Workers outside the office are increasingly the targets of malicious attacks, and unsafe behavior by remote workers is one of the key factors behind a projected increase in security spending around the world.
New research sponsored by Cisco among more than 2,000 remote workers and IT professionals in 10 countries revealed that 62 percent of companies will increase spending on security this year. More than half of those companies will see security investments increase more than 10 percent compared to 2007.
Remote workers are less secure than ever, thanks to advances in Web technology and a new focus by attackers. “Web 2.0 is adding to a lot of the threats we’re finding out there today,” said Patrick Gray, senior security strategist for Cisco. Road warriors and telecommuters are visiting social-networking sites in greater numbers, prompting attackers to follow. That means protection strategies need to change, Gray said.
“We used to focus on internal security and beefing up VPNs and so on, and getting the message out on worms and viruses. Now we need to change the message to let our workforce know that we’re seeing a lot of drive-by downloads of malware out there, specifically in those kinds of sites,” Gray said, referring to social-networking sites like MySpace and Facebook.
Global Attacks
As security risks change, so do the targets of attacks, Cisco’s research shows. In the past, malware attacks such as viruses were aimed at the densest markets for maximum effect. But social-engineering attacks that prompt victims into unsafe behavior such as opening suspicious e-mails are now targeting countries such as China, India and Brazil, where security education is lagging, said Mia Bradway Winter, senior awareness program manager with Cisco. “Workers in those countries are not really familiar with what social engineering is. It’s easy to tap into that human element of trust, and…