On this episode of Cyber Security Inside, Tom and Camille dive into a topic that’s on all of our minds: What does security look like in the new WFH and IOT era? Is it good enough to secure our devices or do we need to be thinking about network security as well? Mauricio Sanchez, Network Security Research Director at Dell’Oro Group, shares his insight.

The conversation includes:

• Shadow IT

• WFH

• IOT

• SaaS

• Network security best practices for the new era

• Data leakage prevention

• Cloud malware

• Phishing

• 5G

... and more!

Plus, they close with some interesting takeaways on tea origins, fire ants, and the astounding number of connections being built in a human baby’s brain every second.

Tune in. You don’t want to miss it.

Here are some key take-aways:

• In this new era of WFH and IOT, i’s not enough to protect our devices. We have to also think about how those devices are talking to each other.

• With the increase in teleworkers and the departure from the corporate confines, there’s an increase in threat exposure. The distributed environment makes it all too easy for data to be lost inadvertently or maliciously.

• When experience suffers, people find ways to circumvent corporate security and access the data directly. That’s where new threats come into play.

• There’s been an increase in attacks from a data perspective against SaaS-based applications. Hackers are realizing that, by cracking a SaaS application, they’re getting access to the same class of data that once lived inside the corporate confines.

• Once inside, hackers are focusing on distributing malware to get deeper into the corporate ecosystem.

• The network architecture of the past isn’t conducive to the new trends that have exploded over the course of the last 18 months.

• All IT teams are now having to participate in the overall security outcome of the enterprise.

• Enterprises need to treat the internet as an extension of the enterprise network.

Some interesting quotes from today’s episode:

“When you look at enterprises and how they conduct their business, what we are seeing is that this work from home phenomenon is here to stay at a much higher level than it was pre-pandemic. And so when you start thinking about that, that then has a number of ripple effects when you think about networking or security.”

“From a network architecture perspective, that classical model of sending backhauling stuff back to the data center and then squirting it back to the internet has a number of problems.”

“As enterprises move to a SaaS-based model and rely on third parties, it becomes extremely important to make sure that the network and the IT infrastructure in general plays a role in making sure that the right connections are happening between the right users and the right applications.”

“It’s all too easy for a user — really by accident, not necessarily maliciously — to push a sensitive document to the wrong spot in the internet, because all of these are internet-based applications, like One Drive or SharePoint. Then all of a sudden you have a leakage scenario come about.”

“They're now pivoting towards blasting corporate accounts that sit off on Google Suite or Office 365. Once they do crack the password and get access to the data, they're placing malware on those file shares that looks like legitimate files. And it’s becoming a way to distribute malware to get deeper into the corporate ecosystem.”

“From a network architect's perspective, the world was much simpler before the pandemic, before the ascension of large ranks of teleworkers, before the internet application — because everything was much more contained and monolithic.”

“The internet is becoming the enterprise network for a business. And this is a huge philosophical shift for those people that grew up in the age of being able to touch the box, know what fiber the packets were running on, and really own the end-to-end network themselves.”

“If a business was predicated on having their employees having to come into the office, and that enterprise wasn't really internet and remote worker friendly, then they found themselves having to catch up and make themselves a little bit more internet friendly.”

“Enterprises have to embrace the SaaS-based because not all workloads are going to come back as proprietary workloads and applications. But there are probably some applications that will be coming back on-prem, which then relieves a little bit of the pressure of having to go full SaaS model.”