Intelligent CISO Issue 33 | Page 76

are needed to ensure they can get the job done . According to 35 % of IT decision-makers , in fact , insider threats increased last year due to employee disengagement and over half of decision-makers in IT agreed that WFH has made their companies more vulnerable due to insecure devices . And there ’ s more – 44 % of companies saw an increase in phishing attacks last year . It ’ s no secret that cybercriminals have been exploiting COVID-19 in fraudulent emails and texts to workers , to breach their organisations ’ defences , so measures need to be put in place to prevent these incidents .
The value of a Zero Trust approach
While employee education and training are of course important , there are other measures companies can adopt . For example , taking a Zero Trust approach to security – not granting automatic privileges to any users on the network – can reinforce protection .
At a time when implicit trust is no longer safe , Zero Trust can help increase protection ; in fact , nearly all of the digital leaders we surveyed said this architecture could help their business deal with the current global situation . Specifically , it has the potential to mitigate threats like human error , as well as employee unawareness and disengagement .
Our data shows that 49 % of IT decision-makers are considering a Zero Trust framework in order to prevent workers from compromising the system . Once again , the technology alone isn ’ t enough : Zero Trust is not a plug-and-play product , it ’ s a mindset . In fact , nearly 30 % of professionals we surveyed said employee support is fundamental to embark on a Zero Trust journey , while 40 % believe the biggest obstacle to achieving it is the need for a culture shift . Employees should keep the ‘ trust no one ’ mantra in their day-to-day , to establish how to behave when targeted by a phishing attack , for instance .
In today ’ s cyber-threatscape , made more complex by fluid working , risks are lurking around every corner . With so many factors that can compromise infrastructure defences and lead to devastating consequences , relying solely on one tactic – be it security technology or employee training – simply isn ’ t safe .
Companies must apply an all-round , comprehensive approach , coupling technology that enables a Zero Trust security strategy , with employee awareness to safeguard their networks in this new world . u
76 www . intelligentciso . com