Security of data processed in the time of remote operation in terms of the threat of cyber attacks and the need to clarify cybersecurity rules
Back to the insights archive
Publications

Security of data processed in the time of remote operation in terms of the threat of cyber attacks and the need to clarify cybersecurity rules

Forced by the epidemic COVID-19 changing the working mode from fixed to remote does not leave any illusions as to the fact that the increase in cyber attacks on processed data in enterprises has its source in insufficient safeguards and lack of employee awareness of the risks lu...

Forced by the epidemic COVID-19 changing the working mode from fixed to remote does not leave any illusions as to the fact that the increase in cyber attacks on processed data in enterprises has its source in insufficient safeguards and lack of employee awareness of the risks lu...

Forced by the epidemic COVID-19 changing the mode of operation from fixed to remote does not leave any illusions as to the fact that the increase in cyberattacks to processed data in enterprises has its source in insufficient safeguards and lack of employee awareness of the threats in cyberspace. It is important that there is no regulation in this area, as the issue of cybersecurity in an era of the COVID-19 epidemic was pushed to the back burner in the face of other priority anti-crisis actions.

The epidemic forced the majority of workers to change their working patterns and perform their work duties from home. Such a change brings many advantages, but it also reveals the negative side of working outside the office.

In addition to obvious advantages such as flexibility and time savings, the lack of the need to move from home to the office, attention should be paid to the risks posed by such a model of work.

Although remote work is nothing new, the scale on which this model was adopted has resulted in increasingly frequent and sophisticated online hacker attacks, and forced the need to increase the security against the company's data leak.

Faced with an epidemic crisis COVID-19 Initially, few companies have taken steps to adapt remote work on such a large scale in terms of cyberspace threats.

The priority was to put in place measures to maintain the financial stability of companies, which did not fully work, as attacks on processed companies caused equally significant financial losses.

Definition of remote work

The concept of "remote work" has been regulated in the so-called crisis shield 1.0.1 , according to which employers were entitled to recommend the performance of the work laid down in the contract of employment, outside the place of permanent performance for a specified period.

This was intended to serve the so-called social distance in connection with the limitation of contact with people while doing remote work from home. Only the passing of the anti-crisis law[2] laid down rules for directing workers to remote work.

On the basis of this, remote work could take place if the worker has the skills, technical capabilities and premises to perform such work.

It is clear that not all work can be done in the context of remote work, but only one that can be done in the ‘use of means of direct communication at a distance or in the performance of manufacturing parts or material services’.

Although the principle is that the employer provides the tools for work, the employee may use his own tools when they provide protection of confidential information, business secrecy and personal data, and also protect information that the disclosure of which could harm the employer.

The public's awareness of cyber attacks is still limited and the employer should not leave the employee free to decide whether he has equipment that is adequately secured at least as in the case of equipment in the office.

Such decision-making freedom may jeopardise the employer if the decision to choose his own equipment is not preceded by prior verification of the employee's equipment in this respect.

EY Global Information Security Survey 20213 , pandemic COVID-19 forced organisations to omit certain stages of security controls in cyberspace. However, in parallel, new technologies and solutions were implemented for customers, enabling remote work. Before considering ways of protecting cyberattacks and regulations in this area, the nature and nature of the most common threats in cyberspace should be indicated.

Types of cybersecurity threats. Statistics

The most commonly used attacks are:

  • 1) bots and viruses that can be installed automatically or are the result of the employee's inadvertently installing such malicious software (so-called Trojans), which is particularly dangerous because it aims to take control of the system and to steal data;
  • 2) hackers, i.e. cyberspace attackers, seeking security gaps to penetrate and control corporate systems;
  • 3) phishing and pharming, or otherwise impersonating a person or an institution, to extort data; phishing acts by using e-mail, in turn pharming redirects to fake web servers;
  1. malware, so-called malware, aimed at taking control of the system without the user's knowledge; government organizations are often attacked through malware and personal data thefts needed to log in to online banking; ransomware, which involves encryption of user data and then in return for payment, decryption of decrypted data;
  2. Man In the Middle, which means an attack involving a person third, intended to intercept information or cash;
  3. DDoS attacks (refused service), i.e. attack on software or website coming at the same time with more than one a computer device intended to paralyze online operations.

According to the Verizon report 2021 Data Breach Investigations Report (DBIR) 4 , where the data from 29,307 events, confirmed 5,258 data breach, including 86% was motivated by financial considerations. This is a significant increase compared to 3.95 confirmed infringements (from 32.002 incidents) from the DBIR report from the previous year.

Phishing is one with the most popular hacker tactics, therefore poses a huge threat and is becoming increasingly widespread every year. Tessian Study 5 to 2021 showed that employees receive average 14 malicious e-mails per year. In the commercial sector, workers received average 49 news like that.

Research by ESET 6 In 2021 showed that the number of attacks based on email messages increased by 7.3%. CISCO Report[7] also confirms that at least one person in ok. 86% organizations clicked on the phishing link and consequently confirms that phishing is the cause 90% data breaches.

The above data gives the basis to claim that these attacks, which use more human vulnerability than technical ones, are the most reliable method of attack among hackers. That is why e-mail security has become so important in terms of potential cyber attacks.

Since the outbreak of the pandemic In 2020 Cybercrime reports increased by 300%. The report by Google and the FBI's online crime complaint center confirmed a significant increase in cyberspace attacks. The daily number of reports was from 3 to 4, While before the outbreak of the pandemic it was ok 1 complaints a day.

IBM studies 8 showed that the cost of data security breach increased with the advent of remote work, as it is estimated that the company may lose even 137 XNUMX USD.

Research on remote work and related cybersecurity threats 9 show that workers performing duties outside the permanent workplace are a major problem. First of all, because cybersecurity was not a business priority in directing workers to remote work, which caused entrepreneurs to suffer losses from malicious software attacks, being forced to pay to avoid stealing data from the company.

In Cisco's annual online report 10 for years 2018-2023 it is indicated that DDoS attacks are becoming increasingly common. Moreover, it is estimated that to 2023 will take place until 15,400,000 attacks worldwide. The number of attacks increases annually by 39%. This shows the scale of threats in cyberspace in the era of remote work, but also the lack of awareness of these threats, mainly among employees.

Cybersecurity rules

The starting point of the reflections will be to say that there are few provisions directly relating to the correlation between remote work and cybersecurity, which should be changed, given the scale on which this model of work has begun to function, and the increase in threats in cyberspace.

Among the provisions to be mentioned First,, is the Data Protection Regulation (GDPR) 11 , which has introduced new obligations on data collectors and processors. It had to do with In the second half 2018 National Cybersecurity Act entered into force 12 . In this state of affairs, data processors and administrators are obliged to apply both the GDPR provisions and the National Cybersecurity System Act. With regard to the provisions of the GDPR, it is indicated that the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security equivalent to this risk, including, inter alia, where appropriate:

  • (a) the pseudonymisation and encryption of personal data;
  • (b) the ability to continuously ensure the confidentiality, integrity, availability and resilience of processing systems and services;
  • (c) the ability to rapidly restore the availability and access of personal data in the event of a physical or technical incident;

(d) regular testing, measurement and evaluation of the effectiveness of technical and organisational measures to ensure the safety of processing 13 .

The safety assessment shall take into account the risks of processing, risks arising from accidental or unlawful destruction, loss, modification, unauthorised disclosure or unauthorised access to personal data transmitted, stored or otherwise processed. The controller and the data processor shall ensure that any person who has access to and acts under their authority processes personal data only at the request of the controller, unless required by Union or Member State law.

Regulation of the Council of Ministers introducing National Interoperability Councils 14 refers directly to remote work, but applies to entities carrying out public tasks. The Regulation requires the creation of basic principles guaranteeing safe working on mobile and distance work, safeguarding information in such a way as to prevent unauthorised disclosure, modification, erasure or destruction, establishing rules for handling information, ensuring that there is a minimum risk of theft of information and means of processing information, including mobile devices, or ensuring an adequate level of security in electronic systems, consisting in particular of:

  • a) care to update the software,
  • (b) minimising the risk of loss of information as a result of an accident,
  • (c) protection against errors, loss, unauthorised modification,
  • (d) the use of cryptographic mechanisms in a manner appropriate to the risks or requirements of the law,
  • (e) ensuring the security of system files,
  • (f) the reduction of the risks resulting from the use of published technical vulnerability of ICT systems,
  • (g) to take immediate action after noticing the undisclosed vulnerability of ICT systems to the possibility of a security breach,

(h) checking the compliance of ICT systems with relevant security standards and policies.

The Regulation also speaks of the need to ensure that internal regulations are updated in relation to the changing environment and the organisation of training of those involved in the processing of information.

It can therefore be considered that these provisions may form a basis for entrepreneurs who are not subject to this Regulation, when creating guidelines for remote work and its impact on the security of the data processed in the company.

Regular training for workers should play a particular role here, as it is they who work from home and do not have direct contact with IT departments that should be aware of the risks and develop certain anti-active behaviours.

Statistics show that this is a human factor and a mistake a man who does not have the right knowledge can put a company at risk. This can be done e.g. by clicking on an unverified link or using an unsecured network, which creates friendly conditions for attacks on the company's processed data.

To a greater extent, EU legislation regulates this issue. That's how it should be pointed out. In 2016 by the European Union NIS Directive 15 dated 6 July 2016, which obliged Member States to introduce appropriate measures and mechanisms in national legislation to ensure the security of digital networks and information systems.

The Directive is first European law on cybersecurity. It has imposed new obligations on Member States, including the obligation to set up specific institutions and to introduce certain cooperation mechanisms. This would lead to a certain awareness and ability to deal with threats in cyberspace.

In Poland the NIS Directive has been implemented Act dated 5 July 2018 about the national cybersecurity system 16 .

The development of digitalisation and the need to increase the protection of cyberspace in Member States has caused the European Commission to 16 December 2020 presented the draft new NIS directive 2 17 , to replace the NIS Directive.

It has been justified that the new draft directive responds to the need to amend EU legislation in relation to the pandemic COVID-19 and an increased number of attacks in cyberspace. The new directive envisages extending the scope of the subject matter to include public administration, industry or waste management and space.

The aim of the new regulation is primarily to ensure cooperation between Member States and to ensure the proper flow of information. The weak side of the NIS Directive was the lack of a harmonised way of implementing the Directive into the Member States, which is to eliminate the NIS Directive 2.

The Directive also provides for increased requirements in terms of management, cybersecurity testing and more effective security of IT data.

An obligation was also introduced to prepare a large-scale crisis and security incident response plan, the so-called incident and crisis response plan, which should include, inter alia, the way information flows and measures aimed at preparing Member States in the event of cybersecurity.

Security of data in cyberspace

According to the report, “2021 Global Security Insights’, 76% Global cybersecurity experts have said the attacks have intensified due to remote workers 18 .

Therefore, entrepreneurs faced challenges resulting from reorganizing the approach to security itself and creating new effective solutions to protect against attacks on processed data in the company.

In the event of an effective attack, the entrepreneur is exposed to loss of sensitive data, financial losses as a result of theft, large costs associated with recovering stolen data, or loss of good reputation.

Action should therefore be taken to reduce the risk of cybercrime, as attacks alone cannot be eliminated, we can only reduce them by individual action.

Among the network security features we can distinguish:

  • 1) development of information security policy,
  • 2) VPN or Citrix, i.e. a private network, allowing secure connection to the Internet by users,
  • 3) two-component authentication (2FA), i.e. a two-stage verification, by authenticating the use of resources through verification on two various devices, e.g. computer and telephone,
  • 4) backup and storage of data on the cloud,
  • 5) training to develop awareness of the threats of attacks on the network and equip employees with the knowledge necessary to identify threats, including anti-phishing training with IT specialists,
  • 6) purchase appropriate insurance, which in case of a hacking attack will cover its losses and provide adequate PR support.

At the beginning of the pandemic, when remote work had not yet been applied on such a large scale, the Personal Data Protection Office presented a list of recommendations that could contribute to increasing data security 19 . He specified the protection of the device itself and e-mail. In terms of the device, he made recommendations:

  • 1) the devices and software provided by the employer for remote work are used for the performance of their duties; the safety procedure adopted in the organisation must be followed,
  • 2) failure to install additional applications and software incompatible with the organisation's safety procedure,
  • 3) make sure that all devices used during work have the necessary updates of the operating system (IOS or Android), software and antivirus,
  • 4) separate appropriate space, so that possible third parties do not have access to the documents they are working on; each time you leave the workplace, you should block the device you work on,
  • 5) the computer must be protected by using strong access passwords, multi-level authentication to limit access to the device and, at the same time, to limit the risk of data loss in case of theft or loss of the device,
  • 6) measures should be taken to ensure that devices used during work, in particular those used for data transmission, as external disks are not lost,
  • 7) if the device used for work or theft is lost, appropriate steps should be taken to remotely clear its memory, if possible 20 .

Regarding the use of e-mail, he made recommendations:

  • 1) follow the applicable rules in the organisation regarding the use of e-mail,
  • 2) use primarily business email accounts,
  • 3) when using a private email, make sure that the contents and attachments are properly encrypted; and avoid the use of personal or confidential information on the subject of the message,
  • 4) be sure to send e-mails to the appropriate addressee, especially if the message contains personal data or sensitive data,
  • 5) check the email sender and do not open the message from unknown recipients, and in particular do not open any attachments and do not click on the links contained in such message,
  • 6) do not e-mail the information encrypted with the password, even in a separate message. Whoever has access to the mail will be able to decrypt the message.

For network and cloud use:

  • 1) use only of trusted network or cloud access and compliance with any organisational rules and procedures for logging in and sharing data,
  • 2) when we do not have access to the network or cloud to ensure that stored data is archived safely 21 .

It is also desirable to provide secure videoconferencing when operating remotely, to use the company software only using encrypted channels (SSL, VPN, iPSec) and, where possible, to provide immediate assistance to the IT department in case of cyber attacks.

Analysis and proposals for amendments

From a HP Wolf Security report 22 it follows that remote work is recommended only if adequate level of network security is ensured.

The report presents the results from the global online survey YouGov that included 8443 office workers performing remote work during the pandemic, and presents data from a survey conducted by Toluna including 1100 IT decision-makers. When examining the data resulting from the report, attention should be paid to several conclusions.

First of all, what the first The plan is the fact that the pandemic caused that the safety theme was not as important as ensuring business continuity during the epidemic.

Almost half of the surveyed office staff aged from 18 to 24 years admitted that security measures were treated as an obstacle, and one third of them, she bypassed the security rules laid down in the company.

Studies have shown that it is more important for workers to keep deadlines at work than to comply with safety rules and to expose themselves to data leakage from the company. Importantly, 39% there is no awareness of how security policy is shaped in their company.

This causes remote work from home to pose a real threat to the employer in terms of hacking attacks due to the ignorance and ignorance of their employees.

It can be assumed that a security team is playing a key role in this situation to ensure data security by updating security rules, given the increase in the number of people working from home and thus increasing the number of hacker attacks.

Remote workers often say that new security measures are too restrictive, and they complain about increased control of their work from their home office.

Therefore, mutual cooperation between safety professionals and workers, who are required to comply with the data protection recommendations, is important even though they are often ignored.

The considerations put forward show that the low level of awareness of the existence of threats, combined with the increase in attacks, in particular phishing and ransomware attacks, makes companies increasingly vulnerable to such threats.

The reason is, for example, use one computer for both private and business purposes, use of wi-fi with unchanged factory data or network security. It is therefore important to educate, train and involve workers on cyberspace threats, making them aware that this is a real threat, especially in the days of remote work.

It is clear that a remote worker has the same obligation to take care of the welfare of the workplace as in the case of fixed work. It must therefore ensure the security of the processed data and use secure links. It must also maintain increased vigilance and caution when using email and do not click on the links of unknown origin.

Nor can it be denied that regulations in Poland have not met the problem caused by the epidemic and the sudden need to introduce remote work on such a large scale, in the context of the security of the data processed. Although the rules indicate that remote work can be done, they say when, but they are still temporary solutions.

There is no regulation on the entry of remote work into the system of work, and this is highly desirable, as it is difficult to imagine that this model will stop working. This would certainly be an impulse to create a regulation on cybersecurity in terms of strict remote work, which would clarify existing indirect rules in this area.

It should be specified under which conditions remote work should be carried out, on which equipment, what conditions it should be, who should assess it.

Attention should also be paid to the system audit itself at a level tailored to the needs of the company, the mandatory and regular training of employees and persons involved in the processing of data, the verification of the level of knowledge and the verification of compliance of their activities with the regulations and guidelines on the security of the company.

Regulations should also be introduced for remote work to define rules for the protection of data processed by workers outside the premises of the company.

Though before the outbreak COVID-19 Remote work has been sporadically occurring, and no legislation has been introduced in this time by introducing this model of permanent work, as opposed to teleworking. It was on the basis of these provisions that employers created internal procedures for remote work.

It should be remembered that it is the employer who is responsible for violating cybersecurity rules, which is why it should be so important to control employees and ensure that they are trained and to verify whether they are using technical measures adapted to current threats in cyberspace. It is highly likely that most attacks could be prevented if companies took more time to train workers, especially since a large proportion of attacks are caused by human error, which is due to ignorance and lack of knowledge in this regard.

Summary

Despite increasing threats and hacking attacks on security on the network, there is no indication that remote work will lose its popularity and will be replaced by stationary work again. On the contrary, more and more organisations are based on this model of work, which is also important for those seeking new jobs.

Maintaining such a working model while at the same time aware that cybercriminal threats are increasing is a challenge for both employers and workers. The base is to create an adequate security system by building a complete IT infrastructure and developing an action strategy for data leakage from the company.

This, combined with current employee training, should form the basis for any company in the age of digitalisation. As statistics have shown, cybersecurity should not be underestimated.

However, the lack of detailed rules in this respect makes it necessary for entrepreneurs themselves to develop rules of conduct and a plan to respond in the event of a company's data leak.

However, it is desirable to introduce regulations which will directly address cybersecurity in the context of remote work and which will clarify the existing indirect provisions in this area.

Until then, it should be remembered that the company's cybersecurity depends to a large extent also on the involvement and responsibility of each of the employees, who above all must develop a certain awareness of risks and the habit of complying with the company's security rules and data processing procedures.

This is why it is worth investing in creating new systems for different risks of attacks and adapting their safeguards to new threats and training of workers. Flexibility, creativity and prevention are key for employers and IT professionals to create conditions for working in all conditions, including work from home comfort.

___________________________

1 Act of 2 March 2020 specific prevention, prevention and eradication solutions COVID-19, other infectious diseases and their emergency situations, Journal of Laws, item 374 as amended

2 Act of 19 June 2020 on interest rate subsidies on bank loans granted to entrepreneurs affected COVID-19 and the simplified procedure for approval of the arrangement in relation to the application COVID-19, Journal of Laws, item 1086 as amended

3 https://www.ey.com/en_gl/cybersecurity/cybersecurity-how-do-you-rise-above-the-waves-of-a-perfect-storm

4 https://www.verizon.com/business/resources/reports/dbir/2021/masters-guide/

5 https://www.tessian.com/blog/phishing-statistics-2020/

6 https://www.welivesecurity.com/wp-content/uploads/2021/09/eset_threat_report_t22021.pdf

7 https://umbrella.cisco.com/info/2021-cyber-security-threat-trends-phishing-crypto-top-the-list

8 https://www.ibm.com/security/data-breach

9 https://www.malwarebytes.com/resources/files/2020/08/malwarebytes_enduringfromhome_report_final.pdf

10 https://www.cisco.com/c/en/us/solutions/collateral/executive-perspectives/annual-internet-report/white-paper-c11-741490.html

11 Regulation (EU) 2016/679 to 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46

12 Act dated 5 July 2018 the national cybersecurity system, Journal of Laws of 2020, item 1369 as amended

13 Article 32 GDPR

14 Regulation of the Council of Ministers of 12 April 2012 on the National Interoperability Framework, minimum requirements for public registers and electronic exchange of information and minimum requirements for information systems, i.e. one: Journal of Laws of 2017, item 2247 as amended

15 Directive 2016/1148 dated 6 July 2016 on measures for a high common level of network and information systems security within the Union (Official Journal of the European Union L (2016), No. 194)

16 Journal of Laws of 2020, item 1369 as amended)

17 Proposal for a Directive of the European Parliament and of the Council on means for a high common level of cybersecurity across the Union, repealing Directive 2016/1148, COM/2020/823 final, available at: https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=72166

18 https://www.vmware.com/resources/security/global-security-insights-report-2021.html

19 https://uodo.gov.pl/pl/138/1459

20 ibid

21 Ibid

22 https://threatresearch.ext.hp.com/wp-content/uploads/2021/10/HP-Wolf-Security-Threat-Insights-Report-Q3-2021.pdf

Continue exploring our insights.

View the full archive
Publications

Damage to the consignment in connection with the execution of the contract of carriage of goods. Selected issues

It happens in everyday life that during the execution of a transport contract a consignment is lost or damaged in part or in full.

Publications

Legal effects of a ‘hull’ board in a limited liability company

This article addresses the issue of “hull management” in a limited liability company under Polish law.

Publications

Mutual relations between the buyer's rights arising from the warranty for defects in the goods sold, the quality guarantee and the seller's liability for improper performance

In case of a defect in the goods sold to the buyer, both the warranty rights for defects and the quality guarantee (if the seller provides a guarantee).