How To Secure Your Business When Remote Working • Blisstech Solutions

The global COVID-19 crisis means that more people are remote working than ever before.  Businesses rushed to enable their employees to work from anywhere very quickly, which may include access to sensitive company data.  In the rush to stay operational during the crisis, it can be easy to overlook security in favour of convenience.  However, remote working can be done securely, and here are some key pointers to help you.

Secure Windows Remote Desktop

A quick way of enabling remote working is to enable Windows Remote Desktop (RDP) and open port 3389 on the firewall.  BAD IDEA!  RDP has had a lot of security vulnerabilities associated with it and should not be exposed directly to the internet.  Use Remote Desktop Gateway or a VPN to protect the systems you want to provide access to while remote working.

Deploy a VPN

A VPN enables employees to make a secure connection into your internal network from anywhere.

The connection is encrypted between the remote computer and network so it can safely be used without fear of snooping.  For the employee,  it can appear to them as if they were connected directly to the internal business network.  You should consider adding multi-factor authentication to ensure that, if a user’s password is compromised, the connection is still protected.

Use Cloud-Based Systems

Using Software as a Service (SaaS) such as Microsoft 365, or other cloud-based systems, gives your business a huge amount of flexibility, and allows your employees to work anywhere.  SaaS solutions are based on centralised systems in the cloud, and because of this they also can offer better security when they are configured correctly, especially when combined with multi-factor authentication.  As company data and systems are available securely in the cloud, there is no need for users to take external copies of data or use shadow IT so they can work remotely.  All of this means you have control of where your data is and who can access it, so it is far less likely to be compromised.

Enable Multi-Factor Authentication

Multi-Factor Authentication (MFA, but also known as 2FA) adds an additional ‘factor’ to the login, in addition to the password.  This ‘factor’ is usually something that you have like a mobile phone, email address, or security token that provides and an extra code needed to log in.  You may be familiar with using this as it has become very popular recently, being used by banks, the UK Government website and many more.  You should consider adding MFA to any critical system exposed to the internet.   This includes, but is not limited to, VPN, email, CRM, accounting system and any other cloud-based system used to run your business.

Centrally Enforce Security Policies

Remote working can be bad for IT security.  When your users are not protected by your companies internal systems like firewalls, and are in the relaxed environment of their home they drop their guard.  Problems like using business issued systems for personal and family use can expose your business to additional threats.  You can use solutions from Sophos and Microsoft to centrally enforce your security policies to prevent this.

Update Your Systems

Having endpoint software up to date is key to ensuring that they are protected from known vulnerabilities and malware.  Having a strategy and systems in place to check and enforce anti-virus, Windows and other software updates means you know that your users’ endpoints are up-to-date and protected as much as possible.

Educate Your Users

A good remote working setup

Threats from phishing and other scams are at an all-time high, with hackers trying to take advantage of people’s fears about the coronavirus.  Employees need to be educated now more than ever.  Protection for the human layer comes down to training and education. Following the training, you need to keep users on their toes and there are services available that can automate this.

Have Remote Working Policies In Place

Clearly articulate what behaviour is expected, and not expected, to your remote workers.  If a user does something that puts your business at risk, you can’t reprimand them if you didn’t communicate policy.  You may also be able to enforce some of this policy (updates, web browsing, etc) using technology, but even if you can’t enforce it, you should explain what is, and what is not, allowed.

We can help

If you need any assistance with remote working more securely, or remote working full stop, please contact us on 01299 382 321 or get in touch through the website.

More Content

Which ransomware payment option is best? (Hint: none)

Which ransomware payment option is best? (Hint: none)

Cyber criminals are giving you more options when it comes to paying your way out of a ransomware attack. Our advice remains the same though. Find out what that advice is here.

Some bosses think their people do less when working from home

Microsoft has become the leader of productivity over many decades. Can you imagine doing your day to day work without their software? So it’s no surprise the tech giant recently conducted a major new survey into productivity in the workplace – and some of the results might surprise you. Researchers surveyed 20,000 people working for […]

Windows 11 will warn you if someone’s snooping

Windows 11 Onlooker Detection will warn you if someone’s snooping

You know that feeling that someone’s looking over your shoulder?
When you’re working, it’s not just creepy, it’s a security issue. But Microsoft’s working on a very cool feature in Windows 11 that will stop people snooping at your work. Here’s what we know so far…

Tech Tip: How to share files securely in Teams

Welcome to a new Tuesday tech tip video where we will be exploring how to share files securely with people outside of your organisation using Microsoft 365 and Teams. Microsoft Teams is a powerful tool that allows for seamless collaboration and communication within an...

Windows 11 optional update: Why it’s better to wait  

Microsoft has just announced an option for people to trial new features before their general release in Windows 11.  This isn’t about fixes to security flaws – everyone gets those at the same time.   This is an opportunity for businesses to jump the queue to receive new features and updates first.  Sound exciting?   Yes!   Worth the risk?   Not quite.  Our …
Read More

Beware the next generation of phishing attacks

Beware the next generation of phishing attacks

Most phishing scams still feel a little… amateur.
But the next shift is dangerous.
Attackers are changing how scams are built, not just how they’re sent. And the signs people have been trained to look for won’t always be there anymore…

Start it on your phone… finish it on your PC?

Start it on your phone… finish it on your PC with “Hand Off”

If you work on your phone while you’re on the move, it can be a hassle to find the right file once you’re back at your PC. Here we tell you about a cool new feature coming to Windows 11 that will help.

Tech Tip: Send quick Teams messages from anywhere

We all know that Teams messaging is a great way to communicate with others, but it can be disruptive if it interrupts our flow. Even though Teams messaging is a great way to communicate with colleagues, it can easily break your concentration and flow. You might find...
Warning: That antivirus website could be a fake

Warning: That antivirus website could be a fake

Scammers have been creating replica antivirus downloads that steal your data instead of protecting it. Here’s what you need to watch out for…

How to get the most from Microsoft Teams

Is your business struggling with too many emails, lost files, and “final_final_v3” documents? Teams could be a game changer. Yep, it does more than just video calls.  For example, you can also: Chat with your employees Host webinars Share and edit files together Keep...
Share This
Contact
Love Lane
Cleobury Mortimer
Shropshire DY14 8PE

01299 382 321
[email protected]
Copyright © Blisstech Solution Ltd
Registered No: 08125391 VAT No : 307 5490 05