# The importance of information security in a post-pandemic hybrid working world
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-10-21
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Protecting Your Organisation: Essential IT Security Measures
Meta Description: Learn how to safeguard your organisation against cyber threats when employees work from home. Multi-factor authentication, antivirus software, and strong
URL: https://financedigest.com/the-importance-of-information-security-in-a-post-pandemic-hybrid-working-worldhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/business-man-using-laptop-computer-in-board-roommyvlq9ho-sbi-300023018-1736837532262-compressed.jpg)

_By **Andy Bridges,** Data Quality & Governance Manager at data and insight agency_ _REaD Group_ _._

According to a recent [survey](https://employeebenefits.co.uk/75-employees-hybrid-working-model/), 75 percent of employees want a hybrid working model while [another](https://www.peoplemanagement.co.uk/news/articles/one-in-four-firms-continue-allow-working-from-home-poll-finds) has found that one in four businesses intend to allow their staff to work from home at least some of the time, once the UK gets back to some type of normality post-pandemic.

While this may be music to the ears of many employees, it certainly won’t be for their organisation’s IT and Information Security teams. For many organisations, this means a shift from 99% office capacity and essentially managing the security of one site to managing multiple sites: that of employees’ homes. And in turn this increases the security risk, as multiple entry points to any organisation’s infrastructure are the stuff of headaches for those in charge of protecting the business.

**Under attack**

The internet influences both our personal and business lives so there will always be a risk or possibility that security is compromised, especially as more employees work from [home and now use work laptops for personal](https://www.financedigest.com/to-be-a-young-person-and-own-your-own-home-should-be-a-dream-that-everyone-has-the-right-to-fulfil.html "“To be a young person and own your own home should be a dream that everyone has the right to fulfil.”") use. Even though organisations allow this, there still [must be sensible level](https://www.financedigest.com/2016-must-be-the-year-of-board-level-transparency-and-good-governance.html "2016 must be the year of board level transparency and good governance") of restriction put in place, and employees need to understand the expectations and acceptable use of company equipment.

One of the biggest and growing threats is phishing emails: the volume of phishing [increased 22%](https://www.phishlabs.com/blog/new-quarterly-threat-trends-intelligence-report-now-available/) this year compared to the first half of 2020, while HMRC experienced a [73% rise in email phishing attacks](https://www.infosecurity-magazine.com/news/hmrc-growth-email-phishing-attacks/) from March to September 2020. And of course, this doesn’t include the many other forms of [cyber threats](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats") such as ransomware, crypto mining, viruses, Trojans, spyware… the list goes on.

So how can you mitigate against this and ensure employees have been given the right tools and appropriate information to spot these [threats and defend](https://www.financedigest.com/how-can-finance-defend-against-the-cyber-threat-educating-staff-is-key.html "How can finance defend against the cyber threat? Educating staff is key") themselves?

[**Protection solutions**](https://www.financedigest.com/kb-kookmin-bank-launches-the-worlds-first-combined-payments-and-messaging-app-protected-by-the-trustonic-application-protection-solution.html "KB Kookmin Bank launches the world’s first combined payments and messaging app protected by the Trustonic Application Protection solution")

Multi-factor or two-factor authentication is a no brainer, because it adds another level of protection in addition to [user passwords](https://www.financedigest.com/ai-is-the-new-password-security-and-ease-for-finance-users.html "AI is the new password: security and ease for finance users "), making it much harder for hackers to break into user accounts. In fact, the majority of company systems will now require some form of authentication, and even Google is [getting in on the act](https://www.cnet.com/tech/services-and-software/google-signs-up-150-million-people-for-two-factor-authentication-what-it-is-how-it-works/) to protect the personal information of 150 million users against hackers and fraud, showing the usefulness of this as a tool.

In addition, ensuring antivirus software is up-to-date and [protecting every machine connecting to the organisation](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") is good basic housekeeping. This ensures malware and other viruses can’t infect a user’s equipment.

Password or passphrase complexity is often overlooked but it is a [key factor in security](https://www.financedigest.com/nine-key-factors-to-maintaining-payment-security-compliance.html "Nine key factors to maintaining payment security compliance"). The average time to crack an eight-character password is five hours, so essentially eight characters will not [protect any employee](https://www.financedigest.com/how-to-protect-your-employees-mental-health-while-remote-working.html "How to protect your employees’ mental health while remote working"). To combat this, passwords of 12 – 18 characters and upwards [moves the time](https://www.financedigest.com/move-over-tina-its-time-for-tara.html "Move over TINA, it’s time for TARA") required to crack them into centuries.

[Security frameworks such as ISO27001 – a well-respected information security standard](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") – are good certifications that ensure an organisation’s information and data assets are secured by establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). And it is worth remembering that [information security](https://www.financedigest.com/privacy-vs-security-is-the-cybersecurity-information-sharing-act-beneficial.html "PRIVACY VS SECURITY: IS THE CYBERSECURITY INFORMATION SHARING ACT BENEFICIAL?") is a business objective not an IT problem. In addition, a security standard relays trust and confidence not just to internal employees but also to an organisation’s client that the organisation has a robust ISMS and the correct procedures in place to [manage](https://www.financedigest.com/managing-the-hidden-security-gap-in-financial-services-the-office-printer.html "MANAGING THE HIDDEN SECURITY GAP IN FINANCIAL SERVICES: THE OFFICE PRINTER") information security.

**The role of the employee**

But it’s not just technology that has a [role to play](https://www.financedigest.com/why-the-bank-branch-still-has-a-role-to-play-for-consumers.html "Why the bank branch still has a role to play for consumers"). Staff training and awareness is also a critical tool in the line of defence.

Staff awareness: The human factor is always the weakest link so it is vital employees have been trained and can spot the warning signs of a [security attack](https://www.financedigest.com/2018-it-security-predictions-methods-for-attacks-investment-areas-cybersecurity-strategies.html "2018 IT Security Predictions-Methods For Attacks, Investment Areas & Cybersecurity Strategies"). This can be done in many forms: a great start is to set up an awareness initiative or programme and to ensure this is presented at regular intervals, so it remains fresh in every employee’s mind. It is always a good idea not just to train employees on internal [security practices but to also look at cyber](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") awareness programmes. Many of these offer additional benefits which allow organisation to set up their own internal phishing test to determine how effective the training has been and, if required, where or which employees [need additional](https://www.financedigest.com/need-additional-funding-but-not-sure-how-to-go-about-it.html "Need additional funding but not sure how to go about it?") training, help and support.

[Remote working](https://www.financedigest.com/7-tips-for-building-a-positive-remote-work-culture.html "7 tips for building a positive remote work culture") policy: This allows all staff to know and understand what the expectations are when remote working, by setting out purpose and scope, guidelines, technical support, security and confidentiality rules.

Incident management: This allows staff to raise what they believe might be a [security incident](https://www.financedigest.com/uks-morgan-advanced-materials-reports-cyber-security-incident-on-its-network.html "UK’s Morgan Advanced Materials reports cyber security incident on its network"). It doesn’t matter how minor or major it might be in the eyes of the employee: the [security team needs](https://www.financedigest.com/the-financial-services-industry-needs-to-get-serious-about-cyber-security-in-the-covid-19-era.html "The financial services industry needs to get serious about cyber security in the Covid-19 era") to be made aware from the outset. This will also allow them to [reduce the overall impact of incidents and mitigate against damages and access risks](https://www.financedigest.com/how-can-you-reduce-the-risk-of-fraud-in-b2b-payments.html "How can you reduce the risk of fraud in B2B payments?") or security breaches with immediate effect. This in turn helps to tailor future training to the [needs of employees and the organisation and ensures services](https://www.financedigest.com/top-5-seo-services-you-need-to-succeed-in-2022.html "Top 5 SEO Services You Need To Succeed In 2022") continue to operate as planned.

While the new world of work will undoubtedly [continue](https://www.financedigest.com/despite-return-to-work-virtual-meetings-will-continue-to-disrupt-business-as-usual-in-finance.html "Despite Return to Work, Virtual Meetings Will Continue to Disrupt Business as Usual in Finance") to encompass some form of in-office and remote working practices for the foreseeable future, ensuring that both technical solutions and personnel training are deployed to protect both organisation and employees should ensure that the business remains protected, wherever employees find themselves working.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

