Mini-Series
Securing Organization’s Cyberspace – Step 2

In the introduction to our series, we identified vulnerabilities and potential entry points for hackers into the organization. In the second step, we’ll dig even deeper—we’ll analyze employees’ actual behavior in the online environment. Specifically, we’ll need to take a detailed look at all the places where they actually log in.
2. Systems, cloud services, third-party applications, social media. Find out exactly where your employees are logging in
Surveys show that employees spend 1–3 hours a day online on activities unrelated to their job duties. This figure varies depending on factors such as age—with younger generations spending more time online—and the day of the week; Friday is the most common day for recreational web browsing. The most common places where employees spend their time include social media, news sites, online shopping, and YouTube. In addition to affecting work performance and task completion, insufficiently protected activity in such environments can impact the security of the entire organization.
This is because employees very often actively use tools that they do not report anywhere, and IT managers have no idea that company data is being sent to them.
What questions should you ask?
Do we keep track of all systems? Is access to them sufficiently protected? Do we prevent the use of unapproved applications?
Why?
Applications that your IT department isn’t aware of can become a real security threat. There are essentially two problems:
1. The connection may not be secured at all or may already be compromised.
2. Employees very often use the same passwords for personal apps as they do for work tools. Stolen login credentials thus become the key to accessing entire internal systems.
This simply creates a golden opportunity for attackers.
Our Tip
A username and password are not sufficient security measures. You should definitely consider implementing multi-factor authentication.
