By Ray Birch
SYDNEY, Australia—The massive shift by employees around the world to working from home has yet to lead to any known, significant data breaches, but that could change, according to one expert, who is also advising CUs to pause to record the lessons they have learned and are learning during the pandemic.
Richard Henderson, head of Threat Intelligence, spoke with CUToday.info about how credit unions, and organizations across the nation, have responded to the pandemic, moving swiftly to send their teams to work at home. He gave IT professionals high marks for how they have performed—to date.
“I think, on the whole, most companies have done rather well so far dealing with staff working from home,” said Henderson. “It's been a challenge for a lot of organizations—both large and small—to scale up the resources needed to provide adequate security for remote employees.”
Among those challenges, he said: having to establish VPN access infrastructure, address increased bandwidth requirements, enforce minimum security standards for employees who have to use their own devices, purchase and provision new devices for employees to take home to use, and more.
“All of these issues, while clearly having relatively simple paths, have been a challenge for companies to solve when you add in factors such as getting these devices into employees’ hands and shortages or lack of resources due to the fact that every other company out there is going through the same thing,” Henderson observed.
A Changed Focus
Henderson said all the intelligence he has gathered indicates the work-from-home arrangements have led to a system penetration.
“I'm not seeing as of right now any huge breaches that can be attributed directly to the large number of people who have been forced to work from home,” said Henderson. “So, you can infer from that businesses for the most part have done a pretty good job on the whole of ensuring people are able to access company resources safely.”
One reason for the absence of attacks on companies, suggested Henderson, is scammers have focused elsewhere.
“We've seen a demonstrable uptick in threats targeting financial institutions’ customers and members rather than their staff,” said Henderson. “There's a lot of government assistance programs out there right now at all levels, and we've seen numerous campaigns trying to capitalize on that. While the crooks aren't targeting the organizations directly in the volume we're seeing compared to customers, they're going after the cash that customers are keeping with their financial institutions—which will eventually lead to headaches and complaints as victims come to the FI looking for reimbursement for fraud.”
COVID-19 Wrapping Paper
Henderson added the vast majority of the attack campaigns are “low tech.”
“What I mean by that is it’s just more of the same stuff simply wrapped up in COVID-19 wrapping paper,” he said. “What it means is for organizations that have a relatively mature security strategy, they've been able to detect most of this and stop it before it got out of hand.”
Henderson said the “silver lining” from companies having to rush to get their people working from home and secure the network has been that most staff only require limited access to the network.
“At home employees are using spreadsheets, working on Word documents, using email...to do their daily jobs,” he said. “The vast majority of people don't necessarily need to VPN into the company network and access specific things. This means that if an employee makes a mistake and gets hit with a ransomware attack, for example, it’s just that one machine that’s likely affected, and not the entire network.”
What May Loom Ahead
While corporations’ luck so far appears to be holding, what looms ahead are possibly some bigger attacks that have yet to be detected, according to Henderson.
“I suspect there's been a lot of resources spent on keeping remote users secure, deploying new machines, new laptops, and making sure everything is patched,” said Henderson, noting IT staffs are often fairly limited at smaller organizations. “What worries me is there are not sufficient resources dedicated now to making sure the crown jewels are safe—for lack of a better term—the internal infrastructure that keeps everything working.
“That means there's an opportunity for attackers to take advantage of that and try to break into the corporate network through traditional channels and steal credentials, steal customer data or steal credit card numbers,” continued Henderson. “The security teams now are all focused on the remote users and could be taking their eyes off this ball for the past couple months. It's very possible in some places breaches have happened and companies just don't know about it yet.”
The biggest positive from having to secure the work of large numbers of remote staff, explained Henderson, is the job that IT staff have done to date.
“They have done incredibly well,” he said. “They've shown they are worth every penny they're paid. When all this hit, they all came to bat and did a really good job keeping the lights on and dealing with the incredible increase in remote workload and volume, and bandwidth demands required from remote networks.”
What Shouldn’t Be Overlooked
Now that the U.S. and the world months into the pandemic, some businesses are reopening and IT teams have become more accustomed to the new working conditions, Henderson said he hopes teams are assessing their own performance.
“Get your brain trust together and do a post-mortem analysis of what you have learned from this experience—what worked and what didn't,” Henderson suggested. “And then have a contingency plan going forward. Write it down, Have a process in place for dealing with this again. Only the biggest organizations in the world have pandemic plans in place, and for some those were not even useful because those plans never really changed. Create pandemic plans and test them on a semi-regular basis so you’re prepared for the next crisis.”
