ADVERTISEMENT

Cybersecurity teams need a commercial mindset as we develop the ‘new normal’

A man's hand pointing with a pin to a map hung on a wall
Adi Gaskell
Adi Gaskell Contributor
August 27, 2020 Updated: September 28, 2021 2 min read
During April, Google revealed that there were around 18 million phishing and malware emails detected every day on Gmail in messages related to the virus.

A dual mindset

ADVERTISEMENT
  1. Directly tackling hotspots - The shift to remote working has forced many teams to adopt ad hoc systems that lack the security of on-premise networks, so teams have had to secure these new networks whilst also ensuring any training gaps are addressed and digital hygiene is maintained.
  2. Patching up operations - The early days of the pandemic saw a great deal of disruption to our ways of working, and so a lot of ad hoc processes were introduced to make such changes in such a short space of time. This typically saw reductions in security forced through to ensure operations could continue, but as organizations became more attuned to the new methods, many security protocols were re-introduced.
  3. Making key digital gains - As new ways of working began to embed in the minds of workers, organizations have begun to standardize security processes for remote working. There have also been clear moves to fortify consumer security and fraud prevention processes.

The new normal

  • Ensuring new ways of working are secure - Many commentators expect the remote working boom forced upon us by Covid-19 to endure beyond the crisis, and so a combination of a range of approaches is likely to be adopted, including:
    • Better use of cloud-based tools and infrastructure to provide the agility organizations need.
    • The extension of operational defenses to include things such as insider threat detection as the workforce adopts remote working as default. For instance, this could include restricting use of company tools by family members, or helping employees manage their stress levels.
    • A fresh approach to workforce privacy, especially as organizations introduce measures to track and trace infected employees.
  • Ensuring new customer journeys are secure - Covid-19 has had a profound impact on customer experience, with many adopting digital channels for the first time. This has created clear trade-offs between making such an experience easy and making it secure. Looking forward, there are a number of things cybersecurity teams will need to consider, including:
    • Ensuring that new cybersecurity processes, such as bot mitigation or firewalls, can function effectively and efficiently at scale.
    • Ensure that privacy is built into digital channels by design, which will require teams to involve customers in the process and make strong use of education and awareness campaigns.
    • Render the customer security experience as seamlessly as possible via the use of a single customer ID across all channels, and therefore enable customers to transact across mobile, web, and telephone in a seamless way.
  • Ensuring new supply chains are secure - Effective security is a collaborative endeavor, and therefore third-party and channel-partners are vital parts of your security efforts. To ensure the network is as resilient as possible will require cybersecurity teams to consider things such as:
    • Widening assessment coverage so that it covers more vendors and shadow third-party services.
    • Build joint resilience with your supply chain partners, with security-assessment controls helping to test the robustness of your network.
    • Collaborate with the supply chain using secure remote-collaboration tools that take account of the security implications of changes in business conditions for your partners.
ADVERTISEMENT