×

Empower Your Business with Innovation

  • Shop By Category
  • Remote Work Enablement and Securing the Insider Threat

    Posted by HSSL Systems Integrators on Apr 12th 2020

    Organizations today are trying to navigate through what is arguably unchartered business territory as their global workforces have shifted to a large-scale remote work model seemingly overnight. And while business continuity plans are developed for external events beyond our control, they aren’t generally intended to cover an entire global workforce going remote within a matter of weeks.

    As enterprises assess the path forward in this new way of working, it is imperative to ensure that your CIOs and CISOs have the tools and resources needed to enable large-scale remote work enablement that keeps employees productive without sacrificing security. And through this exercise, organizations will need to plan to revisit decisions on access rights, entitlements and risk posture, particularly through an insider risk lens as your remote workforce is now the new perimeter you have to secure.

    Following are my 10+1 best practices for managing risk in an extended Work-from-Home business environment to keep employees protected, informed and productive.

    Prevent

    1) Deter disgruntlement – Be proactive in your interactions and be human. Use technology wisely and attempt to increase face-to-face visibility by turning cameras on. Consider how to turn everything you do to virtual.

    2) Communicate desired behaviors – with empathy. Guide your employees in how you want them to act. Understand that normal activities may become increasingly challenging and everyone is balancing work with their own personal situation. Be patient and understanding.

    3) ID areas of unacceptable risk – Identify business processes that in no circumstance should be conducted in an extended WFH situation. Initialize business continuity efforts on these activities.

    4) ID controls that can be loosened – Revisit decisions on implemented controls. Consider opening up access to collaboration solutions, allowing remote print, email to personal addresses. Monitor any changes to infrastructure and policy.

    Detect

    5) Shadow IT – Use of non-approved technology will be pervasive and is likely unavoidable. Reiterate best practices to reduce your risk, particularly where sensitive data is involved. Understand contractual requirements and the impact of recent privacy laws.

    6) Behavior Based AI models – Any model based on employee behavior is now useless. Additionally, models may need to be retrained as there will probably be a new normal. Consider focusing detection efforts on high-risk scenarios and individuals.

    7) Control bypass – Controls will be bypassed, intentionally and unintentionally. Be ready to focus detection tactics on intentional/malicious.

    8) Monitor the environment changing – Loosening of controls and the implementation of new technology will create blind spots. Identify monitoring gaps and understand your risks.

    Respond

    9) Social distanced forensics – Be prepared to perform remote collection. Make sure your BYOD policy allows for investigation of employee owned and managed equipment.

    10) Communicate threat intel – Threat intel will be invaluable in maintaining situational awareness. Increase interactions with peer organizations, share both observations and lessons learned.

    Top

    Don't Miss Out

    Sign up now to receive exclusive perks and unique promotions directly to your inbox.

    Culver Drive, 340 Irvine, CA 92604

    Tel 888.988.5472

    Copyright © HSSL Technologies. All Rights Reserved. HSSL Technologies are registered trademarks of HSSL Technologies. All other trademarks and registered trademarks brands are the sole property of their respective owners.

    HSSL Technologies (US) © 2026. All Rights Reserved.
    american expressdiners clubdiscovermaestromasterpaypalvisa