Category: Work From Home

Virtual Cybersecurity professional
Virtual Cybersecurity Professionals Needed More Than Ever

Data Breaches taught companies hard lessons in 2019. Even back then, Forrester’s VP and group director of security and risk research, Stephanie Balaouras warned that all companies need a chief information security officer.

In a February 24, 2020 MIT Technology Review Business Lab episode, Balaouras makes the case that the world of cyberthreats is becoming more intricate and perilous. Cybersecurity isn’t just stopping the threats you see, but also the ones you can’t see. “Even companies that have a Chief Information Security Officer (CISO) should take a hard look at how high in the organization they report,” Balaouras says. “Do they have the right budget? Do they have enough staff?  Have you given them the right span of control?”

Thanks to technology we are able to carry our office with us, reach out and talk to anyone at anytime, and all at incredible speed.  The mobile devices that make our lives so much easier, also increase the attack surface for cyber criminals. Few corporate functions have had to pivot so quickly or dramatically as cybersecurity operations. CISOs have had to take steps to minimize network threats targeting the legions of work-from-home employees.

According to a McKinsey article by Venky Anant, Jeffrey Caso, and Andreas Schwarz, “The response to the crisis continues to press department budgets and limit resources for other, less essential functions.”

Many companies are freezing their hiring because of the pandemic. Unfortunately, now is a risky, uncertain time to add full-time equivalent (FTE) employees. But companies, most of which don’t have the expertise in-house, need to hire a professional to lead their cybersecurity initiatives. What’s the solution?

VIRTUAL IS THE KEY WORD FOR 2020 & BEYOND

Virtual Cybersecurity Professionals (VSCP). VSCPs are the latest trend in cybersecurity hiring, bringing additional cybersecurity talent at a fraction of the cost, without requiring office-space, benefits, or training. VSCP don’t require on-boarding, and they can hit the ground running.

BUILD SECURITY ON A SOUND FOUNDATION

They are accustomed to handling a wide range of responsibilities geared towards protecting online data from being compromised. Sure, they safeguard organization’s files, networks, install firewalls, and monitor activity, but they should also create security plans that involve all employees of the company. As mentioned in one of our brief articles on phishing attacks, the best technology in the world isn’t going to protect a company’s data if the employees are not educated on the best practices of handling emails. Having mature fundamental processes in place are vital.

VSCP are not traditional employees that require significant investment. Nor are they consultants who are foreign and not part of your team. They are somewhere in between. As such, they tend to have greater access to C level executives. VSCP can be procured by days – you can hire a VSCP for Monday and Tuesday each week, for example – or for a certain number of hours each week. VSCPs typically work remotely, but schedule time on-site at least quarterly, or more often, as your budget and needs require.

In a Forbes article, Jon Younger explains that when a company “lacks the means to hire full time staff,” they can pull together essential skills and keep the business moving forward by combining full-time and freelance professionals together as a flexible, blended workforce. And increasingly, talent marketplaces are able to organize entire engineering or development teams on a “bolt-on” or plug and play basis.

There are downsides to VSCPs. Like all cybersecurity talent, the professionals are in high demand. There is an overall shortage in cybersecurity professionals. A recent Gartner report showed a 65% increase in demand for cybersecurity professionals and an estimated 3.5 million vacancy on the cybersecurity job market. Although they are easier to find than top-quality employees, it still can be difficult to find a quality VSCP. When you find a good VSCP, it’s important to retain them before their schedules become full. And like an employee, personality and team chemistry are important. Although they are remote, it is important that your security consultant fit your organization’s culture and gets along well with the team.

VSCPs are not an entirely new concept. Companies have been hiring Chief Information Security Officers (CISO) for years. Quality CISOs are difficult to find and expensive. A Virtual CISO (vCISO) is an outsourced security practitioner or provider who offers their time and insight to an organization on an ongoing basis, usually part-time. Working remotely, they are usually engaged to design an organization’s security strategy, and some may handle the implementation as well.  vCISOs are less expensive than staff Chief Information Security Officers and with a quick time-to-value.

IN CONCLUSION

The pandemic seems to be expanding this need to a wider range of security tasks. Staff are separated, budgets are tight, but viruses don’t respect deadlines. Projects still need to be completed despite today’s difficult environment. As another Forbes article points out, “Times are challenging, and it’s time to get creative. Organizations must find a way to respond to modern cyber-threats without stretching their financial resources. The vast majority of security budgets are spent on managed services, and that includes consultancy. Because internal security teams need external help, there is a move away from on-premises products towards services.

A virtual chief information security officer (vCISO) could deliver the most bang for your buck.

Here’s why:

Vast Experience and Proven Leadership
No Training Needed
Reduced Overhead
Flexibility
Faster On-boarding

The VSCP concept was reserved mostly for vCISOs, but times have changed and the concept is ready to be deployed for various types of roles.

This might take the shape of a Cybersecurity Compliance Director who ensures the company is aligned with NIST 800-53, FedRAMP, or HITRUST, or prepared for the 2020 CMMC audits. It might be a Privacy Officer who ensures the company is abiding by GDPR, CCPA, or new the privacy laws of Texas or Nevada, ensuring that the company can keep doing business in those states.

Taking a proactive stance on your company’s cybersecurity could mean setting up an incident response program, a SOC or a SIEM, or a disaster plan. Or maybe hire a penetration tester, AI/ML expert, or cryptographer.

The possibilities are numerous, but even if you could hire all the people you could want, you wouldn’t be able to keep up with the vast scale of the cybersecurity threat problem. Phishing scams are on the rise. Smaller companies are being targeted just as much as larger companies because they are known to lack the resources; so, they’re easier to hack. Cybercriminals are sophisticated and they stay informed. They constantly adapt messages to more effectively scam victims. The FTC estimates $100 million dollars in coronavirus stimulus checks have already been lost to fraudulent cyber crimes. The constant threat of cyberattacks presents a huge problem for all industries and guarding against it effectively requires constant attention. That is why IronOrbit has its own division that handles nothing but security and regulatory compliance.

During these difficult times, companies need to ensure they have SOC processes in place, utilize virtual cybersecurity professionals, and incorporate automated security measures. Probably in that order. Whatever you do, as they say at the end of MIT’s Business Lab podcast, get outside help. You don’t want to go it alone. With IronOrbit, you don’t have to. Learn more about how we can protect your company. Check out our Security and Compliance section and then  give us a call at (888) 753-5060.

The Major Business Advantages for a Remote Workforce
Telecommute, remote work, work from home, flexible location. These are all common terms, depicting the ability to do your job from a location other than the work office. These terms have been on everyone’s mind lately. They’ve joined the lexicon along with words like coronavirus, pandemic, and physical distancing.

The government is closing down operations deemed non-critical. More and more state officials are urging people to stay at home. Companies across the globe have to increase their remote workforce or shut-down altogether. Modern-day technology enables employees to work from home and keep operations afloat. Many positions can make the transition to remote work. These include virtual assistants, customer service, sales, IT professionals, writers, designers, and more.

Many Positions Can Transition to Remote Work. For those that can’t, cross-train your staff and shuffle talent in order to leverage their experience with the company.

A recent article by the New York Times reported that over 158 million Americans have been ordered to stay home due to the Coronavirus. Britain has an even more stringent lockdown policy. They have a country-wide ban on meetings of 2 or more people. It’s not known what the numbers of people working from home are. At least not at the moment. The popular web conferencing SaaS company Zoom noted that it had more active users in the past couple of months than it had all last year.

In a May 5, 2020 article in Forbes magazine, Wayne Rush warns that “telling companies to simply have their employees work from home is easier said than done. Not every company has the resources, the training or even the bandwidth to support an en masse move to remote work. In addition, for many companies, a move to working at home requires a significant shift in their corporate culture, something that may be even harder to accomplish than any physical requirements.” The article goes on to suggest doing some incident management exercises. Well, the time for practicing these disaster responses has ended. The window of opportunity has closed. It is true that, as Jack Gold states in the Forbes article, “companies are really going to struggle.” But overcoming these struggles, whether they’re technical or not, is going to make our companies stronger and better prepared for the future.

PERKS WORKING FROM HOME

There are obvious perks to be working from home. For example, there’s no commute, you can be comfortable, and your pets get spoiled having you home all the time. There are also advantages, which may not be so obvious, for the companies. In this Owl Labs report, we see that in the US alone, 48% of workers were allowed to work at least once a week from home. A whopping 30% could work from home full-time. We see some interesting stats on job satisfaction and pay as well. We’ll get into employee availability, cost-savings, and the technology behind it all a bit later. For now, let’s do a deep dive into the question. Why is a work from home option so beneficial to employees? How does it present such an advantage to the health and prosperity of the company?

 

Those companies that had a remote work policy in place before the pandemic are in a much better position to make the transition.

A remote work environment liberates the totality of the company. No longer are the HR options confined to hiring candidates in one geographic region. You are able to pull job applicants from around the globe. This gives a major advantage in the size of the talent available. Not only the size but the quality of the applicants will go up. So there’s an increased talent pool. You can find the best talent available. You will also tap into a diverse workforce. There’s also an ancillary but real boost to the company’s image.

THE BENEFITS GO BEYOND AN ENHANCED SOPHISTICATED CORPORATE IMAGE

When a company advertises a work from home option, it demonstrates a couple of things. Both come across as sophisticated and attractive. It demonstrates flexibility and agility. It also bespeaks a culture that pushes the edge.

A Fast Company article reports that hiring workers from all over creates more diversity and other possibilities. More expansive regions mean less racial, age, and gender biases. For example, mothers will have an easier time re-joining the workforce after long stretches of staying home. Another major advantage to employers for hiring remote workers is salary. Remote workers don’t get paid less. Cities like New York, San Francisco, Boston, and Washington, D.C. are expensive areas to live in. Companies can hire talent away from their headquarters. Comparable employees can found in locations where the cost of living is much lower. This allows the employee more flexibility when it comes to salary. Companies have more leverage to negotiate.

 

Now is the time for companies to focus on revenue over growth. Remote work facilitates long-term cost savings. The benefits include more leverage to negotiate for talent all over the world.

 

Being able to offer telecommuting options to an employee is an actual company benefit. Telecommuting, when it is available, is listed as a benefit on a company’s website. It’s a perk added to a career opportunity ad. You can often find it alongside retirement options and vacation policies. It is also usually touted throughout the hiring process. There’s a reason for it. Telecommuting is a way to lure those that are familiar with working from home. Some professionals have always wanted to work from home but have never had the option. Those who have worked from home, either partially or full-time, often seek out similar jobs. and companies that embrace this type of culture in their next role. Job satisfaction can come from having a strong remote workforce. This satisfaction yields productivity.

INCREASED JOB SATISFACTION EQUALS INCREASED PRODUCTIVITY

 

The infrastructure fo remote working, including laptop computers for every employee expected to work from home must be in place.

 

Remote workers tend to be more satisfied because of the autonomy it brings. At home, there are fewer distractions (well, in most cases). They have more flexibility in their schedule. Allow employees to be autonomous. They’ll have an increased sense of ownership and freedom. In an office setting, there’s a need to conform to certain things like office attire, hours and a cubicle or desk. The Owl report shows that 71% of remote workers are happy in their current role. Only 55% of non-remote workers are satisfied. Job satisfaction yields productivity. In turn, job fulfillment results in less turnover in the workplace.

Having remote employees means much less overhead. You don’t need the office space. The cost-savings alone are reasons to get behind this movement. The cost of space in San Francisco can be around $80/sf. New York City hovers around $90/sf. The cost incurred for remote working space is of course non-existent. The cost of office furniture is another major factor. A high-end office chair can cost a company between $800 to $1,000. Companies have not provided stipends for home office use and expenses. As the current situation continues, that may change. A good case can be made for on-going telecommuting even after the coronavirus crisis comes to an end. In such a situation, some companies will offer reimbursement programs for home offices.

Some employees have high-speed internet connections at home. Some do not. Some are faster and more reliable than the office network. Embracing work from home, employees tend to use BYOD.

If an employee is operating in their own home, and on their own time, why not let them use their own equipment. BYOD adds more flexibility. Most people make use of their personal devices and computer set up in as much as possible. This is especially true if they have a more powerful laptop than the one issued by the company. Think of a company’s infrastructure. The telephones. The Network. The HAV. These become cost savings when large portions of the workforce do their job from home.

Old technology prohibited the work-from-home option for many businesses. Today, that’s no longer true. Companies can remove any obstacles allowing employees to work from home.

THERE ARE MANY TOOLS TO HELP WITH THE TRANSITION
Technology can no longer be an excuse not to work from home. There are a number of collaboration and communication tools that can handle any workflow.

Look at the hardware available today. The quality of wireless headsets (Plantronics and Jabra) have eliminated background noise. Having a Conference call at home is part of regular business life. There are desks that you can raise or lower as needed. These types of workstations provide better energy levels for those who sit many hours in a chair. Other items include multiple monitors for extended viewing. These are particularly useful for doing design work. There are laptops that fit any task requirements.

Web conferencing software (Zoom, Web-Ex or Skype)s for Business can work anywhere. Attendees have the option to use video or have audio-only meetings. Collaboration is key. Keep employees productive within groups. Keep them communicating. The use of tools such as Slack can keep information flowing.

Slack, a simple SaaS solution incorporates single chat or group-chats. It features system notifications and simple file sharing for your entire organization. The pricing is straight-forward. Telecommuters needing technical help can make use of TeamViewer or RemotePC.

Having your data backed up to the cloud is also important. Your computer is not on the company network. Syncing your work to the cloud is as simple as using Microsoft OneDrive or Google Drive. Time tracking tools can report on how long it takes to work on various tasks. They can tell how long you spend on different web pages.

The coronavirus has provoked an exodus from the corporate office to the home. The coronavirus physical distancing might be short-lived or longer-term. How business leaders manage their remote workers will determine the level of productivity. Communication from managers will have much to do with job satisfaction.

There are many SaaS-based apps available. These applications keep employees engaged and available. They also have the flexibility fo step away for a break. It’s a win-win for employees and their employers.

Job satisfaction and productivity are up because of remote work. The question is how will you institute a proper policy? The details will be different for each business. A recent article in Glassdoor proposes a basic approach. It advocates “adequate technology, disciplinary excellence, and clear communicative instructions.”

Employers now have more options to hire cream-of-the-crop talent. They can focus on skillset over the location of a candidate. Working-from-home gives business leaders more time to focus on productivity and bolstering revenue.

 

The Remote Work Survival Kit Under the Threat of the Coronavirus

There is no denying the impact COVID-19 has had on us over the past couple of months. The coronavirus has managed to work its way into every conversation, news headline, and social media post.

The coronavirus is a pandemic according to the World Health Organization. The threat of the virus spreading
has changed the way we live. We have to prepare ourselves for the upcoming months. Canceling large events and gatherings is one way to mitigate the spread of the virus. Sports, schools, churches and many businesses have closed. Or they avoid interaction with the public. Social distancing is the new mandate. Government officials have urged us to not congregate in large crowds. Stay at home if possible. Many companies are sending emails to employees asking them to work from home if possible. Companies that aren’t set up to work remotely are scrambling to make it happen. What was once an option has become a necessity.

This article will provide some options on how to deliver a great work from home experience. None of these technologies are new. If used in combination they will ensure a better work-from-home experience.

Let’s start with the one that can take on many forms and methodologies: BYOD. Bring your Own Device. Gartner defines BYOD as allowing someone to use a personally-owned device to access a company’s resources. This could be the company’s email. It could be actually installing a VPN client on their home computer. Each company has a different take on the level of access granted to non-company assets.

 

The “Bring Your Own Device” concept has been around since 2004. It is not a new trend. What is new is the popularity of using personal mobile devices on the job. The security risks of allowing access to corporate resources has discouraged some companies from adopting a BYOD policy.
Bring Your Own Device

In this post by Remote.CO you can get a sense of the varying level BYOD plays at different organizations. BYOD had its start in the mobile device world. Companies were tired of purchasing cell phones for employees. Employees were tired of carrying around 2 phones. Employees carried their personal phone and the locked-down, outdated one provided by the company. Since then, companies have other ways of getting business data secured on personal devices.

Mobile Device Managers

Microsoft Intune and VMware Airwatch are MDM programs that help protect corporate data on personal devices. Employees have access to an Enterprise app store where they can consume their internal data while using their device of choice. The employee first opts in to install the MDM agent on their device. The list of devices with current modern Operating Systems is no longer limited to only smartphones. Once the agent is installed, the company can push down a profile that allows the device to be managed. Both Intune and Airwatch have a robust set of policies available for Windows, macOS, iOS, and Android. What degree of enforcement the company has on the phone will vary on the company and device type. Once the agent is deployed, and the configuration of Security baseline is set, the device can be actively monitored and secured. This could mean enforcing Bitlocker encryption for Windows 10 devices or managing Filevault on macOS with Intune.

Virtual Desktop Infrastructure

VDI technology has taken many forms over the years. In its purest form, VDI is accessing a virtual machine over the network from a client or web-browser. This enables companies to have virtual machines always available on the internal network. These virtual controlled Existing management systems control these machines. Security tools protect the company provided applications and data. Having a proper VDI solution for employees to use can be a major advantage. Especially if they need to travel or work from various locations and/or devices. If a company already has VDI in place today, the process of deploying new virtual desktops is easy. It only takes seconds to accommodate new users.

VDI began as a technology installed on-premise or in a company’s private data centers. Later VDI transitioned to the cloud. The major VDI players Citrix, VMware and Microsoft all have major cloud offerings. This is called DaaS or Desktops as a service. Citrix and Microsoft host their DaaS offerings within Azure. VMware can host desktops in AWS, Azure, and the IBM Cloud. Google Cloud is coming soon.

The ability to leverage cloud-based virtual desktops has great advantages. Especially in certain situations like Disaster Recovery. Traditional VDI takes longer to procure and deploy new hardware. DaaS has some extra benefits like less IT overhead. This is because the cloud provider manages more components.

 

Multi-factor authentication (MFA) is a means of which a computer user is granted access only after successfully presenting 2 or more pieces of evidence (factors) to an authentication mechanism. These are usually having to do with knowledge (something only the user knows); possession (only the user has it); and inherence (like fingerprint voice scan, or retina scan).

Let’s discuss the use of a multi-factor authentication solution. Two-factor authentication (2FA) is a subset of multi-factor authentication (MFA). It ensures you can pass multiple criteria for identity. This includes something you know (password or security PIN). It also includes an object like a security token or fob. Finally, something physical that is specific to you (fingerprint, retina scan, facial recognition). A 2FA solution would offer only 2 of these mechanisms to prove your identity.

We’ve all had to input our email or phone number when signing up for an account online. Using a mobile banking app is a good example. An authentication mechanism can be a one-time-password sent to you via text message. It could be using your phone’s builtin face or fingerprint reader. These are ways to prove your identity.

The FBI warns MFA solutions are not completely foolproof. Still, it’s the best way to thwart cyber-thieves from stealing your data. Having a second form of authentication proof is safer than only having a long password. Most modern smartphones and laptops have a built-in fingerprint or smart card reader. There are several key players in the MFA space. The top leaders include Okta, Microsoft Azure MFA, and Duo (recently acquired by Cisco). Duo uses a simple cloud-based 2FA approach. Their system integrates with various types of applications. When a user attempts to gain access, a VDI or VPN provider sends a push notification to your smartphone. The user acknowledges the push notification on their smartphone. There’s no need to enter a second password or copy a 16-digit PIN for verification.

The order from management is to stay at home. Do not come to the office for the next 2 weeks. Work remotely until government and health organizations deem the coronavirus has been contained. Don’t worry about a report or project plan saved on your office desktop. Embrace VDI technology.

Do Your Work, Anywhere, and on Any Device

 

If you’re new to working from home, make sure your technology is in order. One important aspect of working remotely is communication. Make sure you have the bandwidth needed to support your tasks throughout the day.

The order from management is to stay at home. Do not come to the office for the next 2 weeks. Work remotely until government and health organizations deem the coronavirus has been contained. Don’t worry about a report or project plan saved on your office desktop. Embrace VDI technology.

VDI means working from a virtual desktop every day. Your data is always available, accessible from wherever you are and protected. Your data is more secure now than it ever was when kept on-premises. The data is backed up across different geographic regions within the cloud. There is no need to worry about catastrophic power or network outage at your local data center. It’s also always on and provides a consistent experience whenever you need to access it.

Maybe you don’t need a full Windows Virtual Desktop to get your work done. You just need access to a handful of SaaS apps like Salesforce.com. An Okta or other MFA solution can help authenticate you from an outside connection. This allows you to gain entry to those specific internal resources without the need to install a VPN client.

Or, what if all you really need is to access your corporate email and files on your phone while safe at your home? Having your smart device enrolled in your company’s Mobile Device Management solution can provide the access you need while keeping the business data secured.

Deciding how to start a remote work enablement plan for your team can seem like an overwhelming task. Like other challenges, it can is not so daunting when done in small steps. Better yet, it is a good idea to bring in experts who can design a solution that works best for your business.

There is no one-size-fits-all approach. While there are many ways to enable employees to work from home, there is only one that is perfect for your needs.

Many adversities are beyond our control. It is helpful to focus on those things we can control. We can take steps to prepare for the uncertainties ahead. We can do what is best for our employees and our loved ones.

Using the cloud to work remote is less to do with “social distancing,” and more to do with benefiting your company. Being on the cloud will democratize opportunities for you across the board. You’ll see that remote work is not so much a challenge to overcome, but a business advantage to achieve.

 

Check out IronOrbit INFINITY Workspaces! The Ultimate Remote Work Tool!

 

Infographic: Hire Out of State with Hosted Desktops

2020 UPDATE: Visit INFINITY Workspaces

 

According to a recent survey cited by the Wall Street Journal, only 19 percent of American businesses plan to hire new employees in 2014. Many of the businesses not planning on hiring this year would probably change their minds if they knew that they could hire workers from other cities and states where the cost of labor is lower. By signing up for IronOrbit Hosted Desktops, for example, businesses can hire people anywhere in the United States, and provide them with all of the same IT resources that onsite employees have access to (IronOrbit Hosted Desktops are anywhere-accessible IT solutions that appear and perform the same as locally-installed Windows desktop operating systems). And by using IronOrbit Hosted Desktops to hire more affordable remote workers in other cities and states, businesses can reduce their payroll costs by an average of up to 42 percent and raise productivity by as much as 350 percent. To learn more about why businesses wanting to hire more affordable remote workers in other areas should sign up for our Hosted Desktops, check out our infographic posted below; and to sign up for our INFINITY Workspaces (Hosted Desktops)

Contact us at [email protected] or (888) 753-5060 today!