Opens in a new tab
vmblog logo 2024 wht (updated)

What Happens with Cybersecurity When Your Office Reopens?

Share: 

David Marshall | Published: October 19, 2021

By Tom Callahan, Director of Operations, MDR at PDI Software

As more business offices start to reopen, you need to ask a critical question: What happens with your approach to cybersecurity? Even if it was necessary to relax your cybersecurity standards during a period of unprecedented business disruption, there’s simply no excuse to do that when you begin returning to “normal” business operations.

Yet, the challenges will be significant. With so many employees opting for the work-from-home (WFH) or hybrid WFH model, the lines will increasingly blur between what constitutes “the office.” An employee might be in the office one day a week or the entire week-but on a completely different schedule the next week. Some will continue using their personal computing devices while others will utilize systems that remain in their cubicle at the physical office.

Nothing about this hybrid working model is completely new, of course. But the scale and complexity have changed dramatically during the pandemic era. And that’s going to continue challenging your IT security staff, processes, and technologies.

Consider the scenario of Company X

With the increase in workforce mobility, even more employees will likely bring personal devices into your physical office space and access the private networks within the confines of your building.

This didn’t create much of an issue when everyone was working from home and those personal devices were accessing your network remotely through a VPN. You at least had some control in terms of being able to restrict access through firewalls. Now, however, you need to think about how to control cybersecurity under these new conditions.

Imagine this scenario: As soon as the COVID-19 pandemic hit and offices shut down, 300-person Company X shifted to a fully remote WFH model. It distributed company-issued laptops to approximately half of the workers, while the other half used whatever personal computer they had at home.

Now Company X is identifying how its employees will choose to work going forward. During the past year, all the desktop systems in the office were sitting idle. They no longer even appear on the domain, the software hasn’t been patched, and the endpoint protection tool stopped monitoring them after 90 days of inactivity. How much effort and cost would it take to get all those machines fully operational again?

Or, if employees have been using company-issued laptops at home and now plan to bring them into the office, how will you discover what types of unsupported software or applications might have been added in the past several months?

Increased mobility creates complexity

After a year of employees working from home, you might have no idea what resides on company-issued equipment. Theoretically, all those employees have been using VPNs. However, you can’t expect that every employee has followed the correct procedures. In fact, it’s a best practice to assume they haven’t.

Any USB drive coming into a secure office network could carry a significant threat. Likewise, if a WFH employee downloaded sensitive company or customer data onto a personal laptop or a thumb drive that’s now sitting under a pile of paperwork on their home office desk, that could represent a significant business exposure.

So, where do you start from a cybersecurity perspective as you prepare your office for the re-arrival of employees? Do you devote valuable IT budget and resources to get all the in-office systems up to speed first? Or do you just start fresh by purchasing brand new (clean) desktops or laptops with all the latest security protocols already enabled?

And what about your current cybersecurity policies and processes-do you need to define multiple sets of policies based on all the different working arrangements? Or do you simply establish a common policy that has to cover every employee and every working situation?

Offload your cybersecurity burden

These are just a few of the questions you need to ask yourself. But if you had to take any shortcuts or make too many exceptions just to keep your business functional during the pandemic, now is the time to review your entire cybersecurity strategy.

Before you start bringing people back into the office, make sure you have a clear plan for getting your systems and employees up to speed. Here are a few actions you can take:

  • For your systems, try to avoid the “quick fix” approach where you’re simply delaying a difficult decision or problem until later. Do it right the first time.
  • Think about how you can holistically roll out security policies that reduce your risk exposure.
  • For employees, prioritize security awareness training-especially if you’ve experienced significant turnover during the past year.

Even more importantly, make sure you have a reliable threat detection and response plan before you start bringing existing machines back online or allowing employees to connect their laptops and mobile devices to your private office networks. If you don’t have the expertise or resources to do this work on your own, consider bringing in a reputable cybersecurity vendor that offers fully managed extended detection and response (XDR) services.

##

ABOUT THE AUTHOR

Tom Callahan 

Tom Callahan has spent more than 15 years in information technology and security, focusing on areas like cloud services, cybersecurity, infrastructure, and operations-including MDR and XDR services. His background also includes business IT restructuring and retooling to support ongoing changes throughout information technology and security.

Tom joined PDI through its December 2020 acquisition of ControlScan Managed Security Services. He holds a B.S. in Information Technology from Towson University. He’s also a Red Hat Certified Engineer (RHCE), Certified ScrumMaster, and an active member of the Mid-Atlantic CIO Forum. Find Tom on LinkedIn and Twitter.