The Covid-19 pandemic, which has affected the whole world since the beginning of 2020, has reshaped every aspect of life. Business life has been redefined with new normals. While most employees experienced the pros and cons of working from home for the first time, companies also fully tested this new working model for the first time. While many studies have focused on how working from home increased productivity, they have also revealed the negative effects it brought along. Along with all these results It was realized that the transition to the hybrid model creates certain security risks. As many companies around the world and at Turkiye adopt a hybrid work model, the question of how to address the emerging cybersecurity threats has arisen.
Prudential’s special published in March 2021 ’Pulse of American Workers Survey” raporuna göre çalışanların %68’i hem uzaktan hem de ofisten çalışmanın ideal çalışma biçimi olduğunu düşünüyor. Anket sonuçlarına göre %87’lik bir dilim en az 1 gün uzaktan çalışmayı tercih ederken çalışanların yalnızca %13’ü tam zamanlı olarak ofisten çalışmayı seçiyor. Uzaktan ya da ofisten çalışan tüm çalışanların %73’ü I believe that employers should expand remote work opportunities even after the pandemic is over¹. Envoy according to research conducted by, the employees %47’si They state that they are considering looking for a new job if their employers do not switch to a hybrid working model.
Looking at the situation at Turkiye, it appears that many large companies will continue to allow remote work even after the pandemic. Eczacıbaşı Group, Starting July 1, 2021, of its white-collar employees %60’ını announced it will work in a remote or hybrid working model. This new working arrangement“Our address is different, our location is the same”announced with the slogan.
Vodafone Turkiye and their runtime with the hybrid model %60 uzaktan, %40 ofisten announced that it would be reorganized in the way of working, and “We work remotely, we care closely”stated that they adopted the approach of. Turkcell based on the feedback they received during the remote working period in the pandemic,“flexible working model”stated that employees will decide for themselves how much they can work remotely and how much from the office. Similarly Yapı Kredi offering both remote and in-office work opportunities“lean manufacturing”announced that they will continue the system after the pandemic.
ING ise continues to innovate in hybrid working models by redesigning its 2-day work-from-home model, which it has maintained since 2015, allowing employees to choose from 4 different models that suit them³.
The hybrid work model also brings many problems for cybersecurity. Access to corporate resources from off-site channels and the issue of authentication carry the risk of creating security vulnerabilities. In this case, what kind of dangers await companies? What kind of precautions need to be taken?
Eset according to research conducted by global companies %73’ü admits that with the hybrid working model, they are more likely to encounter cybersecurity threats. According to the same research, companies %50’si ise reports cybersecurity threats and what they encountered during this process⁴. WeLiveSecurity, according to research results, one of the most important elements threatening cybersecurity human emphasizes that it is⁵. Google, according to the data it announced in April 2020, within the last week 18 million Covid-19 themed malware He states that he blocked the email. Remote workers become more vulnerable to these threats due to distractions in the home environment, personal computer security vulnerabilities, and difficulties in reaching IT support.
According to ESET's Q3 2020 report, remote workers' RDP (Remote Desktop Protocol) shows that they are under attack⁷. Vulnerabilities in VPN connections and authentication processes threaten the data security of the entire company by targeting remote workers, who are the weak links of companies.
So, what needs to be done to ensure cybersecurity in the hybrid working model?
First Step: Training Employees Against Cyber Threats
Endpoint devices cover all devices that connect to the organization's network over the internet. Computers, mobile phones, POS devices, printers and scanners such as any device connected to the network is an endpoint unit. These devices, used for communication and data sharing, are in terms of the organization's cybersecurity is their weakest point. From a data security perspective, ensuring the security of these units is of vital importance.
The larger the organization, the more endpoints there are. This also means greater risk. If an effective security structure is not built, these geographically dispersed endpoints can create a situation that is difficult to control. At this point, firstly, by training the employees using the units, potential cybersecurity attacks human error It is necessary to protect against. Educating users on how cyber attacks occur is the first step that needs to be taken.
Phishing or e-fraud how their methods are used, how to deal with emails from unknown individuals, and when providing links to services, this link SSL It is very important to explain to end-users some very simple procedures known as primary defense methods, such as how to check via the browser whether it is encrypted.
Step Two: Securing Connections and Services
1. Securing endpoint (user computer) devices
User computers, which are the weakest link, are the devices most vulnerable to viruses, trojans, and other types of attacks.
Linux Using a Unix-based operating system largely eliminates viruses, Trojans, and other intrusion methods. In Linux, system-related files belong to the “root” superuser. Linux source code is reviewed by a technology community. Because it has such extensive oversight, it contains fewer vulnerabilities, bugs, and threats.
2. Ensuring security between the endpoint and the corporate network
It goes without saying that in point-to-point communication, it is necessary to use a communication method encrypted with cryptographic algorithms. This traffic must be isolated and completely separated from other internal networks, or controlled via access control, and necessary logs must be kept on the application or the interface providing the connection.
Using a VPN service will easily close this vulnerability. OpenVPN, is an open-source remote access system that can be used for remote access and runs on almost any kind of hardware.
3. Securing the directory service
Directory services store the information of all users within the company. Therefore, the directory service server is a very critical service provider that handles authentication and authorization within the company.
Of a directory service server
- Security hardening has been implemented,
- Resistant to viruses and threats,
- Performance improvements have been made is expected to be.
Many more things can be added to this list, but essentially, requests made to a server providing any service can be reduced to the above.
SambaBox having such a directory service fulfills all the requirements above. SambaBox is a domestic directory service server developed by Profelis on a Linux basis. For more detailed information about SambaBox, which also hosts many services such as DNS, DHCP, and NTP within itself www.sambabox.io You can reach us at.
You can reduce your attack surface and enhance your cybersecurity by accurately identifying your needs and investing in the right software!
4. Password reset for users
Resetting the passwords of users registered in the directory service always imposes a heavy burden on IT system administrators, especially in companies with a high volume of users. Saving labor, time, and costs requires automating certain services.
None of us want to deal with changing 100 passwords a day!
Users' own passwords SMS, Turkcell BIP, Web Interface being able to reset them via interfaces like prevents IT system administrators from knowing temporary user passwords until the users change their passwords. This process SSPR (Self-Service Password Reset) leaving it to a product like this also provides protection against password theft.
Profelis will soon save you from this trouble as well with the SSPR product it is working on!
In summary, the Covid-19 pandemic has made it necessary to take cybersecurity measures just as much as precautions in working life. As threats multiply and vulnerabilities remain unaddressed, Covid-19 is no longer the only virus to worry about. However, taking precautions is not difficult at all; Profelis is ready to provide all the necessary support tailored to your corporate needs. Take your precautions before it is too late and secure your cybersecurity.
Sources
- https://news.prudential.com/presskits/pulse-american-worker-survey-is-this-working.htm
- https://envoy.com/blog/envoy-survey-finds-employees-want-companies-to-embrace-hybrid-work-and-mandate-covid-vaccines/
- https://www.aa.com.tr/tr/sirkethaberleri/sirketler/is-dunyasi-ofis-disinda-calismayi-sevdi/665923
- https://www.eset.com/int/about/newsroom/press-releases/research/80-of-businesses-worldwide-are-confident-their-remote-employees-have-the-knowledge-to-mitigate-cybe/
- https://www.welivesecurity.com/2021/07/13/hybrid-workplace-what-does-mean-cybersecurity/
- https://cloud.google.com/blog/products/identity-security/protecting-against-cyber-threats-during-covid-19-and-beyond
- https://www.eset.com/int/about/newsroom/press-releases/research/eset-issues-its-q3-2020-threat-report-remote-workers-under-fire-from-rdp-attacks/
[/fusion_text][/fusion_builder_column][/fusion_builder_row][/fusion_builder_container]



