During the first year of the pandemic, most of us went to remote working and now we don't want to go back. For Chief Security Officers this is a complete mess. If they don't have control of the people and the devices that access to the company resources, how can they ensure the security of the company?
"Extend perimeter to home". This is the expression that I have heard many times during the last year, but what does it really mean?
After talking with some security officers, I made a list of the questions that are disturbing their nights.
Now with an idea about their needs, let's take a look at potential solutions.

Setup Basic Security Policies on Company Devices

  1. Assign the user a non-administrator account on the device
  2. Disable USB ports
  3. Disable SMBv1
  4. Disable user permission to install software
  5. Define a strong password policy

Remote Access

  1. Setup a VPN with a strong cypher
  2. Enable 2FA on your VPN connection or at least the certificate verification
  3. Create different VPN profiles between different business areas
  4. Create different VPN profiles between employees and providers
  5. Establish a periodic VPN security testing

Monitor and Control User Devices

  1. Take advantage of installed endpoints on the devices to get the most information you can and take action based on that.
  2. If you don't have endpoints, install an endpoint solution like Wazuh, Comodo EDR, Symantec Endpoint Protection that allow you to know what happens on the device and take action on it
Humans are the weakest link in the information security chain, so training is always needed to create awareness of the risk and the prevention methods. It will improve your company security, so I hope this article was useful to identify those opportunities.
Remember if you are not thinking about this topic, your company is seriously late to the game.