As an IT company in Atlanta, we have seen explosive growth in employees working from home in the last decade. In industries like construction and architecture, a large percentage of employees work remotely from a job site. Other more office-bound industries have seen an increase in remote work too. In some cases, remote work is a perk to help retain talent. In others, it’s an absolute necessity due to increasing traffic in Metropolitan areas like Atlanta. According to a recent study done by Gallup, 43 percent of Americans spend at least some time working from home.
Yet, the impacts remote workers have on cybersecurity is rarely considered.
After hours work further complicates things. During non-business hours most employees don’t have access to the on-site IT staff either and have to fend for themselves. This coupled with the fact that they tend to use their own equipment (router, wireless and in some cases home PC’s) makes it difficult to manage security.
So how to manage the security risk but still be able to offer this to your employees? The answer is quite simple in theory but tricky to get right. It’s also dependent on what the employee is doing. A supervisor on a construction site does not need the same level of security as a doctor doing a remote diagnosis.
Depending on your context you may need some or all of these. The exact recipe you follow will be unique but a strategic plan should be in place.
A doctor works from home on Mondays and Fridays and spends weekends being on-call for emergency consultations. The doctor's home office must act the same as a corporate office because they will access confidential information.
It could look something like this:
The actual system will look and feel exactly like a corporate office but located in the doctors home. The goal here is to duplicate the office environment for the user and duplicate the security profile in use.
Construction supervisor that works 90 percent from a construction site. The construction is non-governmental and not sensitive in nature.
Their setup could look like this:
This system is not anything like the one in use at the head office and supplies only the systems and data required to fulfill the specific duties inherent to the role. The user can get remote access to email and files required for that specific job only. This way limited damage occurs should any of this information be compromised. It is very important with remote infrastructures like this to follow through on least access privilege. Make sure the user only has the access they need. Don’t give access to the accounting drives if all they need is blueprints.
Your exact system will fall somewhere in between, but the basics stay the same. Understand the context and understand what your risks are. Always design for the specific job and understand what happens when (not if ) your remote office or worker gets compromised. You need to have a plan in place to address the situation and limit spill-over.