Which Industries Suffer Most From Remote Working?

The specialist security firm Specops Software has surveyed 2,043 business owners across 11 different sectors to discover which sector had the highest number of cybercrime threats or attempts since employers have had to work from home.
 
They discovered that 41% of employees have not been provided with adequate cyber security training whilst working from home. They also found that 54% of business owners have seen a rise in cyber-crime threats, with every sector reporting phishing as the most prevalent attack attempt since COVID-19. Despite this, 52% of businesses would consider a switch to permanent remote working for employees.
 
The US has fallen victim to a huge 156 separate ‘significant’ cyber-attacks in the period between May 2006 and June 2020. Significant attacks include assaults on a country’s government agencies, defence departments, or prominent high-tech companies, and which feature coordinated attacks which incur economic losses totalling more than a million dollars.
 
For the US, this equates to an unenviable average of 11 significant cyber-attacks targeting its government or high-value infrastructures every year.
 
Britain is the second most frequent target of “serious” cyber-attacks according according to the Specops Software report, with 47 such attacks from May 2006 to June 2020, one of which was the large scale cyberattack deployed across the Labour Party’s digital platforms during the 2019 general election.
 
Cybercrime threat rates by sector since lockdown vary significanty and some sectors hav experienced notable increases in cybercrime threat levels:      
 
  • Computer and IT                   -  78%
  • Medical and Health               -  73%
  • Accountancy, Banking           -  67%
  • Charity and Voluntary Work   -  62%
  • Customer Service                  -  55%
  • Marketing, Advertising, PR    -   53%
  • Legal Services                       -  47%
  • Recruitment and HR              -  44%
  • Creative Arts and Design       -  43%
  • Education and Training          -  36%
  • Travel and Hospitality             -  31%
Almost 4 in 5 (78%) business owners in the computer and IT sector have reported an increase in threats since lockdown, although, working from home still appears to be a viable option for many, as 85% of employers in this sector would consider permanent remote working.
 
It might be no surprise that  67% of those in the accountancy, banking and finance sector have seen a huge increase in threats, making them the third most likely sector to encounter cyber-attacks whilst working remotely.
 
The sector least likely to encounter cybercrime threats whilst working from home is the travel and hospitality sector, with only 31% noting an increase.
 
More than 7 in 10 (73%) businesses in the medical and health sector have reported an increase in cybercrime threats since lockdown began. The sector is still highly vulnerable and concerned about future attacks. Therefore, only 32% of businesses in this sector would consider remote working for employees. 
 
The biggest security concerns across the businesses surveyed during lockdown are: 
 
  • Ransomware – 96% 
  • Crypto jacking – 74%
  •  Phishing – 67%
  • IoT attacks – 48% 
  • Cyber attacks  against hardware – 39%  
Specops Software offers the following advise on how  about how businesses with significant reliance on remote workers can stay safe:
 
1. Make use of tools that can check your current passwords for ones that are on existing breached lists. Encourage users that are using breached passwords to change them.
 
2. Encourage the use of passphrases e.g. 3 random words, block the use of any breached passwords and if you are planning on increasing expiry times to avoid the “cached password” issue, look at using these longer expiry times as a way of rewarding the use of passphrases. Also consider reducing complexity as a balance for increasing the length to try an avoid users writing passwords down on post-it notes.
 
3. Another common attack vector post COVID-19 , are social engineering attacks on service desk staff. Users are no longer able to visit IT departments in person and maybe calling from public numbers rather than internal, so making sure that your service desk is actually speaking to “Susan from Accounts” and not a hacker is very important, the days of being able to “recognise the voice” isn’t a viable option any more.
 
4. Don’t forget to enable disk encryption on all devices that handle corporate data, this includes mobile devices, and use restrictions to block logins from disallowed countries or non-compliant devices.
 
5. Don’t forget the basics, make sure you have backups of all business-critical data. Make sure you test the backups and make sure you store those backups in a secure location and in an encrypted state. Review permissions to sensitive data both in the cloud and on prem, to make sure that the right people have the right access to the right data.
 
SpecOps Software:       Techround:         ITProportal:        Security Brief
 
You Might Also Read: 
 

Easing Out Of Lockdown: Why Should Cyber Security Remain High On The Agenda?:

 
« Six Reasons To Move Your SIEM To The Cloud
Australia's Cyber Security Plan Includes Domestic Surveillance »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

AuthenTrend

AuthenTrend

AuthenTrend provide biometric authentication products to achieve high security with extreme ease-of-use for the user.

Deep Instinct

Deep Instinct

Deep Instinct provides comprehensive defense that is designed to protect against the most evasive unknown malware in real-time, across an organization’s endpoints, servers, and mobile devices.

Inogesis

Inogesis

Inogesis helps blue-chip organisations harness disruptive technologies and thinking to drive new revenues or overcome challenges by connecting them with dynamic small companies.

Spherical Defense

Spherical Defense

Spherical Defense offers an alternative approach to WAFs and first generation API security tools.

MagicCube

MagicCube

MagicCube is a device independent IoT security platform that protects against on-device, cloud, and network attacks.

Deduce

Deduce

Deduce use a combination of aggregate historical user data, identity risk intelligence, and proactive alerting to deliver a robust identity and authentication solution.

Advantio

Advantio

Advantio offers a unique combination of technologies and managed, advisory and testing services to increase your cyber resilience and compliance.

Retruster

Retruster

Protect your users against phishing emails, ransomware & fraud with the most advanced, user-friendly, non-intrusive solution available.

Antigen Security

Antigen Security

Antigen Security is a Digital Forensics, Incident Response and Recovery Engineering firm helping businesses and service providers prepare for, respond to, and recover from cyber threats.

Questex Asia Total Security Conference

Questex Asia Total Security Conference

Questex Asia’s Total Security Conferences is one of the industry’s most prestigious and engaging forums for the region's top information security leaders and business decision-makers.

Saiflow

Saiflow

SaiFlow provides a tailor-made cybersecurity solution for Electric Vehicles Charging Infrastructure (EVCI), Distributed Energy Resources (DERs) and energy networks and assets.

Salus Cyber

Salus Cyber

Salus is a provider of world-class cyber security services, enabling our clients to identify and manage their cyber risks proactively and effectively.

Vercara

Vercara

Vercara offers a purpose-built, global cloud security platform that provides layers of protection to safeguard businesses’ online presence, no matter where an attack comes from or where it is aimed.

Theta

Theta

Theta is a New Zealand owned technology consultancy. Our team of over 330 experienced professionals help organisations transform with technology.

Eclypses

Eclypses

Eclypses has a disrupting cyber technology, offering organizations an advanced data security solution called MicroToken Exchange (MTE).

Cyberagentur (Cyber Agency)

Cyberagentur (Cyber Agency)

Cyberagentur is the Federal Agency in Germany for innovation in cybersecurity. Our mission is to advance research and groundbreaking innovations in the field of cybersecurity and related technologies.