Facebook Google Plus Twitter LinkedIn YouTube RSS 菜单 搜索 资源 - 博客资源 - 网络研讨会资源 - 报告资源 - 活动icons_066 icons_067icons_068icons_069icons_070

Tenable 博客

订阅

Spotlight on Brazil: Remote Work Requires New Risk Management Practices

Remote work is here to stay — along with the risks it introduces to Brazilian organizations, if not managed properly. 以下是需要了解的信息。

The pandemic forced many Brazilian organizations to shift employees from working largely in offices to entirely remote in the blink of an eye. Technology was the enabler of this fast-paced change, but not without consequences.

The attack surface has expanded, bringing new and unmanaged cyber risk. In fact, six out of 10 Brazilian leaders said the number of business-impacting* cyberattacks increased with the pandemic and 75% attributed recent business-impacting cyberattacks to vulnerabilities in technology implemented in response to the pandemic.

The self-reported data is drawn from a commissioned study of more than 1,300 security leaders, business executives and remote employees worldwide, including 118 respondents in Brazil. The study, Beyond Boundaries: The Future of Cybersecurity in the New World of Work, was conducted by Forrester Consulting on behalf of Tenable in April 2021.

Remote work introduces new business risks 

The move to a hybrid work model in Brazil required three significant shifts, all of which served to atomize the attack surface:

  1. Dissolving traditional workplace perimeters and providing technology that enables employees to work from anywhere

  2. Moving business-critical functions to the cloud 

  3. Rapidly expanding the software supply chain with new tools for collaboration, communication and productivity

Today, 78% of Brazilian organizations have adopted remote work, with 83% planning to make it permanent in the next 1-2 years; 7% have already made the transition. These changes present significant challenges for security teams as the corporate attack surface expands. Eighty-two percent of remote workers in Brazil have six or more devices connected to their home networks, and many admit to using a personal device to access customer data (55%) and financial records (38%). What's more, 64% of security leaders say employees lack awareness of the available measures to secure home networks and personal devices. The majority of business and security leaders (59%) lack visibility into employee security practices.

As part of this new world of work, business functions are now cloud based. Today 69% of Brazilian organizations moved business-critical functions to the cloud and 82% moved non-business-critical functions. Yet, 97% of business and security leaders believe moving business critical functions to the cloud has increased their organizations' cyber risk.

Expanding the use of third-party software and other services also played a major role in enabling remote work while introducing new risk. More than three-quarters (78%) of Brazilian companies expanded their software supply chain and 76% enhanced existing digital platforms and services to meet changing customer needs. But the majority of business and security leaders in Brazil believe the expanded software supply chain (56%) and the creation of new digital platforms (64%) exposed them to more risk.

Unsurprisingly, 84% of Brazilian executives raised concerns that remote work increased their cyber risk.

Attackers capitalize on workforce changes

Executives' concerns are certainly warranted: the study found that cybercriminals overwhelmingly took advantage of the technology changes that facilitated remote work in Brazil. In fact, 92% of Brazilian organizations experienced a business-impacting cyberattack in the last 12 months.

When looking at the focus of these attacks:

  • 72% of business and security leaders say the attacks targeted remote workers 

  • 66% report they involved an unmanaged personal device used in a remote work environment 

  • 59% say they involved cloud assets 

  • 43% cited VPN flaws or misconfigurations as the cause

  • 41% report the attacks resulted from home router flaws or misconfiguration. 


Securing the new world of work

The new world of work that combines in-office and remote work is here to stay. As a result, security and business leaders are turning their eyes forward and planning to increase investments to fill those gaps. In the next 1-2 years, leaders said the focus will be cloud-based productivity tools (83%), data security (80%) and vulnerability management (78%) solutions. 

Securing the new world of work requires a new mindset. It's crucial that organizations gain a holistic view of their risk profile and re-evaluate their cybersecurity strategies to align with the new realities of the modern workplace and ensure businesses aren't left vulnerable.

If cybersecurity strategy fails to keep pace with business changes, today's risk could become tomorrow's reality.

*A business-impacting cyberattack is one which results in one or more of the following outcomes: loss of customer, employee, or other confidential data; interruption of day-to-day operations; ransomware payout; financial loss or theft; and/or theft of intellectual property.

View more study highlights here

相关文章

您可加以利用的网络安全新闻

输入您的电子邮件,绝不要错过 Tenable 专家的及时提醒和安全指导。

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。

Tenable Vulnerability Management 试用版还包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。

100 项资产

选择您的订阅选项:

立即购买

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。

Tenable Vulnerability Management 试用版还包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。

100 项资产

选择您的订阅选项:

立即购买

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。

Tenable Vulnerability Management 试用版还包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。

100 项资产

选择您的订阅选项:

立即购买

试用 Tenable Web App Scanning

您可以通过 Tenable One 风险暴露管理平台完全访问我们专为现代应用程序量身打造的最新 Web 应用程序扫描产品。可安全扫描全部在线资产组合的漏洞,具有高度准确性,而且无需繁重的手动操作或中断关键的 Web 应用程序。立即注册。

Tenable Web App Scanning 试用版还包含 Tenable Vulnerability Management 和 Tenable Lumin。

购买 Tenable Web App Scanning

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。

5 个 FQDN

$3,578

立即购买

试用 Tenable Lumin

使用 Tenable Lumin 直观呈现及探索您的风险暴露管理,长期追踪风险降低状况,并比照同行业者进行基准衡量。

Tenable Lumin 试用版还包括 Tenable Vulnerability Management 和 Tenable Web App Scanning。

购买 Tenable Lumin

联系销售代表,了解 Tenable Lumin 如何帮助您获取整个企业的洞见并管理网络安全风险。

免费试用 Tenable Nessus Professional

免费试用 7 天

Tenable Nessus 是当今市场上功能最全面的漏洞扫描器。

新 - Tenable Nessus Expert
不可用

Nessus Expert 添加了更多功能,包括外部攻击面扫描,以及添加域和扫描云基础设施的功能。单击此处试用 Nessus Expert。

填写下面的表格可继续试用 Nessus Pro。

购买 Tenable Nessus Professional

Tenable Nessus 是当今市场上功能最全面的漏洞扫描器。Tenable Nessus Professional 可帮助自动化漏洞扫描流程、节省合规周期的时间,并调动起 IT 团队的积极性。

购买多年期许可,即享优惠价格添加高级支持功能,获取一年 365 天、一天 24 小时的电话、社区和聊天支持。

选择您的许可证

购买多年期许可,即享优惠价格

添加支持和培训

免费试用 Tenable Nessus Expert

免费试用 7 天

Nessus Expert 针对现代攻击面而量身打造,可以查看更多信息,保护企业免遭从 IT 到云中漏洞的攻击。

已经有 Tenable Nessus Professional?
升级到 Nessus Expert,免费试用 7 天。

购买 Tenable Nessus Expert

Nessus Expert 针对现代攻击面而量身打造,可以查看更多信息,保护企业免遭从 IT 到云中漏洞的攻击。

选择您的许可证

购买多年许可证,节省幅度更大。

添加支持和培训