{"id":57332,"date":"2023-03-28T08:01:00","date_gmt":"2023-03-28T11:01:00","guid":{"rendered":"https:\/\/dev.abes.com.br\/?p=57332"},"modified":"2023-02-12T20:09:20","modified_gmt":"2023-02-12T23:09:20","slug":"preenchendo-as-brechas-de-seguranca-no-home-office-e-em-configuracoes-hibridas-de-trabalho","status":"publish","type":"post","link":"https:\/\/dev.abes.com.br\/en\/preenchendo-as-brechas-de-seguranca-no-home-office-e-em-configuracoes-hibridas-de-trabalho\/","title":{"rendered":"Closing the security gaps in home office and hybrid work settings"},"content":{"rendered":"<p><em><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-57335 alignleft\" src=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/02\/cesarcandido.png\" alt=\"\" width=\"266\" height=\"246\" \/>*Cesar Candido<\/em><\/p>\n<p>With the pandemic almost under control, organizations around the world have already returned to the office and many have permanently adopted hybrid work, which includes several days of home office. While each arrangement carries its set of pros and cons, from a cybersecurity perspective there are some challenges that need to be addressed to cover all security gaps.<\/p>\n<p>This hybrid arrangement of work blurs the divide between corporate and home networks, while expanding the attack surface in both environments. So, how to deal with these security breaches?<br \/>\nFirst, we must examine the data to see which threats thrived during the transition period. In 2021, most organizations have settled into remote settings. In our annual summary for that year, we noted that there was a 382% increase in malicious files blocked. Cybercriminals also seem to have doubled down on scams.\u00a0<em>phishing<\/em>\u00a0during the period.<\/p>\n<p>Based on data from Trend Micro\u2122 Cloud App Security, the\u00a0<em>phishing<\/em>\u00a0had an absurd growth of 596%. In the age when the workplace has largely shifted from offices to homes, malicious actors have taken full advantage of email to spread malware as it is a low-effort, high-impact attack vector.<u><\/u><u><\/u><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-57333 aligncenter\" src=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/02\/unnamed-6.png\" alt=\"\" width=\"567\" height=\"292\" srcset=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/02\/unnamed-6.png 567w, https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/02\/unnamed-6-480x247.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 567px, 100vw\" \/><\/p>\n<p>And the home network? Data from the \u201cSmart Home Network\u201d solution showed an increase in potential malicious activity on home networks from 2019 to 2020. The number of threats blocked indicates that home devices, particularly routers, were frequent targets during the period. While this was to be expected, as most employees who stayed at home relied on devices to stay connected and continue their activities, the growth in attacks more than doubled, causing immense concern for the information security industry.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-57334 aligncenter\" src=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/02\/unnamed-7.png\" alt=\"\" width=\"567\" height=\"290\" srcset=\"https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/02\/unnamed-7.png 567w, https:\/\/dev.abes.com.br\/wp-content\/uploads\/2023\/02\/unnamed-7-480x246.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 567px, 100vw\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>For hybrid working to work, employees need access to company files from their remote locations. However, moving files can increase the likelihood of a data breach or the introduction of malicious files into a company&#039;s network. According to research conducted by OpenText - a Canadian company that develops and sells software for managing business information - 56% of US employees use personal file sharing tools in their day-to-day work.<u><\/u><u><\/u><\/p>\n<p>Among the respondents, 76% admitted that they feel stressed by the flood of Home Office context information, while 26% stated that they use 11 or more accounts, features, tools and apps, every day \u2013 an overwhelming estimate, to say the least. Minimum.<u><\/u><u><\/u><\/p>\n<p>Organizations must provide their employees with secure ways to transfer large files and access data hosting services. They should also educate employees on what types of files are safe to share and the correct permissions to apply when sharing files.<\/p>\n<p style=\"font-weight: 400\">Virtual Private Networks (VPNs) allowed users to connect to secure networks while working from home. Unfortunately, unsecured vulnerabilities in VPNs have also been exploited in attacks. One of the most used vulnerabilities was CVE-2018-13379. To date, it is the most exploited vulnerability in VPN products, although a patch for it has been available since May 2019. Other vulnerabilities that have seen many exploits include CVE-2019-11510 and CVE-2019-19781.<\/p>\n<p style=\"font-weight: 400\">Enterprises and users alike must be aware of these threats, as hybrid configurations make it easier for them to traverse both home and office networks. As Home Office and hybrid work test the idea of cybersecurity as a shared responsibility, employees and organizations must do everything in their power to prevent threats and bridge the security gap between home and office networks.<br \/>\nBelow are some tips for employees:<\/p>\n<ul style=\"font-weight: 400\">\n<li>Isolate your work devices on your home network;<\/li>\n<li>Use VPNs to make the connection between your home and office network more secure;<\/li>\n<li>Configure the security of the routers to limit the possibilities of invasion by cybercriminals; if possible, use a network security tool to get an additional layer of protection for your entire home environment and connected devices;<\/li>\n<li>Follow your company&#039;s rules of good safety practices;<\/li>\n<li>Be aware of the tactics of\u00a0<em>phishing<\/em>\u00a0and other scams, especially when working in a less secure environment;<\/li>\n<li>Use only tools, applications, services and accounts made available by the company, avoiding the use and download of unapproved alternatives;<\/li>\n<li>Always opt for two-factor authentication (2FA) instead of just using simple passwords.<\/li>\n<\/ul>\n<p style=\"font-weight: 400\">Companies must:<\/p>\n<ul style=\"font-weight: 400\">\n<li>Control employee access to the VPN and require them to renew their login daily;<\/li>\n<li>Establish guest networking for use by guests and on personal devices;<\/li>\n<li>Promote staff training on best digital security practices, in addition to creating a communication line to report suspicious incidents, particularly those with signs of\u00a0<em>phishing<\/em>;<\/li>\n<li>Define tools and establish cloud services for communication between employees and file access and sharing<\/li>\n<\/ul>\n<p>*<em>Cesar Candido is CEO of Trend Micro in Brazil, a company specialized in cybersecurity<\/em><\/p>\n<p><strong><em>Notice:<\/em><\/strong><em>\u00a0The opinion presented in this article is the responsibility of its author and not of ABES - Brazilian Association of Software Companies<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Cesar Candido<br \/>\nManaging Director of Trend Micro in Brazil <\/p>","protected":false},"author":10,"featured_media":57336,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[8,19],"tags":[],"class_list":["post-57332","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artigos","category-ultimas-noticias"],"acf":[],"publishpress_future_action":{"enabled":false,"date":"2026-06-13 06:36:18","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category"},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/57332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/comments?post=57332"}],"version-history":[{"count":1,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/57332\/revisions"}],"predecessor-version":[{"id":57337,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/57332\/revisions\/57337"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/media\/57336"}],"wp:attachment":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/media?parent=57332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/categories?post=57332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/tags?post=57332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}