Cybersecurity / Source date:

Pandemic Cybersecurity Crisis: Remote Work Exposes Every Weakness

The pandemic's sudden shift to remote work in 2020 exposed every security weakness that had been hidden by office perimeters — triggering a wave of breaches, ransomware, and credential theft.

Illustration of a home router, ethernet cables, an unbranded work laptop and a physical security key being checked at a domestic desk.

Three weeks ago your organisation had a perimeter, a managed device estate and a help desk that knew everyone by voice. Today it has several hundred home networks, an unknown number of personal laptops, a remote access gateway running at ten times its design load, and a help desk resetting passwords for people it cannot see. The pandemic cybersecurity crisis is not that attackers have become more capable. It is that the attack surface moved, in a fortnight, from somewhere you monitored to thousands of places you do not. That distinction matters, because it tells you where to spend the next month. Remote work security hardening is not a new programme. It is a small number of specific changes to controls you already own, made in the right order.

The gateway became the front door

The first thing to check, today, is the remote access infrastructure itself. Virtual private network appliances and application delivery controllers have been the subject of serious, widely exploited vulnerabilities over the past year, and the pattern is consistent: authentication bypass or remote code execution on an internet-facing device that terminates every session in the organisation. Those devices were under-patched when they carried fifteen per cent of the workforce. They are now the single point through which the entire company works, and in many organisations they have been hurriedly expanded, cloned or supplemented with a second box configured by someone working at midnight. So: confirm the firmware version against the vendor's advisories, confirm that patching a gateway also required rotating the credentials and session keys that may have been exposed before the patch, and confirm what else got exposed during the scramble. The most common finding this month is remote desktop published directly to the internet, on the standard port, because it was the fastest way to give the accounts team access to a server. Those are found within hours of appearing and they are how ransomware operators get in.

Identity is the only control that travels

Every network-based control you owned two months ago is now partially irrelevant. The device is on a home network. The traffic may not route through your inspection points. The building-based assumptions in your conditional access policies no longer describe anybody. What travels is identity, and this is where the month's most consequential mistakes are being made. Multi-factor authentication requirements relaxed because the help desk could not handle enrolment calls. Legacy authentication protocols left enabled so an older mail client would work from home. Administrative accounts used for daily work because it was quicker. Conditional access rules loosened to unblock a manager at 11pm. If you do only one thing this week beyond patching the gateway, restore multi-factor authentication on every administrative account and every account with access to payment systems, payroll or customer data, and do it before you get to the rest of the population. Then check for the accounts that bypass it, which is where attackers will look first. The help desk itself has become a target worth defending. Verification procedures designed for people who could be recognised by sight or voice are now conducted by phone with strangers, and the attacker who wants a password reset and an authenticator re-enrolment has never had a better environment. Put a scripted verification standard in place, using something the attacker cannot obtain from an out-of-office reply or a social profile, and require a second approver for authenticator re-enrolments on privileged accounts.

The phishing wave is real, and it is mostly ordinary

Every threat report this month leads with pandemic-themed lures, and the volume is genuine: health authority notices, employer policy updates, relief and payroll announcements, infection maps that install credential stealers, video conferencing invitations, delivery notifications. But the mechanics have not changed at all. Credential harvesting pages, attachment-borne loaders, and business email compromise asking for a payment detail change. What has changed is the human context, which is what makes it work: people are anxious, out of routine, unable to turn to a colleague and ask whether an email looks right, and receiving a genuinely unprecedented volume of legitimate messages about new arrangements. The lure does not need to be clever when the recipient has no baseline for normal. The defences are consequently the ordinary ones, applied harder: link and attachment handling, external sender marking, a one-click reporting path with a response that is fast and never punitive, and an out-of-band verification rule for any change to payment details or bank mandates that cannot be waived by seniority.

The hardening order described in the articleQualitative prioritisation from the historical source, not a current vendor-specific remediation runbook or a quantified risk model.
  1. Review the remote gateway

    Check advisories, exposed configuration and any required credential rotation.

  2. Close accidental exposure

    Identify directly published remote desktop and management services.

  3. Restore identity controls

    Prioritise privileged and sensitive accounts, then remove bypasses.

  4. Protect reset and payment workflows

    Use stronger help-desk verification and out-of-band payment-change checks.

  5. Manage endpoints and exceptions

    Track device check-ins and give every temporary exception an owner and expiry.

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Practical Guidance for Remote Work Security Hardening

  • Patch and audit the remote access gateway first, today. Firmware against vendor advisories, credentials rotated if it was exposed while vulnerable, configuration reviewed by someone who did not build it.
  • Find and remove anything published directly to the internet in the last month. Remote desktop, management interfaces, file transfer, database ports. Scan your own external addresses rather than trusting the change log.
  • Restore multi-factor authentication on privileged, finance and payroll accounts before anything else. Then work outward. Document every remaining exemption with an owner and an expiry date.
  • Disable legacy authentication protocols that bypass modern controls. These are the quiet route around every conditional access rule you have written.
  • Harden the help desk verification script. Something the caller knows that an attacker cannot read online, and a second approver for authenticator re-enrolment on sensitive accounts.
  • Impose an out-of-band rule for payment and mandate changes. A call back to a number already on file, made by someone other than the requester. No exceptions for urgency or seniority, which is precisely when it will be tested.
  • Get endpoint protection and patching working off the corporate network. Cloud-managed policy, patching over the internet, and a report of devices that have not checked in for a week. Unmanaged for a month becomes unmanaged for a year.
  • Keep a dated exception register with review dates. Every relaxed control, who approved it, why, and when it expires. This is the document that determines whether the coming months are recoverable.

The Regional Angle

Four local conditions are shaping exposure here in ways the global advisories miss. The first is that there were no laptops to buy. Regional procurement runs on imported stock through distributors, and by the second week of March corporate notebook availability had largely evaporated across the Gulf, with lead times measured in months. Organisations that could not buy devices did the only thing available and permitted personal machines, so a large share of the region's current remote workforce is operating on home computers with unknown patch levels, shared family accounts and consumer antivirus. The mitigation is not a policy document; it is technical. Publish applications through a virtual desktop or browser-isolated session so that data never lands on the device, and if you cannot do that for everyone, do it for finance, human resources and anyone with customer data. The second is the nature of a home network here. A meaningful proportion of the workforce lives in shared villas, apartments and company accommodation where one internet connection serves many unrelated residents, with a router whose administrative password is written on a label and has never been changed. That is not a household network; it is an untrusted public one with a friendly name. Treat every remote connection as hostile by default, require the tunnel for all corporate traffic rather than split-tunnelling on convenience grounds, and make device-level firewalling non-negotiable. The third is the most financially dangerous, and it is specific to this moment. Flight suspensions have left authorised bank signatories, directors and owners outside the country, and branches are operating on limited hours. The result is a wave of hurried delegation: powers of attorney granted remotely, mandate changes submitted by email, temporary authority given to whoever is physically present, and payment instructions approved by message because the signatory is in another time zone with no way to return. Every element of that is exactly what a business email compromise attempt needs. If your organisation is changing banking authority this month, do it through the bank's formal process with verified documentation, record the change internally, and set a date to reverse it. The fourth is a lure with local specificity. Movement permits, government service portals and employer registration systems have become central to daily life across the Gulf in a matter of weeks, and lookalike domains offering permits, clearances and relief applications have followed. Staff who would never click a parcel notification will absolutely click a permit approval. Tell them, by name, which official portals your organisation uses, that requests will never arrive by message with a link, and where to report the ones that do.

The objection worth taking seriously

The fair criticism of security teams this month is that we are enjoying ourselves. The advisories, the threat maps, the daily bulletins about pandemic-themed phishing: all of it has an undertone of vindication, aimed at businesses that are currently trying to keep paying people. Telling a finance director whose revenue has stopped that they must now fund an identity programme is, in the current climate, close to tone deaf. The controls that were relaxed were relaxed to keep the organisation alive, and that was the correct trade. The second objection is evidentiary. Phishing volume is up, and volume is not the same as successful compromise. Much of what is being reported is vendor marketing dressed as intelligence, using an increase in malicious domains containing a keyword as a proxy for risk. We do not yet have reliable data showing a step change in breach outcomes, and the honest position on the first of April is that we are describing exposure rather than measuring loss. Both are right, which is why the guidance above is narrow and cheap. Patch the gateway, close what got exposed, restore multi-factor authentication on the accounts that can move money, harden the help desk script, and keep a register of exceptions. None of that is a programme, a platform or a business case. It is a fortnight of work by people you already employ, protecting the two dozen accounts whose compromise would matter, and it is defensible precisely because it does not ask a business in survival mode to fund a transformation. The transformation argument can wait until the exception register comes up for review.

Common Questions

Should we ban personal devices?

Not if the alternative is that people cannot work. Remove the data instead: publish applications rather than distributing them, prevent local storage, and prioritise managed devices for roles with the most sensitive access.

Is our video conferencing platform safe?

Check the configuration before the brand. Require meeting passwords, disable open screen sharing, restrict recording and control who can join. Most incidents in the past fortnight have been default settings rather than platform flaws.

How do we handle staff who have not connected in weeks?

Build the report of devices that have not checked in, and treat it as an operational queue with a named owner. Every week offline is another month of missing patches.

What should we expect over the next twelve months?

Expect the emergency exceptions granted in March to be exploited later in the year, because attackers are patient and exposed remote access does not expire. Expect ransomware operators to concentrate on remote access and single-factor accounts, which are now the most reliable entry points in most organisations. Expect video conferencing security and privacy to become a procurement requirement rather than a preference. And expect identity, not network, to take the largest share of next year's security budget for the first time.


Remote Work Security Hardening — we start with the gateway, the exposed services and the accounts that can move money, and leave you with a dated register of every exception so March does not become permanent.

Continue reading

Talk to OPS

Start with the operating problem.