[Expert Opinion] 4 Security Commandments for the CIO in the Era of Hybrid Work

Talkspirit
2022-03-11
4
min.

Temps de lecture: 4 minutes

COVID-19 has completely shifted the way that companies operate. According to Stephen Gorham, CIO and Global Head of Operations at critical infrastructure protection (CIP) and cybersecurity solutions provider OPSWAT, “the pandemic forced organizations to accelerate their remote and digital transformation initiatives by an unprecedented velocity, expanding their remote and hybrid workforce to meet business needs”.

And while the shift to hybrid work may have started off as temporary, many companies are embracing hybrid work environments for the long-haul—and, as such, are having to reevaluate the best ways to keep their networks, data, and teams secure. “As the pandemic continues to evolve around hybrid workforce strategies, organizations are balancing this shift by investing in security and accessibility of systems and data,” says Gorham.

Also read: What the COVID crisis has changed for CIOs

But as hybrid work becomes the norm for companies, what, exactly, do CIOs need to keep front of mind? Stephen Gorham reveals four security commandments for the CIO in the era of hybrid work:

Cybersecurity is the top priority

If you’re a CIO in the era of hybrid work, one of the security commandments that needs to be at the top of your priority list? Cybersecurity. CIOs need to “prioritize the implementation of cybersecurity processes and controls,” says Gorham.

Also read: [Expert Opinion] Cybersecurity Challenges for SMEs in 2021

In order to keep your networks, data, and teams secure, as CIO, you should take a multifaceted approach to cybersecurity processes and controls, including:

  • Access Controls. “Elevate a focus on secure access controls, particularly when both employees and customers are working remotely or using public networks to access privileged data,” says Gorham.
  • Prevention Controls. “Implement data egress controls to mitigate data loss,” says Gorham.
  • Detection Controls. “Deploy appropriate…[and] proven to be effective threat detection resources to quickly identify and facilitate responses quickly—including blocking, quarantining, and remediating threats,” says Gorham.

By approaching cybersecurity from all angles, you decrease the likelihood of dealing with any major cybersecurity issues—and, in the event that an issue does arise, you have the right processes and controls in place to deal with it.

Embrace identity and access management

In a hybrid work environment, by definition, you’ll have employees accessing your system from a variety of locations (whether that’s your corporate office, their home office, or an additional remote location, like a coworking space) and from a variety of devices.

And with so much variability in who is accessing your network, data, and applications, verifying that those people are authorized for access has never been more important—which is why investing in identity and access management is one of the must-do security commandments for CIOs in the era of hybrid work.

Also read: CIOs: what IT investments should you prioritize in 2021?

“Invest in solutions and practices that secure remote access for critical applications and network resources by applying zero-trust principles,” says Gorham. “Verify users, devices, access levels, and requested resources before granting any access.”

In addition to investing in identity and access management tools, CIOs should also continually evaluate how these tools are working, any risks that are present in their current processes, and what to do if there is a remote access breach. “These investments should include documentation of new digital business processes, inventory of new infrastructure assets, evaluation of new digital risks, assessment of the effectiveness of existing security controls, an action plan to address security and compliance gaps,” says Gorham.

Secure company communications

Sensitive information is exchanged over company email and communication platforms. But these platforms can also be ripe with security threats, putting that sensitive information at risk—particularly when employees are sending emails and other communications from unsecured remote networks.

That’s why investing in keeping company communications secure should be high on the list of priorities for CIOs in the era of hybrid work. “Invest in solutions and practices that secure communications necessary for business operations,” says Gorham. “These should include multi-scanning technologies to detect threats, sanitizing technologies to remove malware, analysis technologies that leverage artificial intelligence to assess vulnerability to file risks, automation and orchestration solutions to aid in response, and endpoint compliance solutions.”

Train your team

As CIO, you can (and should) take every step possible to keep your company safe. But if you don’t teach your employees how to do the same, your efforts won’t be as effective as you want and need them to be.

That’s why investing in employee training on how to protect themselves, their devices, and sensitive company information while working in a hybrid work environment is a non-negotiable. 

“CIOs should be investing in additional training for their teams to ensure they know how to keep themselves, their devices, and their data secure,” says Gorham. 

“The rapid transition to first remote and now a more permanent hybrid workforce may have resulted in unintended consequences such as an increased attack surface, unaddressed security gaps, or poorly implemented security controls,” Gorham continues. “To help combat this increased risk. It’s imperative to educate employees and contractors about the dangers lurking on the internet, the meaning of a hybrid workspace, and how to spot and report risky emails and other communications from cybercriminals looking to exploit these security gaps.”

Also read: Hybrid Work: What Are The New Challenges For The CIO?

As CIO, develop robust training programs for employees on how to safely navigate the hybrid work environment—and, when appropriate, bring in external training resources to get your team up to speed. It may be an investment, in both time and resources—but it’s an investment that will more than pay off when your training efforts result in fewer security issues.

*
*  *

As so many workplaces shift permanently to a hybrid work environment, CIOs are having to develop new IT strategies to keep their companies safe. And now that you know the top security commandments for CIOs in the era of hybrid work, you have a jumping off point to start developing your own strategies—and increasing security across your company, no matter where your employees may be working.

Are you looking to know more about CIOs’ security challenges in the era of hybrid work? Read our white paper to find out:

Access White Paper

In our white paper “CIOs: Navigating the New Challenges of Hybrid Work”, you’ll discover: the 3 major challenges for CIOs in the era of hybrid work, concrete advice on how to accelerate your digital transformation, secure your workstations and improve the employee experience, as well as testimonials from 10 CIOs working in companies, administrations and associations.

Download



Author: Deanna deBara

Inscrivez-vous à notre newsletter
En vous inscrivant vous acceptez notre politique de confidentialité et consentez à recevoir des nouvelles de notre entreprise.
Envoyer
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
ALLER PLUS LOIN

Vous avez les ressources pour passer à l’action

2025-01-24
7
min.

Top 10 Technology Trends in 2025, According to Gartner

2025-01-02
7
min.

Top HR Trends in 2025, According to Gartner

2024-12-26
6
min.

5 Strategies That Can Help Improve Employee Autonomy at Work

2024-12-19
6
min.

HR: Watch Out for These Employee Burnout Signs

2024-12-12
min.

[Expert Opinion] Elmy’s Journey to Becoming a Mission-Driven Company

2024-12-09
5
min.

Regenerative Business: the Trend Taking Companies by Storm

2024-12-05
6
min.

How can companies combine digital sobriety with well-being at work?

2024-11-29
7
min.

Agile Methodology: What Are the Pros and Cons for Businesses?

2024-11-19
8
min.

Creating OKRs Aligned with Your ESG Goals: a Step-by-Step Guide

2024-11-13
8
min.

Implementing Accessibility in the Workplace: Key Strategies and Best Practices

2024-11-13
6
min.

8 Steps to Create a Collective Intelligence Framework that Speeds Up Decision-making

2024-11-12
7
min.

Comment mesurer l’impact social et environnemental d’une entreprise ?

2024-11-07
7
min.

Management agile : 7 clés pour embarquer vos équipes

2024-11-07
5
min.

Meta Meltdown: What Can We Learn from the Workplace Closure?

2024-11-06
8
min.

How Can You Promote Sustainable AI in the Workplace?

2024-11-04
5
min.

Collaborative Platform: Definition and Challenges

2024-11-03
5
min.

20 collaborative tools to improve employee productivity

2024-10-29
8
min.

Parole d’expert : Comment améliorer l’équité, la diversité et l’inclusion en entreprise ?

2024-10-28
6
min.

7 Best Practices for Leveraging Emotional Intelligence as a Leadership Tool

2024-10-23
7
min.

RH : Les symptômes de burnout auxquels il faut être attentif

2024-10-17
7
min.

Améliorer l’autonomie au travail, c’est possible avec ces 5 leviers

2024-10-10
5
min.

Do Purpose-Driven Companies Outperform Traditional Ones?

2024-10-09
10
min.

Best Leadership Practices for Boosting Employee Engagement

2024-10-08
7
min.

[Parole d’expert] Comment devenir une entreprise à mission ?

2024-10-08
6
min.

Turn your employees into ambassadors for your enterprise social network!

2024-10-01
8
min.

How Does AI Impact Employees Within an Organization?

2024-10-01
6
min.

How can AI shape the future of self-management: insights from the academic literature

2024-10-01
7
min.

10 exemples d’utilisation du biomimétisme en entreprise

Article
2024-10-01
6
min.

Gartner’s 10 technology trends for 2024

2024-09-30
9
min.

What Participative Decision-Making Can Bring to Your Organization

2024-09-30
8
min.

How the Next Generation Company Is Redefining the Future of Work

2024-09-30
6
min.

How Do You Tactfully Handle a Micromanaging Boss ?

2024-09-30
8
min.

How Do You Give Constructive Feedback to Your Peers in a Self-Managing Organization?

2024-09-30
8
min.

How Consent-Based Decision-Making Works

2024-09-30
8
min.

From Corporate Hierarchy to Agility: How to Create Engaged and High-Performing Teams?

2024-09-30
7
min.

Driving Culture Change with Holaspirit: Insights from Welser Profile

2024-09-26
6
min.

5 Interesting Ways AI Can Transform Knowledge Management Processes

2024-09-17
7
min.

Critères ESG : pourquoi et comment les intégrer dans votre stratégie RSE ?

2024-09-10
10
min.

How Can You Improve Organizational Agility in the Workplace?

2024-09-10
5
min.

L’entreprise à impact : LA réponse aux défis du développement durable

2024-09-09
9
min.

How to Improve Cross-functional Team Collaboration

2024-09-05
6
min.

[Expert Opinion] Amicio’s Best Practices for Agile and Effective collaboration

2024-09-03
6
min.

Les entreprises à mission sont-elles plus performantes que les entreprises traditionnelles ?

2024-08-29
7
min.

Raison d’être, vision, mission : de quoi parle-t-on ?

2024-08-29
7
min.

Performance Management: 4 Keys to Building Effective Teams

2024-08-22
6
min.

Managers: 8 Hacks for Improving Teamwork Efficiency

2024-08-20
6
min.

Entreprise régénérative : de quoi parle-t-on ?

2024-08-13
6
min.

7 techniques éprouvées pour responsabiliser ses collaborateurs

2024-08-12
6
min.

Sustainable performance: the art of combining productivity and social responsibility

2024-08-09
6
min.

How Do I Set Up My Internal Communication on Corporate Social Responsibility (CSR)?

2024-08-08
6
min.

5 Examples That Show How Different Organizations Can Leverage the Same Collaborative Platform

2024-08-06
6
min.

[Webinaire] Opportunités et risques de l’IA : ce que les entreprises nouvelle génération doivent absolument savoir !

2024-08-04
5
min.

How to implement an enterprise social network in your company

2024-08-02
7
min.

How will artificial intelligence transform the way we work?

2024-07-30
7
min.

Nos 15 podcasts de management préférés

2024-07-25
8
min.

Key Employee Engagement Data from Gallup's 2024 Study

2024-07-25
10
min.

13 Icebreaker Ideas for More Dynamic Team Meetings

2024-07-23
7
min.

6 bonnes pratiques pour améliorer la cohésion d’équipe

2024-07-22
5
min.

Why Scale Ups Opt for a Self-Management Tool?

2024-07-22
5
min.

Why Is Accountability Important in the Workplace?

2024-07-22
8
min.

The Pros & Cons of Going Teal

2024-07-22
3
min.

The Power of Spotify Squads

2024-07-22
8
min.

Setting Roles Into Your Organization

2024-07-22
6
min.

How to Implement Effective Self-Management in the Workplace

2024-07-22
7
min.

Empowering the right people in the right roles

2024-07-22
7
min.

Our Step-by-Step Guide to Effective Governance Meetings

2024-07-22
5
min.

How to Measure the Success of Holacracy in Your Organization

2024-07-22
5
min.

Integrative Decision-Making VS Consensus

2024-07-22
9
min.

How the Liberated Company Unleashes Your Employees’ Potential

2024-07-22
8
min.

How To Instil Self-Advocacy in Employees and Build Stronger Teams in the Process

2024-07-22
10
min.

💥 How can Scaleups Grow Faster and Successfully by Integrating Strategy into their Organization Structure?💥

2024-07-22
10
min.

Everything you Need to Know About Organizational Health

2024-07-22
4
min.

Finding Your Organization’s Purpose

2024-07-22
15
min.

50 Effective Employee Engagement Strategies

2024-07-22
9
min.

Effective Team Meeting: Strategies, Agendas, and Checklist Included

2024-07-19
8
min.

Why Should you Consider Implementing a Shared Leadership Model?

2024-07-19
10
min.

What is Shared Governance?

2024-07-19
7
min.

5 Tactics to Adapt Your Business to a VUCA World

2024-07-19
5
min.

How Does Employee Engagement Affect Business Results

2024-07-19
6
min.

Agile Trends 2024: What is the Next Wave of Agile Transformation?

2024-07-18
6
min.

What Makes Self-Managed Teams Unique?

2024-07-18
5
min.

The Influence of Company Culture On Employee Engagement

2024-07-18
7
min.

How Does a Flat Organization Actually Work?

2024-07-18
5
min.

Essential Meeting Room Equipment for Modernizing Your Workspace

2024-07-16
9
min.

What Does a Transparent Company Actually Look Like?

2024-07-16
13
min.

What Is Self-Management?

2024-07-16
17
min.

The Best Self-Management Tools for Your Organization

2024-07-16
7
min.

What is Sociocracy? Introducing a Toolkit for Agile Organizations

2024-07-16
8
min.

Teal Organization: Everything You Need to Know

2024-07-16
6
min.

A Guide to Tactical Meetings (Agenda Template Included)

2024-07-16
4
min.

Org Chart Templates and Visual Organization Representation

2024-07-16
7
min.

How to Clearly Define Roles and Responsibilities Within Your Team?

2024-07-16
9
min.

How QoQa Managed to Successfully Implement Holacracy Using Holaspirit

2024-07-16
8
min.

How Great Place To Work Implemented Self-Management Using Holaspirit

2024-07-16
26
min.

Holacracy: Core Concepts, Benefits and Limitations

2024-07-16
8
min.

Example of Company OKRs, How Did They Do It?

2024-07-16
8
min.

8 Best Kept Secrets of High-Performing Agile Teams

2024-07-16
12
min.

5 organizational governance models to make your teams more agile

2024-07-16
6
min.

Les meilleurs outils SaaS pour votre entreprise

2024-07-09
6
min.

Gérer la communication interne d’une association avec Talkspirit : le défi de l’ARSL!