iV4's CTO Michael Montagliano shares his cybersecurity predictions and advice for businesses in the wake of the global coronavirus pandemic.
By: Michael Montagliano, iV4 Chief Technology Officer
As organizations address the scourge of the COVID-19 global pandemic and attempt to mitigate the spread of the coronavirus by moving workforces to a completely remote model, another blight has appeared on the cyber-security landscape. Cybercriminals and rogue nation-states are taking advantage of an expanded attack surface to perpetrate new attacks tied to health care and financial efforts.
Cyber attackers are mimicking communications from health organizations (WHO, HHS, CDC), government agencies (SSA, IRS, Medicare) and financial institutions (banks, credit unions). Hackers are using phishing (email) and vishing (phone) campaigns to create fear, uncertainty and doubt (FUD) in an attempt to gain access to systems and sensitive data.
Organizations and their workers will need to devise a carefully considered approach to address security challenges proactively as we enter uncharted territory during this extraordinary event.
Since January, there have been numerous malicious email campaigns tied to COVID-19. Most recently, campaigns associated with stimulus checks from the US government have been on the rise. To be clear: receiving a stimulus check does not require any signup. Any American who qualifies will automatically receive the funds. If you receive a call or email asking for personal data, banking information or money, STOP. It's a scam!
Legitimate organizations will never request sensitive information through email or over the phone.
Watch! Live interview with iV4's Security Team Lead on Fox Rochester, 'Preventing cyber hacks during social distancing'
'The Treasury Department advises on its website: "If you receive calls, emails or other communications claiming to be from the Treasury Department and offering COVID-19 related grants or stimulus payments in exchange for personal financial information, or an advance fee, or charge of any kind, including the purchase of gift cards, please do not respond."
iV4 recommends delivery of supplemental security awareness training specific to protection against phishing campaigns, and general home security best practices are a priority while we are under an extreme remote worker situation.
The suggestions below are some considerations for companies and remote workers alike:
As organizations recommend employees work remotely, there is increased use of mobile devices and remote access to core business systems. Proactive measures may enhance user experiences and security for remote access. Unprotected devices could lead to the loss of data, privacy breaches and systems held for ransom.
That said, here’s a checklist for businesses to consider:
Not everyone is an “essential” employee, but it is essential that each and every employee plays a part in protecting their organization’s data, privacy and infrastructure. These tips can provide guidance and recommendations, beginning immediately, for all remote workers.
Like each of you reading this, iV4 is working around the clock for our teams, customers and community. We don’t have a “typical work week” these days. If you have concerns about your company’s data and infrastructure, you’re not alone. As business owners and leaders, we also have to worry about the risks to — and health of — our operations during unprecedented times, in addition to the health and safety of our families, loved ones, employees and neighbors. What’s important is that you protect today by taking these important steps and consideration, and plan ahead and pivot when needed. Because ready or not, this isn’t close to being over.
As Chief Technology Officer at iV4, Michael leads the technology strategy and execution for the firm he joined nearly 10 years ago. He is also a “Certified Ethical Hacker.” Michael’s love for music inspires him to bring creativity to the world of IT every day.
iV4 is a Rochester Best Workplace and Rochester cyber security company that defends our clients against vulnerabilities, attacks, and threats.
We are committed to our customers and any organization who may need our assistance at this time.