惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
V2EX - 技术
V2EX - 技术
T
Troy Hunt's Blog
TaoSecurity Blog
TaoSecurity Blog
Attack and Defense Labs
Attack and Defense Labs
SecWiki News
SecWiki News
M
MIT News - Artificial intelligence
N
News and Events Feed by Topic
Help Net Security
Help Net Security
IT之家
IT之家
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
The Last Watchdog
The Last Watchdog
Martin Fowler
Martin Fowler
Hacker News: Ask HN
Hacker News: Ask HN
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
H
Heimdal Security Blog
B
Blog
Blog — PlanetScale
Blog — PlanetScale
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Hacker News - Newest:
Hacker News - Newest: "LLM"
T
Threat Research - Cisco Blogs
I
InfoQ
腾讯CDC
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Know Your Adversary
Know Your Adversary
Cloudbric
Cloudbric
Project Zero
Project Zero
T
Tor Project blog
小众软件
小众软件
博客园 - 司徒正美
www.infosecurity-magazine.com
www.infosecurity-magazine.com
H
Help Net Security
Webroot Blog
Webroot Blog
量子位
NISL@THU
NISL@THU
Schneier on Security
Schneier on Security
Google Online Security Blog
Google Online Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
月光博客
月光博客
宝玉的分享
宝玉的分享
V
V2EX
T
Tailwind CSS Blog
Spread Privacy
Spread Privacy
G
Google Developers Blog
K
Kaspersky official blog

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report Implementing AI Assurance Safeguards Before OMB’s December Deadline The Next AI Wave: Quantum AI CDM’s Evolution to Non-Traditional Technology: Why Now and How Will it Succeed? Customer Expectations Require Agencies to Raise the Bar on Customer Experience, Report Shows Applying for Government Benefits Shouldn’t Be Difficult When It Comes to Identity Verification Four Federal Software Supply Chain Security Trends to Watch FedRAMP Baseline Transition Points to OSCAL-Native Tools What Zero Trust Means for Modern Government: Best Practices for Key Tenets Four Ways to Handle the IT Funding Crunch Agencies Need to Get Creative to Fill the Cyber Workforce Gap Customer Identity trends report shows control trumps convenience Federal Agencies Making Strides Toward Sustainability and Climate Action Executive Order 14028 | Improving the Nation’s Cybersecurity Depends on Data | All Data is Security Data Applying Geospatial Intelligence, AI/ML to Climate Change Challenge My Cup of IT: Angry at Arthritis, Hunting for Cures How the Federal Government Can Help Combat a Fragmented Internet Accelerating Cybersecurity for US Critical Infrastructure Getting in on the Ground Floor of the ‘New Observability’ Comply-to-Connect is Key to Zero Trust for DoD How Will Upcoming Cryptocurrency Regulations Affect Industry? My Cup of IT: Cup Cake for Kushner? Launching a New Era of Government Cloud Security Managing IT Complexity in Federal Agencies Agencies Must Modernize Zero Trust Approaches to Achieve Optimal Protection Five Essential Metrics for Measuring Federal Government CX Unlocking the Benefits of 5G and Beyond The Federal Factory of the Future: How AI is Transforming Manufacturing The Quantum Impact on Cyber How Next-Gen Computers Will Transform What’s Possible for Federal Government Agencies Must Take an Authentic Approach to Synthetic Data Biometrics and Privacy: Finding the Perfect Middle Ground Two-Way Street: Why Officials and Constituents Are Equally Responsible for Securing the Midterms The “Programmable World” Will Bring the Best of the Virtual World Into the Physical One Cyberattacks are a Common Occurrence and the Costs are Higher Than Ever Increasing Equity Through Data and Customer Experience The AI Edge: Why Edge Computing and AI Strategies Must Be Complementary How Metaverses and Web3 can Reshape Government Four Emerging Technology Trends set to Impact Government Most 5G Enables AI at the Edge Plugging Cyber Holes in Federal Acquisition Resilient Critical Infrastructure Starts with Zero Trust The Evolution of Government Tech Procurement Under CMMC 2.0 Zero Trust Requires Continuous, Tested Security for Federal Agencies How Multi-INT Fusion Accelerates Mission Intelligence for Real-Time Decision Advantage Three Things to Consider for Responsible AI in Government Legislation, White House Orders Show Agencies Opportunity for Hybrid Cloud Creating an Effective Framework for DoD’s Software Factories A Future With AI and ML: The Power of Workforce Education Five Tips to Begin MFA Integration and Embrace Zero Trust The Vital Intersection Between Equity and Digital Transformation Equity as a Platform: Applying a New Mindset to Scale Innovation Harnessing the Right Data for Evidence-Based Equity From EO to Action: Human Factors of Enabling a Cyber Safety Review Board For Equity in Government Services, It’s Time to Change the Paradigm Critical Questions to Ask When Considering Explainable AI (XAI) for Your Federal Agency The Telework Model for Government: COVID Lessons for Building an Effective Workforce DevSecOps: 4 Steps for Mitigating the Next Cyber Attack in Your Federal IT Environment Better Cyber Hygiene Helps, but Federal Security Needs SASE Lift DoD, Feds Plot Top Cyber, Cloud Priorities for 2022 Cloud-Native Government: How to Transform With Intention DoD and VA Health Networks Face Growing Threat From Medical-Device Vulnerabilities New Federal Cybersecurity Requirements: How Agencies Should Implement a Zero Trust Architecture Protecting Our Nation Through Big Data Analytics Three Ways COVID-19 Altered Federal, State IT Budget Allocations Ransomware is More Than a Cybersecurity Issue From Me to We: Take the Mission Further With Multiparty Systems Anywhere, Everywhere: Integrating Your Virtual Workplace ‘I, Technologist’: Empowering Innovators in the Federal Workforce Mirrored World: Digital Twins Report for Duty Across Government Stack Strategically: Rearchitecting Government for What’s Next
Realizing Upsides for Digital Security in the Hybrid Workplace
Ann Cleavela · 2022-03-10 · via MeriTalk

If and when the COVID pandemic fades into history, the shift toward remote and hybrid work is poised to persist. In an April 2021 Forrester Consulting survey of more than 1,300 security leaders, business executives, and remote workers, 70 percent said their organizations will have employees working from home one or more days a week during the next 12 to 24 months.

Amid its challenges, hybrid and remote work represents a significant opportunity in terms of human capital development. Many employees welcome the flexibility associated with hybrid work, and firms that allow remote roles can recruit without regard to location, increasing their potential applicant pools.

The problem is, we’ve only just begun to grapple with the digital security challenges ushered in by remote and hybrid work. Sixty-seven percent of respondents to the Forrester survey reported they had experienced “business-impacting” cyberattacks that specifically targeted remote workers.

Privacy and security challenges lie at the intersection of technology, human behavior, and policy. For example, as more and more workers are logged in to corporate networks from their homes, workers’ smart speakers, thermostats, or other “smart” devices — and their vulnerabilities — are now part of the virtual work environment.

There are also more opportunities for workers to inadvertently reveal proprietary or sensitive corporate data to others in their household, whether family members or roommates. And in an era of video conferencing, they may also risk revealing protected characteristics of themselves and their household. As a result, hybrid work could lead to a range of novel equity and liability concerns. For businesses operating across jurisdictions, the multitude of policy regimes that govern data make these privacy considerations even more complex.

For all these challenges, though, the shift to hybrid has plenty of potential upsides. The University of California, Berkeley’s Center for Long-Term Cybersecurity recently published a

paper, Security and Privacy Risks in an Era of Hybrid Work, that spells out recommendations for managing many of the emerging privacy and security issues attached to hybrid work environments, based on interviews with security, policy, human resources, and other leaders from private firms and government agencies.

The good news is that the shift to hybrid offers a rare opportunity to break through many of the long-standing habits and assumptions that have negatively impacted privacy and security.

First, firms now have more incentive than ever to move toward so-called “zero trust” architectures, which promise a seamless experience for employees and state-of-the-art digital security for employers. The zero trust model uses both multi-factor authentication and continuous authentication of the users and devices on a network, regardless of where they are located. Until now, many firms have been slow to adopt zero trust given its complexity and the investment required.

But we must do better to bring down the cost and simplify implementation for businesses of all sizes – hybrid work makes even more clear that the old password-based model is no longer a sustainable solution. Industry and government must work together to invest in zero trust and build awareness of its benefits.

Another habit that needs to be broken: conversations about security and privacy between firms and employees need to occur at a deeper level than boiler-plate consent agreements or an annual compliance-based cybersecurity training. Employees are uncertain about expectations concerning their own privacy in the hybrid workplace, as well as how they might protect firm data.

Solutions include investing in fresh approaches to employee training, creating mechanisms to make a firm’s security and privacy commitments visible in the context of an employee’s hybrid workday, and building coalitions of firms to establish a consensus on expectations for security and privacy. Firms that do engage in a robust discussion around privacy and data protection expectations with employees will reshape norms and improve security while strengthening their relationships with workers.

At a higher level, government investment should be allocated to improve home network security. Through the recently passed bipartisan infrastructure deal (Infrastructure Investment and Jobs Act), the U.S. Federal Government is set to invest approximately $65 billion in broadband to improve internet access, speeds, and pricing, with two-thirds of this funding to be allocated to the Department of Commerce Broadband Equity, Access, and Deployment Program. Broadband is a necessary ingredient for workers in less privileged circumstances to participate effectively in the hybrid labor market, but connectivity alone is not sufficient.

A more refined policy should repurpose some of these funds (or expand the overall pool of investment) to subsidize other parts of the hybrid work environment, including, for example, secure routers and other home network equipment. “The last mile” for internet connection (such as the coaxial cable from the street to the home router) should now extend fully into the home network and reflect the security and privacy requirements associated with hybrid work, regardless of whether the home is rented or owned.

Realizing all these potential upsides — and breaking through past habits and assumptions — will require a combination of legislative and regulatory action, roles for industry associations, and new tools and technologies. Security and privacy in the hybrid work environment will be tied tightly to productivity, equity, and innovation in the next decade. How firms and policymakers converge around new privacy and security considerations will determine whether hybrid work lives up to its promise.