HomeSecurityUseful tips for safe use of corporate VPNs while working remotely!

Useful tips for safely using corporate VPNs while working remotely!

The U.S. Department of Homeland Security (DHS) cybersecurity agency has released some tips on how companies can secure their VPNs (Virtual Private Networks) as more and more governments around the world recommend working from home in light of the COVID-19 coronavirus pandemic . As companies choose to implement remote work, the Cybersecurity and Infrastructure Support Agency (CISA) is encouraging them to strengthen their cybersecurity, as it is highly likely that hackers will exploit remote work to carry out malicious attacks .teleworking due to COVID-19

As more and more employees tend to use their company's VPN when working remotely, hackers are looking for opportunities to exploit any security in corporate VPNs, which are less likely to be fixed in a timely manner if the work is performed around the clock.

CISA also notes that hackers may significantly increase phishing attacks to steal credentials from users working from home, at a time when companies have yet to implement multi-factor authentication (MFA) for the most vulnerable remote access. In addition, companies may have a limited number of VPN connections beyond which no other employees can work remotely. This increases the likelihood that companies, including IT, will have difficulty addressing any cybersecurity issues.CISA for VPN+teleworking tips

For this reason, CISA suggests some tips for companies considering teleworking for their employees due to the COVID-19 Coronavirus pandemic:

  • Keep VPNs, network infrastructure devices, and devices used for remote work up to date by applying the latest security patches and new settings .
  • Inform employees about a potential increase in malicious activities, such as electronic phishing.
  • Ensure IT staff is ready for remote file review, attack detection, and remediation.
  • Implement multi-factor authentication (MFA) on all VPN connections and encourage employees to set strong passwords to reduce the risk of falling victim to malicious attacks.
  • Check the limits of your VPN infrastructure when preparing for mass deployment and take measures, such as limiting connection rates, to prioritize users who need higher bandwidths.

In the context of teleworking, among the tips that CISA recommends to companies is to review what DHS recommends on how to secure network infrastructure devices, avoid social engineering and phishing attacks, and select and protect passwords, as well as the National Institute of Standards and Technology provides guidance on corporate teleworking and BYOD (Bring Your Own Device) security.phishing hackers vs remote work due to Covid-19

The DHS had previously warned companies to protect and harden their Pulse Secure VPN servers to reduce the chances of falling victim to attacks that aim to exploit the remote code execution (RCE) identified as CVE-2019-11510.

Meanwhile, the FBI reported that state-backed hackers have breached the networks of a US financial entity and a US government after exploiting servers that were vulnerable to exploits of the CVE-2019-11510 vulnerability.

CISA also published information on how companies can protect themselves from hackers exploiting the COVID-19 coronavirus for online scams.

At the same time, the World Health Organization (WHO) and the US Federal Trade Commission (FTC) issued warnings about ongoing phishing attacks and fraud campaigns exploiting the COVID-19 coronavirus.tips for teleworking

Finally, Microsoft, Google, LogMeIn and Cisco announced that they are offering remote work tools and other facilities so that those forced to work from home due to the Coronavirus can participate in virtual meetings and chat with their colleagues while working remotely.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS