Need for Cyber Security Post Covid-19
CA. Partho Ghosh
The author is a member of the Institute. He can be reached at caparthoghosh@yahoo.com and eboard@icai.in.
“Covid-19 has caused a lot of disruption which also resulted in unprecedented lockdown in various countries. Despite the lockdown, companies across the globe were able to restart their operations through technological changes and remote working. Some companies have already adopted technology and have reengineered their business processes and more will follow with time. These changes in business processes and adoption of technologies for going digital not only bring about greater efficiencies but also give rise to new forms of risks, which needs to be addressed Let us understand the new and changing cyber-risks due to this sudden digitisation in the present and post Covid-19 world, and some ways to mitigate these risks. Read on...”
Introduction
Covid-19 has taken the entire world by surprise and business are also not unaffected by the same. The lockdown across different countries have forced businesses to shut down their offices, and has posed a challenge of continuing operations despite closures of offices.
Businesses who have already adopted digitisation, and had their data centres, servers on cloud and were using SaaS based applications saw comparatively lesser disruption vis-a-vis those who had not gone digital.
Covid-19 has shown that the traditional ways of working are at a greater risk of disruption caused by pandemics, and that businesses cannot afford to continue working with a physical office setup at the core and they need to go digital and reengineer their processes to facilitate remote working in order to reduce if not completely eliminate the loss due to similar disruptions.
In this article, an effort is made to provide an overview on the changes in business processes which are most likely to take place post Covid-19 and its impact on Cyber Security risks and how effectively to mitigate those risk.
Business Processes Being Reengineered
As social distancing becomes the new normal, companies are looking at ways to adopt to remote working. Organisations have already started reengineering business processes, they are moving their data and applications from on-premise to cloud and are automating the workflows to reduce dependencies on paper documents and are trying to go digital. The current situation require organisations to assess their IT infrastructure, for digitisation and facilitation of remote working and need for advanced cyber security solutions.
Most of the organisations lacked adequate Business Continuity Plan or Incident Response Plan, specially the small and medium enterprises and those who had, did not anticipate and plan for the scale of disruption as being faced today due to Covid-19. The organisations will now be forced to understand the criticality of Business Continuity Plan and Incident Response Plan and accordingly need to make plans for. Digitisation and use of Information technology is going to be a critical part of the same.
Post Covid-19, digital transformation at companies will accelerate dramatically. We have already seen changes in education and healthcare sector with the spurt in online education and emergence of telemedicine services.
Companies are looking at the effectiveness of remote working/ work from home (WFH) concept, and are digitising their records and developing remote working capabilities to insulate its operations against any similar disruptions. Virtual meetings have become the new norm and webinars has taken the place of seminars and people are using video conferencing tools for the same. The management is continuously deliberating on the ways of reducing physical contact for completion of tasks and cloud applications are gradually replacing legacy systems.
Covid-19 is in the process of revolutionising the business process like never before, and these changes are not going to be temporary in nature rather they will be the new normal.
Risks Associated with Remote Working and Digitisation
With more and more businesses adopting to digitisation, the potential number of targets for cyber criminals will also rise. And among these, small and medium enterprises will be the most vulnerable as they often lack the understanding of cyber security risks. SME’s are reluctant to invest in cyber security measures and they think the spending to be an unnecessary expenditure, as they feel they are too small to be a target for a cyber-attack. The lack of security measures leaves them prone to cyber-attacks leading to serious business disruption along with putting financial health and reputation of organisation at stake.
In a remote working environment, physical meeting are replaced with virtual meetings and most of the interactions within team and with clients happens over messaging apps and third-party applications through personal user devices. An organisation usually secures its network against any kind of intrusion and unauthorised access, using network firewalls, intrusion detection systems, etc. However, the personal user devices usually have very limited security features installed in them and are prone to cyber security risks. Mostly used unsecured or less secured networks for connectivity raises such risks. In the absence of adequate security measures, the confidentiality of data can be breached by exploiting backdoors in un-secured applications. In such a situation it is critical that all communications and data are shared through secure communication channels only.
Remote working environment changes the way data is stored and accessed. Factors such as collaborative tools, availability of data on endpoint devices, virtual meetings, remote access of IT assets give rise to additional cyber security threats and businesses who do not have a secure remote access mechanism becomes most vulnerable.
Need for Cyber Security
Cyber risks are dynamic and multidimensional in nature. Most of the organisations also undertake cyber risk assessment as part of their overall risk assessment strategy. However, it must be noted that as far as cyber risk is concerned it is not enough to only review cyber risks twice or thrice a year and it requires a continuous review, as against other categories of business risks.
Owing to changing threat landscape, it is imperative for an organisation to ensure that their IT assets are secure, and data is efficiently protected and managed. Cyber security measures can provide the required shield against such threats.
Measures for Mitigating Cyber Risks
User Awareness Programs
Most of us have this perception that “Cyber Security is all about use of technology”. Though partially correct it’s not completely true. Sensitising the people about the various ways in which cyber-crimes are committed, educating them about security policies of the company, various technological tools available to detect and prevent any security breach is equally important for any Security Policy to work effectively. The staff needs to be made aware of what precautions they need to take while dealing with sensitive data and how to avoid official data misuse.
Intrusion Detection System
These are software applications which works as a detective control and are used for monitoring the network. Intrusion Detection System identifies an unauthorised activity or entry into the network of the organisation and can be used to detect and identify and malicious activity or attacks early.
Encryption
“It is one of the oldest methods used for ensuring that data is available in a meaningful form only to those who are supposed to receive them.”
It is one of the oldest methods used for ensuring that data is available in a meaningful form only to those who are supposed to receive them. Simply put Encryption is the method of converting plain text into cipher text. Encryption uses an algorithm to encrypt the data and recipient can decrypt the same using designated keys. A strong encryption i.e. 128 bits will ensure that even if Cyber criminals are able to capture data in encrypted form, it would me of no use to them as data in encrypted form is not readable.
“A strong encryption i.e. 128 bits will ensure that even if Cyber criminals are able to capture data in encrypted form, it would me of no use to them as data in encrypted form is not readable.”
128-bit encryption is one of the most secure encryption methods and is considered logically unbreakable. Most of the banks are currently using 128-bit to 256-bit encryption.
Multi Factor Authentication
Owing to Social distancing and organisations encouraging their staff to work from home, people will have to remotely access their organisational network or database from their devices. Since people are not physically accessing the resources, the login credentials become the only means to track and monitor the user activity. Traditional usernames and passwords can be stolen despite having a strong and effective password policy, by keyloggers, spywares or social engineering and are also susceptible to brute force attack.
Multi factor authentication (MFA) provides an additional security layer, where cyber criminals even if they are able to obtain the user name and password, they will not be able to breach the security layer due to want of additional credentials such as OTP or passcodes.
Virtual Private Networks
Virtual Private Network is like creating a secure tunnel using the internet to provide a secure connection between the remote user and company’s private network. A virtual private network uses firewall, encryption and other security mechanisms to restrict unauthorised access to an organisations private network and facilitate secure communication/ exchange of data between the remote users and the organisations private network.
Access Privileges
With the reengineering of business processes and increase in the culture of remote working, companies will have no other option but to convert their physical documents into digitised form and store the same in a document repository either on their physical servers or on cloud. Under both the options, all critical, confidential and important data will be stored in the same repository, thereby creating the need to define access privileges, so as to ensure that users can view only those documents, which relates to their work profile and for which they have a permission to access.
We cannot have a situation wherein all the company data is accessible by every user.
Password Management
An organisation should develop a set of principles and guidelines for password management. Following points may be considered while developing a strong password policy:
- Use a combination of alphabet, numbers, and special characters
- Minimum length of password should be defined
- Expiry of passwords after a fixed duration
- Restriction on use of old passwords again
- Use of a secure Password Manager
Backup
“Having a updated backup at a secure and isolated location helps in restricting the spread of the worm into the backup files thus resulting in quicker resumption of business critical operations.”
Backup of user and application data is the most critical aspect of a business continuity plan and can also assist an organisation in cases of ransomware attacks. During 2017, in a worldwide cyberattack a ransomware called “WannaCry” targeted Microsoft windows based operating systems by encrypting data and demanding ransom payments in Bitcoin. As per estimates, millions of systems across 150 countries were impacted by the same. The ransomware made the files unreadable by encrypting them and severely affected the business. Having a updated backup at a secure and isolated location helps in restricting the spread of the worm into the backup files thus resulting in quicker resumption of business critical operations.
Firewalls
These are security systems which monitors and controls incoming and outgoing traffics as per predefined protocols which are configured therein. Firewalls are classified as either network based or host based. Network based firewalls are either software applications or hardware-based firewalls positioned on the gateway. Host based firewalls are positioned within the host and controls network traffic.
Chartered Accountants understand Cyber Security Risks and its impact on business operations. The Institute of Chartered Accountants is conducting webinars and providing e-learning platforms to help professionals gain a deeper understanding into Cyber Security area. Also, the accountancy professionals can employ cyber security professionals to provide additional security services to their Clients. There are ample ways of getting insight on these risks and security measures. It is upto us to take that initiative and prepare ourselves for the upcoming changes so that we are ready to embrace and make efficient use of these new business opportunities.