Apply caution and common sense to your inbox
Links.. Documents should be cautiously handled. Risks will be exacerbated by the simultaneous relaxing of security controls in order to facilitate the use of non-standard web conferencing software and the sharing of files by email. Attackers will have both the opportunity and the means. MFA a must.
Expanding Threat Landscape
Employees suddenly taking their work computer home with them will find themselves stripped of protection as they trade the office network for their home Wi-Fi. Without internet proxy, NAC, IDS and NGFW, client devices will now be sitting exposed on potentially unsecured networks amongst potentially compromised devices. Endpoint security will have to bear the full brunt of protection. Internal network security may be compromised as well; employees might need access to resources previously only accessible on a wired network in one location. To make it reachable over VPN, internal segmentation might need to be flattened. This will open the door to malware spread and lateral movement. Client certificate authentication protecting web services might need to be turned off to enable BYOD working for employees that don’t have a company laptop. These changes must be scrupulously logged, and dependencies understood. The extra weight will have to be carried elsewhere: perhaps host AV policies can be tightened to compensate for lack of network protection, perhaps employee devices can be reconfigured to use a secure external DNS provider instead of the on-prem DNS server.
A new wave of attacks
Beyond the weakening of existing controls, spinning up new infrastructure will bring fresh risks. In January we saw a spate of attacks on web-facing Citrix infrastructure. Companies will be rapidly deploying VPN gateways, transitioning to Sharepoint and expanding their internet-facing perimeter. This rapidly increased attack surface will need monitoring and protecting. Security teams should be on heightened alert for brute force and server-side attacks. DDoS protection will also become more important than ever; for many companies this will be the first time that a DDoS attack could cripple their business by preventing remote workers from accessing services over the internet. We should expect to see a sharp rise in both of these forms of attack immediately.
Don’t make rash decisions
Both IT and individual employees will face blockers. There won’t be an authorised solution for their needs, and those needs may well be extremely urgent. At a time when businesses are extremely worried about their financial position and ability to operate, there will be pressure to throw caution to the wind and protect ‘business as usual’. This pressure may even come from the top. Security leadership must do the best they can to both push back against rash decisions and provide creative solutions. Well-meaning employees will get creative, and responsibility will be delegated to team leaders to “do what it takes”. It may be impossible for security to police this centrally but monitoring vigilance will be required to spot risky behaviour and non-compliance.
This is easier said than done; the SOC will be asked to monitor for incidents in a sea of change. Existing use-cases and rules will not apply, and companies will need a more proactive and dynamic approach to detection and response.
Your home is a business’ zero-trust environment
Unfortunately, there will be some within our companies that want to kick us while we are down. Sudden remote working is a godsend to malicious insiders. Data can now be easily taken from a company device over USB within the privacy of their own home. Security monitoring may be crippled or disabled entirely. This risk is harder to address. It may not be eliminable, but it can be balanced against the need for productivity and access to data. We should also be wary of those around us. We all hope we can trust the people we live with. But from a company perspective, employee homes are zero-trust environments. Confidential conversations will now be conducted within range of eavesdroppers. Intellectual property will be visible on screens and monitors in living rooms around the country. This risk is greater for younger demographics likely to be house-sharing, but it remains for all workers; delivery men, visitors to the house – they could all potentially steal a company laptop from the kitchen room table. Education of employees in particular risk groups will be key.
Adjusting to the new normal
Autonomous Response technology can also surgically intervene to halt malicious activity when teams can’t be there to stop it, protecting devices and systems whilst allowing essential operations to continue unaffected.
All of the above changes and risks create a monitoring nightmare for SOCs. We are entering into a period of digital unknown, where change will be the new normal. Data flows and topology will change. New technology and services will be deployed. Logging formats will be different.
The SIEM use-cases that took 12 months to develop will need to be scrapped overnight. For the next few weeks, business practice will shift rapidly. Static defences and rules will not be able to keep up, no matter how diligently and rapidly we rewrite them. Companies need to leverage technology that can allow them to continue to operate amidst uncertainty without choking productivity at this critical time.