5 Digital Transformation-Driven Cybersecurity Considerations

On their road to recovery from the pandemic, businesses face unique dilemmas. This includes substantial and entirely necessary investments in digital transformation, however tight budgets are making such endeavors difficult if not impossible. Businesses continue to struggle with pivots like adopting new digital platforms, shifting their corporate model to resolve supply chain disruption and enabling a remote workforce.

The inability for businesses to quickly adopt technologies that support digital transformation processes, including identity-based segmentation, virtual desktop interfaces and full-stack cloud, is hindering their ability to adequately address new threats and even to test new security systems and protocols.

“Now more than ever, it’s imperative to remediate risk exposure and vulnerabilities within an organization’s existing systems—optimally from the get-go,” urges cybersecurity expert Nishant Srivastava, Cyber Security Architect and field expert at Cognizant—an IT Solutions and Services firm for which he's focused on designing and implementing Identity and Access Management (IAM) solutions. “Biggest threats should get highest priority, of course, but the magnitude or even likelihood of a threat should not be the sole consideration. Organizations should also look at other forms of value that new technologies can bring.”


Below Srivastava, a senior-level IAM, governance and cyber risk authority, offers key digital security vulnerabilities businesses need to be mindful of given increased digital dependency  amid the   pandemic. Heed these best practices to help keep your company—and customers—uncompromised.

Consumer-Facing App Gaps
 

For consumer-facing web applications, some of the biggest security threats include path traversal, cross-site scripting (XSS), SQL injections and remote command execution. Of course, protecting customer data is an utmost security concern and breaches abound. One of the biggest challenges to address these kind of issues lies with lacking human resources. There is a lack of aptly trained and skilled security staff in even the most sophisticated of regions, which is cultivating a gap in cybersecurity skills across the globe. It goes without saying that employee training and investing in highly-qualified staff are among the best ways to establish, maintain and uphold security levels of consumer facing apps. Rifts, however small, can induce excessive damage and losses.


eCommerce Exposure

Online delivery businesses that are aware of security risks would be wise to introduce more secure logins, automatic logouts and random shopper ID verification and are preventing shoppers from swapping devices when ordering. Such measures will help thwart breaches that expose of customer names, credit card information, passwords, email addresses and other personal and sensitive information.

Companies selling goods or services online also should not launch without a secure socket layer (SSL) connection. It will encrypt all data transfer between the company’s back end server and the user's browser. This way, a hacker won’t be able to steal and decode data even if he or she manages to intercept web traffic.

Another useful strategy is to enforce password limitations. Passwords should be as complicated as possible with a combination of symbols, numbers and letters. Investing in a tokenization system is worthwhile because any hacker who accesses the back end system can read and steal sensitive information, which is held in the database as plain text. Some payment providers tokenize cardholder information, which means a token replaces the raw data so the database then holds a token rather than the real data. If someone steals it, they can’t do anything with it because it’s just a token.

Ransomware Recourse

Ransomware threats are escalating, which is why those doing business digitally should enforce a multi-layer security strategy that incorporates data loss prevention software, file encryption, personal firewall and anti-malware. This will protect both a company’s infrastructure and its endpoint.

Data backups are key because there’s still a mild chance of a breach even with all of the aforementioned security solutions in place. The easiest and most effective way to minimize cyberattack damage is to copy files to a separate device. This very reliable form of backup makes it possible for people to recommence work as usual with little to no downtime, and all their computer files intact, should an attack occur.

Gone Phishing
 

Gmail blocks over 100 million COVID-related phishing emails every day, but more than 240 million are sent. That means less than half sent via Gmail alone are blocked. Experts cite imposing limits on remote desktop protocol (RDP) access, multifactor authentication for VPN access, in-depth remote network connection analysis and IP address whitelisting as some of the best strategies to maintain security. In addition, businesses should secure externally facing apps like supplier portals that use risk-based and multifactor authentication—particularly for apps that would let a cybercriminal divert payments or alter user bank account details.


Shielding Teleconferences

The shift to remote work after the pandemic hit has given cybercriminals more and more opportunities, directing their focus on the tools people use for work. It’s important that people recognize their vulnerabilities, particularly while they work from home. Among these are hacked videoconference passwords and unprotected videoconference links, which criminals can use to access an organization’s network without authorization. Many people who work from home do not use secured networks, unknowingly and unintentionally. Many are just not aware of the risks.

To avoid online teleconference security issues, meetings should always be encrypted. This means a message can only be read by the recipient intended and that the host must be present before the meeting begins. There should also be waiting rooms for participants. Screen share watermarks, locking a meeting, and use of audio signatures are additional recommendations.

When asked what his best advice would be to tweak security for a workforce that’s predominately working remotely, Nishant says that companies should start by analyzing the basics (like those specified above) against the backdrop of a wide range of ever-escalating and evolving threats. “Employees should use dual-factor authentication and make sure apps, mobile phones and laptops are updated and that available patches and updates are always installed,” he says. “They should certainly be wary of all information requests and verify the source. These even include unexpected calls or emails seemingly from colleagues.”
 

Srivastava also pointed out that insiders at the CIO Symposium in July 2020 agreed that the pandemic packed years of digital transformation into just a few weeks. The use of third parties emerged as a major security concern to take into account. For instance, some employees abroad were unable to move their computers to their homes, so employers rushed to supply them with new equipment. In the process, some of it was not set up correctly thus compromising security. Companies should have done more to determine out whether individuals were using technology properly, such as if employees were sharing work devices or using their own personal equipment.


On the plus side, the shift toward working from home sped up multi-factor authentication adoption. This is a great opportunity that today’s digitally-driven businesses should take advantage of.

In short, Srivastava advocates taking a zero-trust approach. “It might sound harsh, but this is the idea that you can’t trust devices, people and apps by default,” he says. “Everything needs to be authorized and authenticated. Users should always verify and never trust, and businesses should act as if there has already been a breach and work to shore up weak links in the security chain. Finally, businesses should give access to information and data to as few people as possible—and wholly ensure those who do have access are appropriately trained to recognize when a red flag presents.

By employing all or even some of the advice above, businesses can continue to thrive as the digital transformation age unfolds—and do so more confidently and contently all around.

Become a contributor

Spotlight

The Luxe List

The best of the best across all product, service and travel categories–as well as noteworthy marketplace change makers, movers and shakers–are spotlighted in her exclusive “The Luxe List” reporting, which reaches millions each month through multiple syndication channels: print and online as well as broadcast TV and terrestrial radio. An array of top-tier online and print media outlets like Forbes.com (with 53 million unique visitors), FastCompany.com, BlackEnterprise.com, ThriveGlobal.com and more publish Merilee’s feature article content. Among her copious editorial endeavors, Merilee serves as Features Editor for Impact Wealth—a luxury lifestyle magazine catering to ultra-high net-worth individuals, reaching the richest 4 percent of the U.S. and global populations with average household income of $10 million+ and average net worth of $100 million+. The magazine is distributed to one of the largest Family Office Networks in the world. Merilee is also the creator, executive producer and host of the Savvy Living TV show that airs in New York on the CBS-TV owned/operated WLNY, in Los Angeles on the CBS-TV owned/operated KCAL, in San Francisco on CBS-TV KPIX, in San Diego on FOX and CBS-TV KGTV and in Miami/Ft. Lauderdale on the CBS-TV owned/operated WBFS. In addition, she’s a recurring guest with multiple other international, national and regional TV and radio programs. This includes the internationally-syndicated “The Jet Set” travel TV program, and nationally-syndicated shows like Coffee With America, Daily Flash, Daytime, The Tech Show, and more. She is also a frequent contributor to an array of major market/network regional TV programs airing in key DMAs like NBC’s Atlanta & Company (#10 DMA), ABC’s The Morning Blend Tampa/St. Pete (#11 DMA), ABC’s Sonoran Living Phoenix (#12 DMA) and others across the U.S. Since 1994, Merilee has worked to bring various multi-industry B2B and consumer-facing projects to the public consciousness. Over the past decade, hundreds of her articles, news items and interviews have been featured by media outlets worldwide and her expert insights have been featured by top-tier media like Bloomberg and American Express. Merilee is also a highly regarded communications industry expert source within the media, contributing perspective and commentary to leading media outlets. An instant Google search for “Merilee Kern” yields thousands of results that provide a strong sense of the breadth of her experience, reach, and presence. As a former fitness competitor and champion twice over, having won the title of “Miss South Florida” and “Miss Palm Coast,” Merilee is also a health advocate and published author whose childhood obesity-related fictional title, “Making Healthy Choices – A Story to Inspire Fit, Weight-Wise Kids,” earned a coveted iParenting Media ‘Excellent Product’ award as well as acclaim from Oprah’s personal trainer Bob Greene and media personality Sally Jessy Raphael. https://luxelistreviews.com/wp-content/uploads/2014/09/kusi-football-SM-300x196.jpgAmong other honors realized throughout her career, Merilee was named a Finalist in the 3rd annual Stevie Awards for Women in Business – an international competition recognizing the accomplishments of outstanding women executives, business owners, and the companies they run, hailed by the New York Post as “the business world’s own Oscars.” Merilee holds a Master of Business Administration degree with a marketing specialty and a Bachelor of Science degree, both earned from Nova Southeastern University in Fort Lauderdale, Florida. She also received “Marketing on the Internet” certification from the University of Massachusetts Dartmouth. Merilee is currently a member in good standing with Luxury Society, the International Food, Wine & Travel Writers Association, the North American Travel Journalists Association, the International Travel Writers Alliance and the National Association of Professional and Executive Women (NAPEW).

Spotlight

The Luxe List

The best of the best across all product, service and travel categories–as well as noteworthy marketplace change makers, movers and shakers–are spotlighted in her exclusive “The Luxe List” reporting, which reaches millions each month through multiple syndication channels: print and online as well as broadcast TV and terrestrial radio. An array of top-tier online and print media outlets like Forbes.com (with 53 million unique visitors), FastCompany.com, BlackEnterprise.com, ThriveGlobal.com and more publish Merilee’s feature article content. Among her copious editorial endeavors, Merilee serves as Features Editor for Impact Wealth—a luxury lifestyle magazine catering to ultra-high net-worth individuals, reaching the richest 4 percent of the U.S. and global populations with average household income of $10 million+ and average net worth of $100 million+. The magazine is distributed to one of the largest Family Office Networks in the world. Merilee is also the creator, executive producer and host of the Savvy Living TV show that airs in New York on the CBS-TV owned/operated WLNY, in Los Angeles on the CBS-TV owned/operated KCAL, in San Francisco on CBS-TV KPIX, in San Diego on FOX and CBS-TV KGTV and in Miami/Ft. Lauderdale on the CBS-TV owned/operated WBFS. In addition, she’s a recurring guest with multiple other international, national and regional TV and radio programs. This includes the internationally-syndicated “The Jet Set” travel TV program, and nationally-syndicated shows like Coffee With America, Daily Flash, Daytime, The Tech Show, and more. She is also a frequent contributor to an array of major market/network regional TV programs airing in key DMAs like NBC’s Atlanta & Company (#10 DMA), ABC’s The Morning Blend Tampa/St. Pete (#11 DMA), ABC’s Sonoran Living Phoenix (#12 DMA) and others across the U.S. Since 1994, Merilee has worked to bring various multi-industry B2B and consumer-facing projects to the public consciousness. Over the past decade, hundreds of her articles, news items and interviews have been featured by media outlets worldwide and her expert insights have been featured by top-tier media like Bloomberg and American Express. Merilee is also a highly regarded communications industry expert source within the media, contributing perspective and commentary to leading media outlets. An instant Google search for “Merilee Kern” yields thousands of results that provide a strong sense of the breadth of her experience, reach, and presence. As a former fitness competitor and champion twice over, having won the title of “Miss South Florida” and “Miss Palm Coast,” Merilee is also a health advocate and published author whose childhood obesity-related fictional title, “Making Healthy Choices – A Story to Inspire Fit, Weight-Wise Kids,” earned a coveted iParenting Media ‘Excellent Product’ award as well as acclaim from Oprah’s personal trainer Bob Greene and media personality Sally Jessy Raphael. https://luxelistreviews.com/wp-content/uploads/2014/09/kusi-football-SM-300x196.jpgAmong other honors realized throughout her career, Merilee was named a Finalist in the 3rd annual Stevie Awards for Women in Business – an international competition recognizing the accomplishments of outstanding women executives, business owners, and the companies they run, hailed by the New York Post as “the business world’s own Oscars.” Merilee holds a Master of Business Administration degree with a marketing specialty and a Bachelor of Science degree, both earned from Nova Southeastern University in Fort Lauderdale, Florida. She also received “Marketing on the Internet” certification from the University of Massachusetts Dartmouth. Merilee is currently a member in good standing with Luxury Society, the International Food, Wine & Travel Writers Association, the North American Travel Journalists Association, the International Travel Writers Alliance and the National Association of Professional and Executive Women (NAPEW).

RELATED ARTICLES