Skip to content
September 11, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Enhancing Security Amidst a Global Shift to Remote Work
  • Technique

Enhancing Security Amidst a Global Shift to Remote Work

Do Son January 27, 2022 5 minutes read
Img_2022_01_25_18_19_39

The pandemic has resulted in increased digitalization of business processes. Along with this comes enhancements in the so-called future of work, wherein businesses that have grown mature in their digital transformation are able to provide an opportunity for employees to work remotely. 

The effects of the pandemic have only sped up this process. Digital adoption among businesses jumped to 55 percent when the pandemic started, from around 33 to 35 percent on average in the previous years. According to the World Economic Forum, 97 percent of global companies have accelerated their technology adoption. The proportion of full-time remote workers has jumped from 33 to 61 percent on average, according to a study by Gallup.

There are still gaps, however. Even with increased adoption, most of the capability lies in big enterprises. Digital giants like Facebook and Google have famously continued to embrace the remote working model, and it is only natural for technology-driven companies to have the tools at their disposal for such. Small and Medium Enterprises (SMEs) have much to catch up on, as only 23 percent were able to dedicate enough resources to digital tools.

An uptick in remote working and digital activities will increase cybersecurity risks

This rise in digitalization and digital activities includes both transactional and relational activities, such as digital payments and remote collaboration. E-commerce transactions rose by 32 percent in the US alone. Payment platform PayPal saw a 20 percent increase in transactions compared to the same period in the previous year.

Work-from-home and remote-working arrangements have also increased, and along with this comes a rise in cybersecurity concerns. The growing decentralization of the workplace is making it increasingly challenging for businesses and enterprises to address cybersecurity concerns.

For instance, at least half of employers across various industries are now allowing remote employees to use their personal devices and even email addresses while working from home. Their remote work forces are also not trained or poorly trained in the cybersecurity risks of remote working.

Businesses need to invest in improving cybersecurity capabilities and protocols

The task of securing sensitive company data becomes much more challenging. New factors come into play, such as using unsecure home WiFi connections, inadequate malware protection, and the use of potentially insecure or even harmful client-side applications. 

It’s no longer adequate for IT departments to deploy simple anti-malware solutions or utilize strategies that are static and reactive in nature. Businesses need to ensure the integrity of authentication systems, verification, and fraud prevention. There needs to be an improvement in how client applications handle data. There is also the need for adequate cybersecurity training and education across all technology users in the company.

Security is often sacrificed when developing mobile applications, underscoring the real need for improving the integrity of data and applications in real-time. Perimeter defenses such as firewalls and anti-malware can be rendered moot as users are now mostly accessing data and apps remotely. RASP security addresses these concerns in real time, being built into the application runtime environment. 

Runtime application security protection does not rely on malware signatures, nor is there a need to rely on patching. Even zero-day exploits can be prevented, with the protection being built into the runtime itself.

Users are still the weakest link, thus education is key in ensuring security

In terms of authentication, utilizing two-factor (2FA) or multifactor (MFA) authentication keys would provide an added layer of security in gaining access to important company networks and resources. These are not foolproof, however, and there are alternatives being offered by technology providers, such as biometrics and heuristics-based access.

Worse, there is complacency among users who prefer convenience to security. Thus, even the uptake of 2FA or MFA is limited. Authentication provider Okta says only 55 percent of businesses use MFA on their platforms, whereas Microsoft says utilizing such security measures can already prevent 99.9 percent of attacks.

Even with proactive security measures, however, there is still a need to provide adequate training to employees and all stakeholders against falling victim to social engineering attacks. Phishing attacks are commonplace, and these have evolved into other platforms such as SMS (e.g., “smishing”), which results in the added danger of malicious actors potentially obtaining 2FA, MFA keys, or one-time passwords (OTP).

Malicious actors can use a combination of spoofed pages, stolen user data, as well as social engineering, in obtaining MFA keys generated by devices or sent through SMS. Once an unwitting user shares these, the entire security chain fails. It is thus essential to provide adequate training to a company’s employees–and this extends to internet users at large as well.

The new normal is here to stay

User education, as well as the general strengthening of systems for access and authentication, verification, and fraud prevention will play a big part in preventing data breaches and unauthorized access to sensitive data. It pays to use solutions that do not rely on reactive measures.

There are new and emerging solutions gaining traction that are providing a way to identify and authenticate that do not rely on MFA, which can be overcome through social engineering type attacks. Still, with malicious actors quickly finding ways to mitigate such security measures, it pays to be one step ahead and always be updated with the latest trends in cybersecurity.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intel📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intel📅 Updated: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-19490
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1...
    CISA KEV📅 Added to KEV: Sep 9, 2026
  • CVE-2026-75650CVSS 10.0
    Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that...
    Admin intelCISA KEV📅 Added to KEV: Sep 8, 2026📅 Updated: Sep 8, 2026
  • CVE-2026-81963CVSS 7.8
    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate...
    CISA KEV📅 Added to KEV: Sep 8, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-8778CVSS 9.8
    The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout...
  • CVE-2026-82107CVSS 9.6
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote...
  • CVE-2026-82100CVSS 9.6
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote...
  • CVE-2026-81204CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to...
  • CVE-2026-80424CVSS 9.1
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote...
  • CVE-2026-79724CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to...
  • CVE-2026-78573CVSS 9.8
    IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker...
  • CVE-2026-45764CVSS 9.1
    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network...
  • CVE-2026-19646CVSS 9.1
    IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART...
  • CVE-2026-89094CVSS 9.9
    Forgejo before 16.0.4 allows remote code execution via a crafted template repository...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Bluesky
    • Facebook
    • Linkedin
    • Mastodon
    • RSS
    • Twitter
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.