Many staff are still using work devices for personal and illegal activities
Remote employees do not always consider cybersecurity risks
Since the transition to remote working, businesses have failed to communicate the importance of sticking to cybersecurity policies and preventing cross-contamination between work and personal activities, new data from Yubico suggests.
The password security company surveyed 3,000 remote staff from around Europe and found that almost half (42%) use work-issued devices for personal tasks. Roughly a third of this group use corporate tech for banking and shopping, while 7% visit illegal streaming websites.
What’s more, senior members of staff are among the worst offenders; 43% of business owners and 39% of C-level executives admit to misusing work devices, with many also dabbling in illegal activities online.
- We've built a list of the best business computers right now
- Here's our list of the best business smartphones available
- Check out our list of the best business tablets out there
Although using a work computer for a bit of online shopping does not in itself pose a threat to cybersecurity, the overlap between personal and professional activities could amplify risks associated with shadow IT, including the accidental compromise of corporate data.
With employees accessing the web and other services for personal reasons, the risk of malware or ransomware infection is also increased.
Remote working security
Another area of vulnerability for many businesses operating under a remote model is password hygiene.
According to Yubico, 54% of employees use a single password across multiple work accounts and services. Meanwhile, 22% of staff still write down their passwords on paper, including 32% of executives.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
However, IT departments aren’t holding up their side of the bargain either, the report suggests. Yubico found that more than a third (37%) of remote employees are yet to receive any form of cybersecurity training, which goes some way to explaining the lapses in judgement on the part of employees.
Further, only 22% of respondents said their company has adopted two-factor authentication, which is described as “the best line of defence” to protect against account takeover.
“Virtual working patterns bring new opportunities for businesses and employees, but also introduce additional risk. This includes new avenues for bad actors to breach corporate defences,” said Yubico.
“With millions of workers focused on the pressures of completing tasks in varying and sometimes unusual circumstances, security best practices are often put on the backburner.”
“Organizations that don’t get a handle on these hazards risk lasting financial and reputational damage from attacks that can leave their assets in tatters.”
- Here's our list of the best security keys right now
Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.