{"id":198639,"date":"2021-03-10T16:00:36","date_gmt":"2021-03-10T13:00:36","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/quick-steps-to-better-home-working-security-cloudsavvy-it\/"},"modified":"2021-03-10T16:00:36","modified_gmt":"2021-03-10T13:00:36","slug":"quick-steps-to-better-home-working-security-cloudsavvy-it","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/","title":{"rendered":"#Quick Steps to Better Home Working Security \u2013 CloudSavvy IT"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6a9b2075209d9\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd3333;color:#dd3333\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd3333;color:#dd3333\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6a9b2075209d9\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/#The_New_Normal\" >The New Normal<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/#Use_Encryption\" >Use Encryption<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/#Harden_Home_Wi-Fi\" >Harden Home Wi-Fi<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/#VPNs_RDP_and_2FA\" >VPNs, RDP, and 2FA<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/#Penetration_Testing\" >Penetration Testing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/#Compliance_and_Standards\" >Compliance and Standards<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/buradabiliyorum.com\/en\/quick-steps-to-better-home-working-security-cloudsavvy-it\/#Wash_Your_Hands_for_40_Seconds\" >Wash Your Hands for 40 Seconds<\/a><\/li><\/ul><\/nav><\/div>\n<p><strong>&#8220;#Quick Steps to Better Home Working Security \u2013 CloudSavvy IT&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 700px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-10081 size-full\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/9f3ddbaae65b95fe614a42571a70044e\/p\/uploads\/2021\/03\/42bf4b40.png\" alt=\"\" width=\"700\" height=\"350\" data-crediturl=\"https:\/\/www.shutterstock.com\/image-photo\/work-home-man-works-on-laptop-1681318753\" data-credittext=\"Shutterstock\/Sharomka\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/work-home-man-works-on-laptop-1681318753\">Shutterstock\/Sharomka<\/a><\/span><\/figcaption><\/figure>\n<p>The new normal involves fewer people in offices and more people working from home. Full-time or part-time, much of the workforce now work remotely. That introduces a new set of security challenges.<\/p>\n<h2 id=\"the-new-normal\"><span class=\"ez-toc-section\" id=\"The_New_Normal\"><\/span>The New Normal<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>There\u2019s a reason security professionals hate sudden changes, especially those of a drastic nature. The risk of a vulnerability being introduced because something was overlooked or someone acted in haste\u2014albeit with best interests at heart\u2014is all too real.<\/p>\n<p>The COVID-19 pandemic brought just such a change to most organizations. Workers were forced to stay at home and work remotely. Companies\u00a0that had some remote working capabilities had to try to quickly scale that up. Other organizations had to try to put something together as fast as possible. Security rarely comes first in these scenarios.<\/p>\n<p>Needless to say, businesses that had no remote working capability whatsoever were the least prepared to cope with the change. Having no remote working capability meant there were either none or very few laptops in the business. Many of them had to let home workers use their own, domestic, computers to work on.<\/p>\n<p>The IT department\u2014which suddenly found itself distributed and working from home\u2014now had to support an IT estate that had mutated overnight to include out-dated and unsupported operating systems, home routers, and hardware from any number of manufacturers.<\/p>\n<p>If any of that sounds familiar, here are some effective steps to bring some security back into the situation.<\/p>\n<h2 id=\"use-encryption\"><span class=\"ez-toc-section\" id=\"Use_Encryption\"><\/span>Use Encryption<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A security-conscious organization will already encrypt portable and mobile devices such as laptops, tablets, and smartphones. On corporate PCs it\u2019s easy to do, and free\u2014as long as you are on the correct version of Microsoft Windows. Microsoft Windows 10\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/redirect.viglink.com?u=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fwindows%2Fdevice-encryption-in-windows-10-ad5dcf4b-dbe0-2331-228f-7925c2a3012d&amp;key=204a528a336ede4177fff0d84a044482\">Pro, Enterprise, and Education<\/a>\u00a0support\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/redirect.viglink.com?u=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fwindows%2Fturn-on-device-encryption-0c453637-bc88-5f74-5105-741561aae838&amp;key=204a528a336ede4177fff0d84a044482\">BitLocker device encryption<\/a>. Windows 10 Home does not. By contrast, if you use an <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le computer macOS supports device encryption by default, and\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/support.apple.com\/en-gb\/guide\/mac-help\/mh11785\/mac\">right across the board<\/a>.<\/p>\n<p>Encrypting your computer protects your data from access if the device falls into the wrong hands. Even if the threat actors remove the hard drive and try to read it on another device, they\u2019ll be thwarted.<\/p>\n<p>However, a different kind of risk exposure occurs when files are transmitted electronically. If they are intercepted by threat actors, they\u2019ll be able to read them unless they are encrypted before they are transmitted. This is easy to do. All the\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/redirect.viglink.com?u=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fprotect-a-document-with-a-password-05084cc3-300d-4c1a-8416-38d3e37d6826&amp;key=204a528a336ede4177fff0d84a044482\">Microsoft Office products<\/a>\u00a0allow you to save your files with a password. This encrypts them, protecting them from prying eyes.<\/p>\n<p>Other applications may not offer that facility. If you use a software package that doesn\u2019t offer encryption from within the application you can still encrypt the files before sending them. Use a free utility such as\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.7-zip.org\/\">7Zip<\/a>\u00a0or one of the other archiving applications to compress your files and encrypt them with a password. It also reduces the size of the files, reducing transmission time and storage requirements.<\/p>\n<p>Zipping files is a great way to encapsulate collections of disparate files that were created with different software packages that have to be distributed as a parcel of related documents. Compressing them into a single file means you only need to send someone that one file and you know they\u2019ve got the entire set of files.<\/p>\n<p>Communicate the password to the recipient using a different medium\u2014or at least, a different message\u2014than the one carrying the files. And don\u2019t re-use passwords or make them predictable or formulaic. Don\u2019t use a client\u2019s name and the date, for example.<\/p>\n<p>For users with ancient versions of Windows, you might as well let them take their office computer home. If you don\u2019t, it\u2019ll only sit unused in an empty office, depreciating. Why not let them use a current, secure device that is known to your IT team, is on your hardware asset register, and that you can exert total control over?<\/p>\n<h2 id=\"harden-home-wi-fi\"><span class=\"ez-toc-section\" id=\"Harden_Home_Wi-Fi\"><\/span>Harden Home Wi-Fi<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Domestic Wi-Fi can be secure but it is often not set up that way. Start a project now to have your IT team work their way through the home workers, making sure the default router administration credentials have been changed, that secure and robust passwords are in use, and updating the firmware.<\/p>\n<p>Ensure the most secure protocol that the device offers is being used and change the password to a unique, secure password. This means friends and visitors won\u2019t be able to get onto the Wi-Fi when they visit, which is the point.\u00a0If the device supports it, create a guest Wi-Fi so that family and friends can get onto the internet. They\u2019ll get the access they need, be segregated from the main Wi-Fi, and won\u2019t need to get the private Wi-Fi password.<\/p>\n<p>You could consider hiding the main Wi-Fi network altogether, but most home users will find that a problematic system to live with. The same goes for\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/MAC_filtering\">MAC address filtering<\/a>, sadly.<\/p>\n<p>Turn on the firewall, and check the firewall rules If the router is archaic, replace it.<\/p>\n<h2 id=\"vpns-rdp-and-2fa\"><span class=\"ez-toc-section\" id=\"VPNs_RDP_and_2FA\"><\/span>VPNs, RDP, and 2FA<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Use encrypted secure communication methods, such as\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Virtual_private_network\">Virtual Private Networks<\/a>\u00a0(VPNs) or Microsoft\u2019s\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Remote_Desktop_Protocol\">Remote Desktop Protocol<\/a> (RDP). Or, more strictly speaking, they\u2019re secure when they are patched up to date and everyone uses unique and robust passwords. Make sure you limit the number of attempts before an account is locked out.<\/p>\n<p>Wherever it is supported, implement <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Multi-factor_authentication\">two-factor authentication<\/a> (2FA) or multi-factor authentication (MFA). Use systems that have authenticator applications or devices that generate codes. Systems that use\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/SMS\">Small Messaging System<\/a>\u00a0(SMS) text messages are less secure.<\/p>\n<p>If your workforce use cloud-based services, remember that many of these will be able to provide two-factor authentication at no extra cost. Turn it on, and leverage those free features to your advantage.<\/p>\n<h2 id=\"penetration-testing\"><span class=\"ez-toc-section\" id=\"Penetration_Testing\"><\/span>Penetration Testing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Threat actors are many things, but they\u2019re not dumb. They know that there has been a ground shift in working habits and that the workforce is now remote and accessing IT resources in the main office remotely.<\/p>\n<p>They also know that many organizations had to establish their remote working solutions as fast as was physically possible. And they\u2019ll know that very few of them will have been revisited. So the security no-no\u2019s and botches that were ignored when the C-suite was screaming to \u201cjust get it working\u201d will still be present.<\/p>\n<p>Be pro-active. Have penetration testing conducted on your organization before the cybercriminals do. Have the testing done, review the results, and deal with the worst vulnerabilities straight away.<\/p>\n<p>Prioritize the remainder and work through them in order of severity.<\/p>\n<h2 id=\"compliance-and-standards\"><span class=\"ez-toc-section\" id=\"Compliance_and_Standards\"><\/span>Compliance and Standards<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The change of working environment and practices mean a lot of your processes and procedures will need amending. Your governance will need to be reviewed to make sure that the guidance and controls placed on staff still make sense and still apply in the new situation. If they need amending or updating, have that done as soon as possible.<\/p>\n<p>In particular check your password policy, your acceptable usage policy, and your rules about data storage and transmission. The change to homeworking may have contravened existing rules about taking IT equipment home, not connecting to domestic networks, only accessing corporate resources from corporate computers, and so on. It\u2019s vital that staff understand what rules still apply, which have been superseded, and by what.<\/p>\n<p>Remember to review your standards certifications and accreditations. If your organization has achieved compliance with any standards such as <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.iso.org\/isoiec-27001-information-security.html\">ISO 27001<\/a>, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/iasme.co.uk\/cyber-essentials\/about-cyber-essentials\/\">Cyber Essentials<\/a>, or the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.nist.gov\/video\/cybersecurity-framework-0\">Cybersecurity Framework<\/a>, the IT estate that you described, documented, and created processes for no longer exists. You need to bring all of your governance in line with the new situation.<\/p>\n<p>Data protection legislation will need to be reviewed to see how they map onto your current data processing activities. If you make changes to your data protection policies and procedures make sure you update your Privacy Policy so that data subjects are informed of the changes.<\/p>\n<h2 role=\"heading\" aria-level=\"2\"><span class=\"ez-toc-section\" id=\"Wash_Your_Hands_for_40_Seconds\"><\/span>Wash Your Hands for 40 Seconds<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Like other hygiene regimes that are critical at present, remember your basic cybersecurity hygiene too. Getting the basics right will go a long way to winning the battle.\n<\/p><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.cloudsavvyit.com\/10049\/quick-steps-to-better-home-working-security\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Quick Steps to Better Home Working Security \u2013 CloudSavvy IT&#8221; Shutterstock\/Sharomka The new normal involves fewer people in offices and more people working from home. Full-time or part-time, much of the workforce now work remotely. That introduces a new set of security challenges. The New Normal There\u2019s a reason security professionals hate sudden changes, especially&#8230;<\/p>\n","protected":false},"author":1,"featured_media":198640,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/9f3ddbaae65b95fe614a42571a70044e\/p\/uploads\/2021\/03\/42bf4b40.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-198639","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/198639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=198639"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/198639\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/198640"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=198639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=198639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=198639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}