How can IT managers ensure a secure home office during the coronavirus pandemic?

Due to the coronavirus pandemic (COVID-19), not only has our daily life changed significantly, but the world of work has also undergone a rapid development towards the home office. The transition happened very suddenly, so that even large companies from Silicon Valley are struggling with problems. However, internet criminals also reacted just as quickly to this change and are exploiting the previously unusual situation to gain access to valuable company data. Therefore, it is very important for employers to provide employees with a secure home office environment. We provide below a guide for IT managers with the most important points regarding a secure home office.


Is your company affected by the corona crisis? Consulting services are 100 percent subsidized by the federal government, up to an invoice amount of 4,000 euros. aramido is accredited with the BAFA and qualified as a subsidizable consultancy.

Securing endpoints

The first step towards a secure home office is also the most obvious: for a secure home office, the work device must be as secure as possible. Here, "security" means protecting the work devices from unauthorized access and manipulation by attacks as well as protection against failures.

To ensure the confidentiality of company data, the use of private devices should be avoided as much as possible. On the one hand, a company has no influence on their configuration (antivirus program, firewall, updates) and on the other hand, private devices could already be infected before being used in the home office, without the employee being aware of it. In addition, private devices, which may be used by several family members, do not offer high integrity or confidentiality. Therefore, it should be considered to provide securely set up company laptops. In this process, two-factor authentication should be used if possible, so that the theft of the user password does not immediately lead to the complete takeover of the device.

In addition to digital security, the physical security of the endpoint is also an important point. Since small children or pets are in the immediate vicinity in the home office, physical damage to the device is significantly more likely than in the office. Therefore, in the interest of ensuring availability, a practical backup strategy should also be considered, so that in the event of damage, data loss and work downtime are as low as possible. Approaches for this could be, for example, the use of a network drive or collaboration programs from one's own or a public cloud.

Securing the employee's WLAN

In our experience, many home networks are insufficiently protected. Such an insecure network does not provide a good prerequisite for secure telework and should therefore also be secured - after all, a chain is only as strong as its weakest link. Although an employer has no influence on the configuration of the employees' WLAN network, it could still be worthwhile to provide employees with instructions on how, for example, to choose a secure password and deactivate unnecessary services of their router. Help on this can be found in our article on seven recommendations for a secure WLAN .

Securing data traffic

In addition to securing the home WLAN network, the encryption of all data traffic is an effective means of preventing the interception of emails, passwords or important documents. To implement this, a company-internal VPN is often used, which encrypts all communication. Thus, employees can access the company's own network encrypted, without an attacker having the possibility to obtain important data by eavesdropping on the communication. A VPN also offers the advantage that communication is secured even for those applications which do not support secure data transmission on their own.

Provide clear assistance and offer unambiguous communication channels

Many attackers exploit the general uncertainty surrounding the coronavirus and the anxiety of employees to persuade them to give up passwords or to install a supposedly necessary program for telework. Therefore, it is important for IT managers to remove this uncertainty for employees, for example by clearly stating who employees should contact if they have questions or which communication channels are open to them. In addition, employees should be encouraged to ask questions if they have problems setting up their system. This avoids employees searching for possibly insecure solutions on their own (and thus bypassing the administration), installing programs independently or giving passwords to unauthorized third parties.

In addition, the IT administration must be as well prepared as possible for the increasing number of support requests, for example by postponing non-critical projects or increasing the number of employees. Detailed instructions also help employees to overcome many problems independently.

Sensitize employees

As mentioned in the previous point, is a promising possibility for criminals to smuggle in malware or steal passwords. To prevent this as much as possible, employees should be sensitized to the increased number of phishing emails and encouraged to check emails for credibility more critically than before.

Employees should also be pointed out the separation of private and professional life. Especially because professional and private life are very close to each other in the home office, one can quickly tend to open a private email on the company laptop or install a private messenger service on the company laptop. In this way, it can happen that one clicks on a link sent by friends or opens an email attachment with a supposed invoice on the work laptop, which then turns out to be malware. In this way, malware that would otherwise only spread in a private environment can now also spread in the company environment.

Adjust threat model

Another important point is that the threat model changes fundamentally when switching to the home office. We observe that the attack surfaces increase when originally internal services are made available on the public internet. Previously rather unlikely threat scenarios, in which an attacker first had to overcome perimeter protection measures, now become more likely. Security concepts must therefore focus more on ensuring the trustworthiness of devices and user identities, and companies must be prepared for incidents (Assume-Breach paradigm).

To counter these new scenarios, for example, a stronger segmentation of the internal network up to a micro-segmentation of individual services can be useful. In addition, stricter access controls should be introduced. This allows the user groups that have access to certain resources of the network to be more strongly restricted. This leads to the fact that in the event of an infection, it cannot spread throughout the entire network. An important guiding principle in this context is "authentication is not the same as authorization" - just because a device and user have access to the company network, they should not automatically be authorized to access sensitive data. Additional authorization checks should be used for this.

It is also important to consider that due to the programs used for telework, new ports and services could be exposed to the outside on the internet. Here too, the use of a VPN can help to keep the number of publicly accessible services as low as possible. Additionally, it is more important than ever to check the "visibility from the outside" through regular vulnerability scans .

Jonas Lehmann

On 03.04.2020 in the category Security Advisories published.