In what ways are cybercriminals trying to deceive remote workers?
Phishing
In recent months, there has been a surge in phishing emails. Cybercriminals exploit existing fears and the need for information when sending them. Phishing emails may, for example, contain so-called information about the coronavirus, tips on tax refunds, or even preventive measures from the “World Health Organization.” Clicking on links or attachments in those emails leads to a fraudulent page that tries to steal your employees’ login credentials or financial or tax information.
VPNs
Many remote workers use a virtual private network (VPN). Since the start of the coronavirus crisis, a number of critical vulnerabilities have been discovered in various VPN systems. Patches have now been released for those vulnerabilities to prevent cybercriminals from taking further advantage of them. Not all companies have installed these yet, so make sure to check this.
Tips to reduce the risks
Warn employees and train them: Make employees aware of the dangers of phishing emails and teach them how to recognize them.
Take technical measures:
- Keep all VPN hardware and software fully up to date and install all updates.
- Close any unnecessary ports on your firewalls.
- Allow employees to use only applications that the company has vetted and recommended.
- Avoid having employees access your company networks from personal devices.
Ensure you have a well secured network.
Implement a good password policy that requires your employees to choose a secure password.
Give your employees tips to create a secure work environment:
- Lock your computer when you leave your workspace.
- Do not leave passwords lying around and do not store them carelessly.
- Encrypt the data on your computer.
- Shut down your computer every evening so updates can be installed.
- Use secure communication tools to share information with colleagues.