Security – A Pandemic Evolution
CIOREVIEW >> Security >> NEWS

EBSCO Industries

Willie Clemons, Director Identity & Access Management

Security – A Pandemic Evolution

Willie Clemons, Director Identity & Access Management
Willie Clemons, Director Identity & Access Management, EBSCO Industries

Security continues to become more and more critical in today’s post-pandemic world. While security has to grow and mutate to support new and rising threats, it’s interesting to look back at the changes that occurred as a result of the Covid pandemic. Covid shifted security into fast-forward mode for a number of reasons that I want to highlight below.

The mandate of working from home due to the Covid pandemic placed a spotlight on the need to ensure employees and contractors were able to access resources safely and securely and this need is now an expected entitlement for most employees and contractors. In other words, people needed to get to data from anywhere safely and securely. For those companies that had moved critical systems to the cloud, Covid did not disrupt business as much as others. But many businesses had not and still have not made the move to SaaS-based solutions or to cloud environments. The sudden need to adjust for full time remote access put a strain on many support teams, including security.

When the lockdowns started in 2020, not everyone had a laptop. Not everyone worked from home. Not everyone had software and licenses in place to address all employees and contractors working remotely. Some organizations required corporate equipment for any access to information. So many people didn’t work from home. Employees did not have equipment in place for a home office. All of this placed a burden on infrastructure teams to get equipment in place. Equipment shortages occurred. Shortages for specific components grew with this demand and the fact that manufacturing output was reduced due to illnesses and lockdowns. But it also put a burden on security to monitor and protect the changes.

Covid spotlighted the need to have multi-factor authentication (MFA) in place. Companies could no longer rely on just an id and password for access. Too many employees did not take password etiquette seriously, providing bad actors an easy path through brute force to infiltrate networks. It’s not a coincidence that ransomware rose and still continues to rise.

End users were the target of attackers and end user education needed to improve. Implementing MFA helped. But making sure employees didn’t acknowledge illegitimate requests was also needed. With workers not interacting in person, attackers used phishing attempts to try and extract credentials and/or data from end users. Phishing campaigns needed to grow across businesses to help mitigate this threat vector.

Collaboration tools were not ready for prime time when Covid lockdowns took place. The sudden need for video forced companies to get products like Teams and Zoom in place as quickly as possible. Security vulnerabilities popped up because vendor software had vulnerabilities that needed to be addresses and many companies did not properly educate users on the need to limit who could access their video sessions. It didn’t take long before vendors and corporations started tightening security to protect their customer’s information.

Monitoring teams had to make adjustments to address the expansion of the office space to the home. Application vendors added and continue to add features to help with threat monitoring. Impossible travel (when a user logs in from more than one place in succession and there is no way the person could travel that distance in that period time) became a common vector to watch. Geofencing also increased to reduce external attackers. But the focus continued not be the endpoint that was no longer in the office.

Endpoint protection became much more important now that machines were not sitting in hardened corporate offices. Ensuring proper cloud-based EDR/XDR solutions to protect workstations were more important than ever. Having a way to monitor and ensure hardware and software patching took place also required changes. Many companies had used internal servers/services to make this happen and because computers were not being brought into the office, these patching processes were failing. 

Whether companies had the tools and technology in place, Covid caused changes in processes. One foundational area of security that needed to adjust was Governance, Risk and Compliance (GRC). GRC also had to be involved to ensure new procedures were included in corporate policies. New exceptions occurred and had to be documented to determine risk.

Because of the rise in ransomware before, during and after the Covid pandemic, cyber insurance companies made adjustments in how they wrote insurance. With remote access increasing, insurers started asking more detailed questions and wanted more visibility about company security. Requirements such as MFA for any Internet/external facing applications were expected and rates were increased when the applicants admitted to not having it in place. The same also occurred with local administrative access on workstations. Even insurance companies realized an increased threat with employee endpoints residing outside the safe confines of the corporate office.

Many of the items highlighted above would be addressed over time as businesses adjusted to the changes. Covid caused all of these areas to be changed all at the same time. For those companies that have weathered the storm, they should look back and be proud of the work they accomplished. For those who are reading this article and are realizing they still have work left to do, you need to make time to catch up or you may be next victim to a security event. 

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.