST CSF Tips to Address Remote Work Cybersecurity Risk
Finally, the fifth NIST CSF Function, Recover, helps organizations get back to normal after a cyber event. With a more remote workforce, additional considerations may be necessary.
Axio’s Top 50 NIST CSF Tips to Address Remote Work Cybersecurity Risk
The Axio360 platform is the easiest and fastest way to get started with NIST CSF. With the considerations above, you are well on your way to optimizing your work-from-home or remote work cybersecurity program. If you’d like to learn more information and dive into more detail on how to perform a NIST CSF assessment in Axio360, you can book a demo and speak with one of our experts.
Download this handy checklist as you go through your NIST CSF assessment.
Axio’s Top 50 NIST CSF Tips to Address Remote Work Cyber Risk
About the author: Craig Shuster is Axio’s VP of Cyber Risk Engineering
As the world recalibrates to the new normal, we’re giving back to the community by releasing our most popular assessment tools for free. Starting today, anyone can have...
Some of the common questions we encounter while building cybersecurity programs for organizations include: What is the NIST cybersecurity framework exactly? What do the...