Connect with us

Hi, what are you looking for?

BUSINESS

Strengthen risk management programs – RSA Security

For Ramon Karingal, Chief InfoSec and Risk Advocate for Asia Pacific and Japan of RSA Security, “Disruptions demand everyone’s attention, and if they extend over a long period of time, the risk of not achieving business objectives can create strategic risk.”

When COVID-19 happened, Ramon Karingal, Chief InfoSec and Risk Advocate for Asia Pacific and Japan of RSA Security, noted that there were three common tech issues most of their customers encountered.

First, there’s the shortage of corporate technology equipment to provide for most of their employees who are now working from home. “Some organizations had to allow the use of personal devices to access their corporate network. Setup and connectivity issues were also encountered by some of our customers, especially making sure they have a secured way of accessing the corporate network,” Karingal said.

Second, “some organizations reported having technology infrastructure capacity issues, e.g. compute, storage and network capacity to support their customer-facing online applications.  Organizations resorted to migrating some of their internal and non-sensitive applications to public cloud like AWS or Azure.”

And third, “our RSA Anti-Fraud Command center has reported a rise in pandemic-specific scams through the form of phishing, smishing, brand abuse and the like.  A lot of the fraudsters are taking advantage of the panic and confusion surrounding COVID-19.” 

Advertisement. Scroll to continue reading.

These issues weren’t really surprising.

“The COVID-19 pandemic has a far-wider impact that potentially affects almost every household globally when compared to other instances that also wreaked havoc to tech use of companies/people (like Y2K and the Thai flooding that affected businesses all over Asia).  COVID-19 pandemic perhaps could be the only instance where every country in the world had to issue stay-home orders to all citizens, except for those performing essential services, like doctors, nurses, policemen, firemen, etc.,” Karingal said.

 Also, “the duration of the current COVID-19 pandemic is more prolonged compared to other incidents/disaster.  It’s been more than a semester since the COVID-19 outbreak in most countries; and, there is still no indication where this pandemic will end.”

Finally, “post-COVID-19, things are not going back to normal unlike other instances/disasters.  There will be a different and new normal way how companies/people will make use technology post COVID-19.”

NAVIGATING HARD TIMES

Advertisement. Scroll to continue reading.

For Karingal, there are some security-related tips for companies/businesses as they move forward for them to successfully navigate or face similar pandemics like COVID-19.

First, “provide employees with the capability to securely access the corporate network when working either in the office and/or remotely from location outside the office,” he said.

Second, “provide continuous education and reminders to employees on cybersecurity aware and safety, especially on phishing and identity thefts.”

And third, “improve organization capability to detect and respond to any cybersecurity-related incidents by either building inhouse cybersecurity capabilities or subscribing to managed services.”

RSA Security, in fact, has offerings that eye to specifically deal unforeseen instances like COVID-19. These include:

Advertisement. Scroll to continue reading.
  • SecurID Suite – risk-based MFA identity access management.  This should be part of the minimum security controls organizations should adopt while providing remote access
  • NetWitness Platform – Cyber security solutions for the Security Operations Center which includes our Evolved SIEM, EDR, EUBA and SOAR technologies
  • Archer Integrated Risk Management – to help automate and simplify organizations’ Governance, Risk and Compliance processes
  • Fraud & Risk Intelligence Suite – to help organizations mitigate fraud risk and protect their brand and customer transactions

The RSA brand is being carried by VST ECS Phils., Inc, the largest ICT distribution company in the country.

MOVING FORWARD

Knowing that something like Covid-19 may happen again, what is the best lesson that companies/businesses can learn from this experience?

“Organizations should learn from their experience in dealing with the unexpected disruptions that they may have encountered arose during COVID-19 – workforce, business operations, supply chain and security. Challenges like enabling most of your employees to work from home with the necessary secure access and authentication technologies and controls in place. Third parties like partners, vendors, contractors and supply chains your organization engages should also be considered in terms of their capability to provide the required support to your organization in delivering services to your customers,” Karingal said.

He added that during disruptions, other risks organizations are dealing with don’t stop. In fact, they may even escalate as bad actors try to take advantage through cyberattacks or fraud. Regulatory compliance can receive less attention as teams change their focus to current business impacts. 

“Disruptions demand everyone’s attention, and if they extend over a long period of time, the risk of not achieving business objectives can create strategic risk,” Karingal said. “It is critical to ensure your risk management program enables you to continue to identify new risks, evaluate and measure critical risks, take appropriate steps to manage the risks within acceptable tolerance levels, and advise executives on decisions they need to make.”

Advertisement. Scroll to continue reading.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

White Papers

When compared to 2023, Sophos saw a 51% increase in abusing “Living off the Land” binaries or LOLbins; since 2021, it’s increased by 83%.

HEADLINES

Someone illegally acquires or uses personal information such as bank account or credit card numbers of another person to obtain money, goods or services....

HEADLINES

To stay ahead of these challenges, organizations need to invest in AI-driven defenses, transition to quantum-safe encryption, and adopt a Zero Trust approach to...

HEADLINES

There was a 121% Year-on-Year (YoY) increase in identity fraud in 2024 across the region, with significant surges recorded in Singapore (207%), Thailand (206%)...

HEADLINES

As part of RCBC’s 2024 Cybersecurity literacy program, the webinar aims to help Filipinos level up their online banking safety by providing them with...

White Papers

The survey found that CXO’s feel less prepared than their global peers. Less than half or 48% in APAC said they felt completely prepared...

HEADLINES

On average, a single organization in the Philippines experiences 4,003 attacks per week, significantly higher than the APAC average of 2,870 attacks per week.

White Papers

Exploiting this vulnerability, cybercriminals craft deceptively authentic phishing emails that align with current trends, exploiting human emotions to invoke urgency and trick recipients into...

Advertisement