

The white-collar workforce is likely to look very different long into the future. While some workers are already heading back into the office, the reality is that most of your staff likely want to stay home at least three days each week. We’re expecting to see more businesses offering remote workdays as a perk even after restrictions ease and ultimately come to a close. This means more businesses need to be implementing robust permanent measures and policies that address cybersecurity when working from home.
Ransomware attacks have increased dramatically over the past 12 months as malicious actors take advantage of increased vulnerabilities resulting from work-from-home arrangements. In fact, attacks have increased in frequency so much that The Conversation referred to them as a “digital pandemic”. But the reality is that your organisation faces significant cybersecurity risks that don’t involve malicious actors.
When your team works from home, you have less control over the equipment being used to access your server and network security. You also face significantly higher risk of privacy breaches, especially where team members access personal data stored by your company from their homes. You need to take steps to protect your IT infrastructure from both internal and external threats.
It is a mistake to assume that your cybersecurity risk can be managed by your IT team. Cybersecurity risk management involves careful preparation and planning that reflects the risks posed by:
Current technical cybersecurity best practices include (but aren’t limited to) reliance on:
These technical measures should be supported by the appropriate policies and training.
Your IT team should work with legal counsel to develop robust guidelines and implement a Bring Your Own Device (BYOD) Policy or similar guidelines on the use of employee-owned devices (laptops, phones etc) to access organisational systems and process corporate data. These policies address employee and employer obligations u which should include, at a minimum:
As work-from-home arrangements become a privilege or perk, not an obligation, organisations are in a better position to demand that certain standards and requirements are met. You should implement mandatory staff training for workers who will continue to work from home. This training should address:
The Australian Cyber Security Centre Resources for Small to Medium Businesses.
The Australian Cyber Security Centre Resources for Large Organisations & Infrastructure.
Privacy108’s lawyers work with organisations to improve your cybersecurity protections.
We develop cybersecurity programs that address technical, operational, and personnel-related risks, and provide guidance and oversight while you implement the changes.
We also develop and deliver tailored privacy and security awareness training targeted at your organisation’s requirements. You’ll receive high-quality training from a leading privacy and cybersecurity lawyer, as well as supplementary resources to help upskill your team.
To start building a better cybersecurity framework, get in touch.
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.