Skip to main content
How Endpoint Security Can Mesh with Rapid Digital Transformation
Business Transformation

How Endpoint Security Can Mesh with Rapid Digital Transformation

Endpoint management is key to shrinking the threat landscape during rapid technological change.

The COVID-19 pandemic has meant nothing but opportunity for hackers seeking to exploit vulnerabilities in corporate networks.

The closure of offices has pushed millions of workers into remote settings, where many rely on unsecured Wi-Fi networks and a mix of work and personal devices that are not protected by the usual firewalls. The result? An unprecedented spike in the number of phishing attacks, ransomware, and other cyber threats.

During the first two months of the pandemic, 90% of companies in the U.S., U.K., France, and Germany saw an increase in the frequency of cyberattacks, according to a Tanium survey.

The examples aren’t hard to find. Nefarious phishing campaigns have targeted users of Microsoft Teams, a collaboration hub that’s grown in popularity with the rise of remote work. Cybercriminals have also launched attacks against pharmaceutical companies aimed at stealing proprietary vaccine research.

None of this should come as a surprise. Even before the pandemic, the ability of organizations to fend off cyberattacks was strained, as major digital-transformation investments brought countless new endpoint devices onto their networks, creating new vulnerabilities.

You need asset discovery and management to know what devices exist and what they can access in order to apply security policies to them.
Dan Dahlberg, director of security research for BitSight Technologies

“Because employees are out of the office, they can’t rely on traditional protections, such as the corporate firewalls, which would otherwise block malicious traffic from unknown or unclassified websites,” says Andrew Jaquith, CISO of QOMPLX, an analytics and insurance software firm. “Instead, CISOs need to rely even more on their endpoint controls to maintain visibility and enforce web protections."

As companies invest more in digital technology initiatives, they need to manage and protect endpoint devices more effectively and at scale. Here are five approaches companies should consider to help keep their networks secure.

  1. Explore EM solutions
    Enterprise endpoints have become a weak link in cybersecurity. About one-fourth (28%) of respondents in last year’s SANS Survey on Next-Generation Endpoint Risks and Protection reported that attackers gained access to their networks through endpoints in PCs, smartphones, tablets, printers, and the ever-growing number of internet-connected devices.
  2. Map the entire IT environment
    With increasing size and complexity of corporate networks, CIOs and CISOs need real-time endpoint visibility — a complete picture of how many devices are on the network at any given time, where they’re located, who owns and is using them and, perhaps most importantly, whether they’re adequately updated and patched.
  3. Declutter IT infrastructure To bolster security during turbulent times, resilient organizations must retire outdated tools and technologies.
    Legacy technologies are a common avenue for hackers to penetrate a network, in part because support for them may have lapsed, and hackers prey on those weaknesses. Dahlberg notes that even though old malware families like Conficker or BlueKeep may have been thwarted long ago, they are still lurking in older systems.
  4. Jump-start collaboration between security and IT teams
    Many enterprise organizations struggle with IT assets that are dispersed across digital silos, each with their own admins or owners. The bigger companies get, the more that becomes true.
  5. Invest more in educating employees
    Up to 83% of ransomware attacks occur when an employee clicks on a malicious link, according to estimates. That’s why many organizations view unwitting insiders as their biggest vulnerability.

That highlights the need for companies to invest more in security awareness, with well-planned and sustained initiatives. Current approaches are clearly insufficient: About 95% of working adults in a 2020 Proofpoint study said they had completed training for phishing awareness at work, yet phishing remains a leading cause of corporate breaches.

Experts say organizations must continually be in front of employees with information — which can be presented as part of entertaining games, videos, or pop quizzes — about what to watch out for and how to stay vigilant.

Most IT leaders have adapted remarkably well to the challenges presented by the pandemic. They’ve kept the lights on and stayed productive. But operational focus is not enough. As an increasing number of devices access corporate networks, a unified management solution to track, control, and secure endpoints, along with smart organizational and operational security practices, are needed urgently to keep attackers at bay.