For well over a year, COVID-19 dominated global headlines. The pandemic forced companies and individuals to adopt new practices such as social distancing, surface sanitizing, and remote work. Governments scrambled to protect public health and economic stability. While the world focused on the threats posed by COVID-19, cybercriminals exploited the crisis. These were some of our observations about its cybersecurity impact.
- Our research staff observed elevated phishing, malspam, and ransomware activity as criminals exploited fear surrounding the virus to impersonate trusted brands and mislead employees, contractors, and customers. Individuals downloading COVID-19-related applications were also tricked into installing ransomware. Employers needed to train staff and contractors to exercise greater care when opening links, emails, or documents related to the pandemic. Organizations also needed to ensure their intrusion-detection and alerting capabilities remained operational while large numbers of workers moved off premises.
- Internal defensive-security operations were likely to suffer during the pandemic, impairing the detection of and response to security incidents. Even fundamental processes such as patching became more difficult when corporate computing assets moved into employees’ homes and beyond the immediate reach of security teams. Organizations needed to evaluate their defenses and consider co-sourcing with qualified security consultants where key-person risks existed.
- With employees working remotely and students learning virtually, enterprise VPNs moved from convenience to necessity. Their security and availability became ongoing concerns. We saw a marked rise in requests for VPN configuration assessments and mitigation services. Poor preparation led to VPN misconfigurations that could expose sensitive information to the Internet while making corporate networks vulnerable to denial-of-service attacks. The trend toward using personal computers for official duties created similar risk. Without rigorous mobile-device management, configuration management, and network segmentation, temporary capital savings rarely justified the exposure.
- Organizations had maintained disaster-recovery and business-continuity plans for decades, but many considered only natural disasters, civil unrest, and utility disruption. Some had not been meaningfully revised since Y2K, and very few anticipated the rapid progression of a global pandemic. We saw increased interest, particularly at the enterprise level, in revising those plans to address future pandemics. Companies also benefited from comprehensive risk assessments that considered supply-chain and partner disruption.
- The displacement of workers created two forms of physical-security pressure. Our Red Team practice experienced increased demand for physical penetration testing of offices with reduced staffing and social-engineering tests directed at remote workers. Reduced occupancy, security staffing, and monitoring made many office buildings easier to penetrate. Remote workers seeking a change of scenery could also expose sensitive information or devices while working from public locations and networks.
- Companies around the world reduced their workforces to mitigate financial strain. Restrictions on movement cost individuals and families their livelihoods in many countries. We believed those conditions would inevitably create more cybercriminal activity as displaced and disaffected workers sought new income. Employers conducting layoffs needed to enforce sound exit procedures. As insider-driven incidents continued to rise, retraining and placement assistance could also serve as practical risk-reduction measures.
A year into the pandemic, organizations were still discovering new security implications almost weekly. The threat environment changed rapidly, but the fundamentals of risk reduction and incident mitigation remained relevant. Organizations that examined their controls honestly and adapted their plans were better positioned for the next disruption.