Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Data Breach
  • The Cyber Risks of Remote Workers Returning to the Office
  • Data Breach
  • Malware
  • Vulnerabilities

The Cyber Risks of Remote Workers Returning to the Office

6 years ago Tripwire Guest Authors
The Cyber Risks of Remote Workers Returning to the Office

The COVID-19 pandemic has created a huge list of challenges for businesses. One that is potentially going unnoticed or under-reported is cybersecurity. Specifically, as lockdown ends and as individuals return to offices and places of work, it may be the case that something malicious is already waiting for them on their devices.

Here we take a look at the cyber risks of remote workers returning to the office.

Cybercriminals lying in wait

Cybersecurity specialists have been noticing a rise in the number of cyber-attacks and other threat activity over the course of the COVID-19 pandemic. However, it would be wrong to assume that a relatively modest increase in attacks is all that can be expected.

“This is only likely to be the tip of the iceberg,” says George Glass, Head of Threat Intelligence at Redscan. “Many more organisations are certain to have been targeted without their knowledge; to maximise returns, cybercriminals will bide their time in order to conduct reconnaissance, avoid detection and strike at the most opportune moment”.

According to Ponemon Institute, the average “dwell time” for a company to become aware of a cyber breach in its system is 206 days. However, it may well be the case that this figure has increased over the course of the COVID-19 crisis. This is because many businesses may not have prioritised cybersecurity during this time. Additionally, their IT and security teams may lack the ability to identify the latest endpoint-focused attacks.

A concern for cybersecurity police

It is not just cybersecurity professionals who are concerned about the number of businesses that may have been infected with malware over the course of COVID-19. Senior cybercrime police officers have been making their feelings known about the dangers that can be on the horizon for companies across the UK.

“One of our concerns in the UK is the number of businesses that have been abandoned,” said Peter Goodman, chief constable for the Derbyshire Constabulary and National Lead for Cyber Crime. “Because IT and cyber-specialists have been off, and whole premises have been shut down, we do anticipate that there may be some malware sitting on people’s systems as they get back to work”.

Dormant malware – Understanding the nature of the threat

A huge number of employees have been working from home due to government restrictions and recommendations regarding social distancing. However, as restrictions have been gradually lifted, these employees are slowly returning to the office. And whilst this might be seen as positive for business, it could be a problem, too.

Employees returning to the office post-lockdown will begin to connect to corporate networks. If cybercriminals have been lying dormant on devices, they will then be able to use this opportunity to move through the network and cause more serious damage such as by deploying ransomware.

Over the course of the pandemic, there has been a substantial rise in malspam campaigns distributing malware such as Emotet and Trickbot, among others. These threats can be extremely difficult to detect without strong endpoint visibility across employee devices. These capabilities are simply something that many businesses do not currently possess.

Are businesses too reliant on traditional antivirus software?

One of the reasons that organisations remain at risk of the latest cyber threats is due to their current reliance on traditional antivirus solutions. Whilst antivirus software has been – and remains – an important aspect of cybersecurity for companies, it cannot be seen as a silver bullet that will keep an organisation entirely secure.

When a business is over-reliant on antivirus software, it can lead to some fileless and polymorphic malware being missed by our defences. Antivirus works by identifying the signatures of known malware. But these forms of malware do not have static signatures and constantly change. As such, they cannot be detected by antivirus solutions.

In order to deal with these sorts of threats, businesses must look to identify and respond to them by leveraging next-generation solutions such as Endpoint Detection and Response tools that utilise a behavioural-based approach to detection. This is a proactive form of cybersecurity. By monitoring activity in the system, the cybersecurity solution can determine normal behaviour and also recognise dangers from unusual activity.

What else should businesses do to mitigate return to work security risks?

As well as updating antivirus signatures, businesses should review and update firewall rules. (These may have been relaxed during lockdown.) It is also important to conduct daily vulnerability assessments, either themselves or through a vulnerability management service. Doing so will help them to identify vulnerabilities, such as unpatched software and the use of weak credentials, that may not have been identified during the lockdowns.

Final thoughts

As staff return to the office, it is essential for businesses to prioritise the potential cyber threats that could be waiting for them. It is a great idea to work closely with cybersecurity specialists to ensure that your organisation is as prepared as possible.


About the Author: Chester Avey has over 10 years of experience in cybersecurity and business management. Since retiring he enjoys sharing his knowledge and experience through his writing.
Twitter: @ChesterAvey
Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” The Cyber Risks of Remote Workers Returning to the Office” appeared first on TripWire

Source:TripWire – Tripwire Guest Authors

Tags: COVID-19, Encryption, Malware, Ransomware, TripWire, Vulnerability

Continue Reading

Previous Emotet Returns in Malspam Attacks Dropping TrickBot, QakBot
Next 3 Emerging Innovations in Technology that Will Impact Cyber Security

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories

5 hours ago [email protected] (The Hacker News)
  • Data Breach

The Buyer’s Guide to AI Usage Control

7 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends

8 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows

12 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign

13 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

Microsoft Develops Scanner to Detect Backdoors in Open-Weight Large Language Models

1 day ago [email protected] (The Hacker News)

Recent Posts

  • ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories
  • The Buyer’s Guide to AI Usage Control
  • Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends
  • Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows
  • Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT