Many of us are still using work passwords for personal use
One-third of the companies don’t even suggest using a VPN to log into work remotely.
When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.
Many employees admit to using their workpasswordsfor signing into consumer websites, new research has claimed.
The 2021 Secure Consumer Cyber Report by automation platform Ivanti found that one in four admitted using an official workemailor password to log in to websites and applications such as food delivery apps, online shopping sites and even dating apps.
A sizeable propotion were also found not to have any password update policy, nor do they ask their employees to have specificsecurity softwarewhile working remotely.
Zero trust model
The survey follows Ivanti’s observation that the use of insecure, unmanaged, and unsanctioned IoT devices has emerged as a popular attack vector last year.
“The FBI issued a warning about an increase in credential stuffing attacks in September 2020 and yet consumers are still using work emails and passwords to log in to consumer apps and websites, putting the enterprise at significant risk of a credential stuffing attack,” noted Ivanti’s Chief Security Office, Phil Richards.
As an increasing number of employers work from home on theircompany-provided laptops, Richards believes that given the increase in data breaches of consumer-based websites and apps, chances are that several enterprise email and passwords have already made their way into the hands of unscrupulous elements.
“Companies across all industries must implement a Zero Trust model to ensure that entities accessing corporate information, applications, or networks are valid and not using stolen credentials,” Richards suggests.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
When it comes to remote working, the survey also discovers that enterprises have been unable to secure several key areas. It notes that 30% of the respondents said their organization doesn’t require remote workers to use a secure access tool, such as aVPN.
With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’sTechRadar Pro’sexpert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.
Phishing attacks surge in 2024 as cybercriminals adopt AI tools and multi-channel tactics
This new phishing strategy utilizes GitHub comments to distribute malware
Arcane season 2 finally gave us the huge Caitlyn and Vi moment we’ve been waiting for – and its creators say ‘we couldn’t have done it in season one’