Resources - eBooks & On-Demand Webinars - Field Effect

Strengthening Defenses: Best Practices for Securing Remote Work

Written by Field Effect | Oct 24, 2024 2:46:28 PM

Recorded live on September 17, 2024.

Best practices for securing remote work

Remote work is no longer an exception. It's a fixture of how modern businesses operate. But the same flexibility that makes distributed teams possible also introduces real cybersecurity risk. In this webinar, Thomas Dunne, Strategic Cybersecurity Adviser at Field Effect, draws on over 20 years in Canada's security and intelligence community to walk through the threat landscape facing remote workers and the practical controls that can reduce it.

The state of remote work in 2024

The numbers tell a clear story. In Canada, about 18% of workers are classified as fully remote in 2024, up from just 7% in 2016. In the US, fully remote workers account for roughly 16-20% of the workforce, while hybrid workers make up about 54%. And 65% of companies are currently offering some form of remote work arrangement, according to the Small Business and Entrepreneurship Council.

Collaboration tools have grown alongside this shift. Microsoft Teams had about 2 million daily users in 2017. By 2022, that number was 270 million.

Remote work brings genuine benefits: flexibility, better work-life balance, and cost efficiency for businesses that no longer need to co-locate everyone. But it also means corporate data is being accessed and shared from more places, on more devices, over more network connections than ever before. That creates new exposure.

Why remote work changes the cybersecurity picture

For a long time, network security was built around a clear perimeter. The assumption was that everything inside the boundary was safe, and everything outside was a threat. That model is no longer sufficient.

Remote work, the pandemic, and the rise of cloud services have eroded those boundaries. Today, the field calls this "defense in depth," meaning organizations need multiple layers of protection, not a single outer wall. As Thomas puts it, the old model was like a cookie: hard and crunchy on the outside, soft and chewy on the inside. If an attacker finds a way through the exterior, there is nothing to slow them down once they are in.

The specific risks remote work introduces include:
  • Expanded threat surface. When users work from home, coffee shops, or shared spaces, the boundary of your network becomes harder to define. More entry points means more opportunities for attackers.

  • Reduced network visibility. Organizations may not have the same tools or ability to monitor activity when employees connect from outside the traditional office environment.

  • Physical security risks. Corporate devices used outside the office can be lost, stolen, or accessed by others in a household.

  • Third-party cloud applications. Tools like Microsoft Teams, file-sharing platforms, and cloud storage services introduce new means of communication and data storage that need to be accounted for in any security program.

Understanding your threat surface

A threat surface refers to all the possible points within a system, network, or application that a threat actor could exploit to gain unauthorized access. The larger the threat surface, the greater the risk.

Threat surface has two dimensions. The external threat surface includes anything accessible from outside your perimeter: systems, services, and devices exposed to the internet that could be targeted through phishing, brute force attacks, or exploitation of known software vulnerabilities. The internal threat surface is what exists inside your network: user accounts, devices, and applications that could be exploited by an insider or by an external attacker who has already gained a foothold.

Understanding your threat surface means knowing who is connecting to your corporate resources, from where, over what means, and for what purpose. As remote work evolves, so must the security practices designed to manage it.

A principled approach to securing remote work

Rather than a checklist of tools, Thomas frames the foundation of remote work security around five core principles:

  1. Ensure the confidentiality, integrity, and availability of corporate systems and data.
  2. Nurture a mature cybersecurity program through improved awareness and a focus on people, processes, and technology.
  3. Employ a managed detection and response solution for real-time, 24/7 monitoring of your network, cloud services, and endpoints.
  4. Keep remote workers top of mind when securing device and account connectivity.
  5. Ensure remote work connectivity is secured, including through VPN and multifactor authentication wherever possible.

The CIA triad underpins all of this. Confidentiality means corporate data stays private and reaches only its intended audience. Integrity means data is stored safely and hasn't been altered from its original form. Availability means data is accessible when and where it needs to be. Applying effective security controls across all three builds trust and reliability across the organization.

Building a culture of security awareness

Technology alone is not enough. Human behavior is one of the most significant variables in any organization's security posture, and the most effective programs address it directly.

Security awareness training should be available to all employees and tailored for audiences with higher exposure to threats, such as finance and HR staff, or executive leadership, who may face more targeted attacks based on their visibility and role. The goal is to reduce human error and help employees understand the part they play in protecting the organization.

A few specific elements that support this culture:
  • Phishing reporting. Giving users a way to safely report suspicious emails reinforces good habits and builds a feedback loop. Field Effect's Suspicious Email Analysis service lets users submit emails for review directly from their Outlook or Gmail toolbar and receive a response indicating whether the message is malicious and what to do about it. The key message: don't click, don't enter credentials, and report promptly.

  • Financial fraud awareness. Business email compromise and financial fraud often go hand in hand. Documenting and sharing formal processes for invoicing, payment processing, and bank account changes, along with identity validation procedures that happen outside of email, can significantly reduce the risk of financially motivated attacks.

  • Cybersecurity policy framework. Policies formalize roles, responsibilities, and expected behaviors. Particularly relevant for remote work: a password policy that sets standards for creation and storage (including use of a password manager), an acceptable use policy that sets guidance on using corporate or personal devices to connect to the organization's environment, and a bring-your-own-device (BYOD) policy that defines minimum security requirements for personal devices, protocols for lost or stolen devices, restrictions on what data can be accessed or stored, and clarity around monitoring expectations.

  • A cybersecurity champion. Someone needs to set the tone from the top and guide the ongoing evolution of the organization's security program, including how remote connectivity is handled. This is a leadership role that also shapes cybersecurity investment decisions over time.

  • An incident response plan. Having a documented, shared IR plan is one of the most important elements of any cybersecurity program. It should include playbooks for the most common incident types (ransomware, malware, business email compromise) and answer the questions: who does what, when, and how? The purpose is to minimize impact and reduce response time when an incident does occur. Field Effect provides policy templates, including IR plan templates, within its portal.

Technical security controls for remote work

Security awareness sets the culture; technical controls provide the layer of protection that backs it up:

  • Managed detection and response (MDR). Real-time monitoring of your network, endpoints, and cloud services is the foundation. An MDR solution should identify vulnerabilities and suspicious activity, correlate signals across your environment, provide clear and prioritized guidance on what to do, and take defensive actions on your behalf when warranted, such as isolating a compromised account or endpoint before a threat actor can cause further damage.

  • Account protection. Strong, unique passwords managed through a password manager reduce the risk of credential reuse. Multifactor authentication is one of the single most effective controls available: effective MFA implementation can reduce the chance of account compromise by as much as 99%. Conditional access policies add another layer by flagging or denying access when activity falls outside defined parameters.

  • Email protection. Spam filtering, attachment scanning, quarantining, and link validation are now standard in modern email security solutions. Equally important is logging: authentication and audit logs, inbox rule auditing, and sufficient log retention give you the ability to reconstruct what happened in the event of an incident.

  • Secure remote connectivity. A secure VPN provides a single, protected point of entry into your network, allowing remote users to access resources without exposing those resources to the public internet. Recent SonicWall vulnerabilities are a timely reminder that VPN infrastructure itself needs to be kept patched and monitored.

  • User access controls and least privilege. Users should have access only to what they need to do their job, nothing more. Privileged administrative accounts should be tightly controlled and regularly audited, since they are high-value targets for attackers looking to move laterally through a network.

  • Minimizing personal device use. Personal devices are often shared within households, harder to monitor, and less likely to have consistent patching or security controls applied. The recommendation is to minimize personal device use as much as possible. Where it is permitted, a BYOD policy, mandatory MFA, and logging all connections help reduce the associated risk.

How Field Effect can help

Field Effect MDR addresses the monitoring and detection side of this picture across network, endpoint, and cloud. It provides real-time visibility, active response capabilities (including isolating compromised accounts or devices), the Suspicious Email Analysis service, and a DNS firewall that blocks access to known malicious sites.

For organizations looking to assess and strengthen their overall security posture, Field Effect also offers three professional services:

  • Cybersecurity assessments identify existing strengths, surface gaps in controls and policies, and produce a prioritized plan for addressing them.

  • Incident response readiness helps organizations evaluate their current threat surface, build or improve their IR plan, and be better prepared to respond when an incident occurs.

  • Phishing simulations test employees' ability to recognize suspicious communications and build organizational resilience against social engineering.

All three are designed around the same framework: understand where you are strong, identify where gaps exist, and provide a clear path to addressing them.

Q&A

The LastPass breach was caused by a personal device..is this a common risk?

Yes. The LastPass breach is a well-known example of how personal device use can create a path to a serious compromise. This is exactly why minimizing personal device use is recommended wherever possible, and why organizations that do permit it need a clear BYOD policy, mandatory MFA, and logging in place. The risk is real, and the controls exist to reduce it.

What is the difference between security awareness training for the C-suite versus a standard employee?

There is overlap. Everyone in an organization needs to understand the types of threats the organization faces and their role in defending against them. The distinction for the C-suite is that executives may face more targeted attacks based on their visibility and role, sometimes referred to as "whaling." Training for executives should include awareness of those more tailored attack types, in addition to the general security awareness that applies across the organization.

Will organizations ever stop shaming employees for clicking a phishing link?

Hopefully. Shame is not an effective motivator and is likely to result in less reporting, not more. The better approach is regular, recurring awareness training, phishing simulations, and security tools that give employees a way to report suspicious activity before or after interacting with it. Threat actors are sophisticated and creative, and it is not realistic to expect every employee to never make a mistake. The goal is to minimize the window of exposure when something does happen, and that means creating an environment where people feel safe reporting quickly, even if they already clicked.

Do you offer support for clients just starting to build a security strategy or incident response plan?

Yes. Field Effect's cybersecurity assessments and incident response readiness service are designed for exactly this. The right starting point depends on where an organization is in their journey, whether they are just beginning or have already built parts of a program. Having a conversation about objectives and current state helps determine which service is the best fit.