40% of businesses sacked staff due to breach of security during COVID-19
Almost 40% of business decision makers have laid off their staff members due to a breach of company cyber security policy since the start of the COVID-19 outbreak, according to new research from Centrify,
The research, which involved a survey of 200 UK business decision makers, found 39% of respondents admitted to dismissing employees due a breach.
It also revealed that almost two-thirds (65%) of companies have made substantial changes to their cyber security policy in response to COVID-19 and 100% remote working. Despite this, 58% agreed that employees are more likely to try and circumvent company security practices when working from home – indicating a fundamental flaw in the execution of security measures in a remote-working model.
In an effort to combat poor security practice from employees, 57% of business decision makers revealed that they are currently implementing more measures to securely authenticate employees. Such measures include biometric data checks, such as fingerprint and facial recognition technology, and other multi-factor authentication steps when gaining access to certain applications, files and accounts.
Also, more than half (55%) of businesses already have, or plan to formally ban staff from using personal devices to work from home.
"With more people than ever working from home and left to their own devices, it's inevitable that some will find security work arounds, such as using personal laptops and not changing passwords, in order to maximise productivity," says Andy Heather, VP, Centrify.
"It's also possible that the changes in security procedures are not being communicated well to employees, and many are practising unsafe internet usage without even realising," he says.
"The reality is the weakest link in any organisation continues to be the human element," says Heather.
"Combatting this issue starts from the top. CIOs and business decision makers must implement strict and transparent, cloud enabled and identity-centric security solutions.
"This will allow companies to quickly and safely deploy scalable security privileged access management measures, which make it impossible for an employee to access company networks, applications and data, unless they are following correct procedures," he explains.
"Centrify Identity-Centric PAM is designed to handle requesters that are not only human but also machines, services, and APIs. For increased assurance, best practices now recommend strongly authenticated individual identities – not shared accounts – where least privilege can be applied," adds Heather.
"All controls must be dynamic and risk-aware, which requires modern machine learning and user behaviour analytics. PAM must integrate and interoperate with a much broader ecosystem including the cloud providers, DevSecOps tools, containers, microservices, and more."