Listen to this episode

How the COVID Pandemic Paved the Way for the Cybersecurity Pandemic

0:0054:38

Recorded May 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig, Erin, and Blake discuss how the COVID-19 pandemic's rushed shift to remote work sparked what Craig calls a cybersecurity pandemic. Craig explains that many companies adopted work from home without bring your own device policies, leaving employees on shared family computers, home operating systems, and outdated equipment, which he compares to a garage door open for hackers.

Craig argues that standardized, company-issued, business-grade equipment gives companies a cleaner compliance foundation, and Blake notes that surprisingly few companies assign devices to staff. Craig also distinguishes consumer VPNs used for privacy from corporate VPNs that bring remote workers back to the office, while Blake recounts hearing that Apple equips remote support staff with hardware firewalls. Craig presents virtualization through remote desktop services, virtual desktop infrastructure, and thin clients as a way to centralize data, ease compliance, and cut costs. Blake and Craig criticize a ruling that, at the time of recording, allowed personal use of work email, citing resource and privacy concerns. Craig closes by describing Petronella Technology Group's four pillars assessment process, which Blake compares to medical testing and contrasts with competitors' reactive approaches.

Worth remembering

Key takeaways

  1. Craig urges companies to define a bring your own device policy specifying which devices employees may use for work and how those endpoints are secured.
    “it's a policy. It's a document that defines what kind of devices can employees use for work?”
  2. Craig warns that letting staff work from shared family computers that may harbor malware is like leaving a garage door open for hackers.
    “That is literally like a garage door open for hackers to come in and just drop nasty ransomware and malware.”
  3. Craig argues that standardizing on business-grade, company-issued equipment gives companies a strong foundation for cybersecurity and compliance.
    “But it's that standardization and that consistency that gives you that strong foundation from an it or a hardware perspective that now goes into cyber because now you've got policies.”
  4. After a ruling permitted personal use of work email at the time of recording, Craig recommends a company policy prohibiting it to avoid resource and privacy problems.
    “For company standpoint, I would try to put a policy in place that basically prohibits that.”
  5. Craig distinguishes consumer VPNs that mask location for privacy from corporate VPNs that securely connect remote workers to office servers.
    “the purpose of the corporate VPN is really to bring you back into the office virtually”
  6. Blake argues every company should explore virtualization because workers remote into company-managed machines and access can be clipped when they leave.
    “I think every company should be exploring virtualization in my mind.”
  7. Craig compares cybersecurity to medicine, arguing companies cannot fix problems without proper testing and diagnosis first through an assessment.
    “you can't fix something unless you run proper tests and diagnosis first, and once you zero in on the problem and find the root cause of it, we can write a prescription of what's the plan of action.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Hackers have no shame.

Any opportunity they think they can exploit will be exploited.

That includes a global pandemic that has taken the lives of millions of people around the world. The death and destruction are of no consequence to these bad actors and with millions of workers working remotely, hackers have a field day.

Did your business go remote to stay afloat? Was your IT Department unable to fully prepare the at-home workers? If so, know that you aren't alone, and listen along to find out what you can do to improve your cybersecurity portfolio.

Hosts : Craig, Erin and Blake

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.