ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Post-pandemic cyber risks

post pandemic cyber risks
post pandemic cyber risks

Chris Harris at Thales discusses the knock-on effects of the pandemic, and how businesses can better safeguard against them going forward.

 

The COVID-19 pandemic has transformed workforces beyond recognition. In the past two years, we have seen widespread shifts to remote and hybrid working models, and ‘the great resignation’, with disgruntled employees re-evaluating their workplace priorities. These seismic culture shifts have coincided with an influx in post-pandemic cyber risks, with nearly a third of organisations experiencing a breach in the last 12 months alone.

 

Whilst cyber criminals have successfully upped their game in this period, with their techniques incessantly evolving to stay one step ahead, these newfound security risks can also be partly attributed to these culture shifts. Indeed, such shifts have provided cyber criminals with new, uncharted territory in which to exploit unsuspecting employees.

 

As the dust begins to settle and we firmly enter the post-pandemic landscape, it’s clear that these ‘new’ workplace priorities and working preferences are becoming the norm for many. This is putting businesses in a precarious situation from a cyber-risk perspective. With this now set to continue for the foreseeable future, workplace security is proving a significant challenge for businesses to navigate.

 

The great resignation

The correlation between staff turnover and cyber incidents in the last couple years at the hands of ‘the great resignation’ is surely no coincidence. Fatigued or disgruntled workers who have already set their sights on greener pastures, will no doubt have developed a detached mentality when it comes to cyber-security at their current workplace.

 

Although not malicious, such employees may be lax in following security guidelines if they take their eye off the ball, with workplace dissatisfaction and COVID-19-incuded burnout higher than ever.

 

With a higher employee turnover as a result, new staff will also be unfamiliar with security protocols, heightening the risk of breaches further. In 2022, the cost to replace an employee needs to go beyond recruitment and training costs; it must consider the potential cost to the business in cyber incidents. And after the rush to fill seats following this mass exodus, organisations need to:

  • Double down on cyber-security training and onboarding for new recruits - It’s important to ensure new employees are up to speed from day one of their new role – this is arguably their most vulnerable period from a cyber-security perspective. Make sure training is accessible and digestible; gone are the days when such mandatory programmes were laborious tick box exercises by default. Consider engaging e-learning platforms and workshops to encourage employees to be more receptive.
  • Invest in your current employees too - With current employees also posing a significant risk, ensuring their cyber hygiene remains front of mind should not go amiss. As cyber criminals adapt and evolve, so too should your training to make sure employees are adequately cyber-literate and aware of the latest risks.

 

Decentralised workforces

Workforces nowadays are more distributed than ever - all employees need to do their job is a strong internet connection within their home, or indeed anywhere. Whilst this opens many doors from recruitment and retention perspectives, there’s risk and reward in equal measure with diverging from the traditional office-centric model.

 

Business leaders and IT professionals no longer have centralised control of their workforce under one roof, meaning employees can unfortunately stray away from their watchful eye, and don’t have the same security blanket to fall back on as being in-house.

 

Businesses need to provide their employees with a sufficient infrastructure to independently safeguard against the cyber criminals looking to infiltrate their home working setup. But likewise, business leaders should not leave them to their own devices. Your organisation should:

  • Prepare for the threat: Create, maintain, and test encrypted, offline backups of critical data. Develop and exercise both a cyber incident response and communications plan. Make digital asset management a key competency for your organization. Create and maintain a cyber-security awareness training program for your users.
  • Harden your systems: Keep systems up to date, consistently maintained, and use appropriate tools and security teams to regularly test and evaluate your environments. For those critical systems where updates are challenging, make sure to add layered defences and threat detection capabilities to further protect those systems from attack.
  • Implement multi-factor authentication: Verify users and system components using multiple factors (not just simple passwords) and according to the risk associated with the role, requested access or function.
  • Implement the least privilege principle: Allow users only the minimum necessary access to perform their job — nothing more. System components should be allowed only the minimum functionality required.
  • Segment your network: Logically and physically divide your network infrastructure into smaller parts to make it more manageable to protect and contain the damage if one part is compromised.
  • Encrypt all your data: Protect all your data, whether stored or transmitted. In the event of a data breach, the encrypted data will be of little value to the attackers.

 

Chris Harris is EMEA Technical Director at Thales. For more advice on how to further safeguard your workforce and empower employees with cyber resilience, visit Thales.

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543