Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2026 GBAF Publications Ltd - All Rights Reserved. | Sitemap | Tags | Developed By eCorpIT

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Business > REMOTE WORKING STRATEGY REQUIRED TO STRENGTHEN CYBER RESILIENCE
    Business

    REMOTE WORKING STRATEGY REQUIRED TO STRENGTHEN CYBER RESILIENCE

    Published by Gbaf News

    Posted on October 22, 2013

    11 min read

    Last updated: January 22, 2026

    An image depicting a remote working environment, illustrating the importance of operational resilience and cyber resilience testing in financial institutions, as discussed in the article.
    Remote working strategy for operational resilience in financial institutions - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Cyber security has recently been identified as one of the top risks facing banks, with the Bank of England’s systemic risk survey highlighting the extent of the challenge facing the industry. In response, banks have developed strategies to deal with such threats, backed by increased vigilance and innovative technology. But in a sector that is renowned for its global reach, the drive to offer convenience and ease of access to corporate and client data for staff on international assignments has changed the risk landscape forever.

    REMOTE WORKING STRATEGY REQUIRED TO STRENGTHEN CYBER RESILIENCE

    REMOTE WORKING STRATEGY REQUIRED TO STRENGTHEN CYBER RESILIENCE

    The ubiquitous nature of smartphones and tablets has transformed the workplace, creating greater scope for flexible and remote working. But as the barriers to the use of personal devices have come down, the threat to corporate systems and confidential information has risen exponentially. Cyber criminals are eager to tap this rich seam of data and access gateway.

    A sharp rise in the use of personally-owned devices in the workplace, dubbed ‘bring your own device’ or BYOD, has seen many organisations implementing policies for the use of non-corporate hardware. This trend is likely to continue, with some analysts forecasting a doubling of the current number of consumer devices in the workplace, reaching 350 million globally by the end of 2014. An additional challenge is also emerging in the guise of ’bring your own application’ (BYOA), where staff being confident with the latest app want that installed in all places that they work. Inevitably, this is likely to include personal, home and corporate devices.

    With international assignments and remote working comes the risk of blurring the well-defined boundaries of a physical office, which goes well beyond the use of smart devices or the occasional day working from home. There is growing evidence to suggest that a greater focus is required to keep sensitive information away from prying eyes, while safeguarding the safety and well-being of staff.

    Tackling this challenge is one that requires the involvement of HR, IT and security teams, to allow the development of a strategy that effectively addresses security, personal safety and corporate governance.

    For any work in high risk areas staff should be issued with a ‘clean’ designated laptop, pre-loaded with a basic profile that does not contain company or personal data. This should have whole disk encryption installed, which renders the device unusable, should it fall into the wrong hands. In countries where stable internet access is available, some companies opt for ‘thin client’ type devices, which allow remote data storage over a secure connection, rather than held locally on the device itself.

    Some simple additional steps, such as restricting the use of removable USB drives; strengthening passwords; and restricting user privileges can build further barriers to unauthorised access.

    On location, the team must consider arrival and departure issues, particularly if carrying specialist kit and documents. Data storage and the possible removal of sensitive data from the jurisdiction can also prove challenging in some parts of the world.

    Martin Baldock

    Martin Baldock

    Whether working out of a hotel room, a hotel meeting room, space in the firm’s local office or a client’s site, each scenario will present different security risks. Irrespective of the location, issues such as room cleaning and access control should be considered, alongside the safe storage and disposal of documents, flipcharts and diagrams.

    Electronic devices are of particular concern and teams must remember working remotely means corporate security can only do so much; local security rests squarely with the staff on-site.

    Laptops should be turned off when work is completed or not in use and these should not just be locked using the screen saver or left unattended in sleep mode, which may prevent encryption from being switched on. In particular, any training should highlight the importance of keeping an eye on laptops immediately after power down, as the encryption key is temporarily retained in the computer’s memory.

    Public Wi-Fi hotspots have mushroomed in recent years and, while convenient, pose a particular security challenge for remote workers. If unavoidable, a secure connection, often referred to as a VPN, should be established before any sensitive data is transmitted or internet sites visited. Apart from the technical risks, there are also physical considerations, such as ‘shoulder surfing’ and eavesdropping. Likewise, if printing, copying or scanning a document on a digital device, including copy and fax machines in hotel business centres, an electronic copy is probably stored in that device and, therefore, vulnerable to unauthorised retrieval. For the same reason, electronic devices should not be lent or borrowed from anyone outside the organisation.

    Security measures used for work-related equipment should also be used on personally-owned devices. It is important to remember that location services on smart devices and posting information to social media can inadvertently generate risks. Meetings where sensitive issues are being explored should be held in internal areas of the building and it is sometimes a good idea to change rooms with minimal discussion and notice. For high risk countries, some organisations may even opt to bring their own security specialist or employ a trusted source for technical security countermeasures (TSCM), such as bug-sweeping.

    Mobile telephones pose a security challenge in their own right and should be protected, with particular attention to the SIM card. The same rules should apply to tablets, where appropriate.

    Once back home, devices that have been used outside the office should be reviewed. Best practice would suggest quarantining such equipment before connecting to the corporate network, as any digital media used or collected during the visit and files transferred electronically could contain malware. A forensic examination of activity, such as existing processes/services, open connections, auto run features, remotely opened files, mounted and un-mounted volumes and virus content, will identify anything unexpected. This information, in addition to a formal debriefing of travellers returning from high-risk locations, will be valuable for future assignments and help develop a profile of personal and information security risks for a specific country, client or project.

    International assignments, with or without smart devices, poses a particular security challenge. Preparation, investment in configuration and reporting procedures, along with training, vigilance and common sense, will help strengthen banks’ resilience to such threats.

    Martin Baldock, CISSP-ISSMP, is a managing director of Stroz Friedberg, a digital risk management and investigations company.

    Cyber security has recently been identified as one of the top risks facing banks, with the Bank of England’s systemic risk survey highlighting the extent of the challenge facing the industry. In response, banks have developed strategies to deal with such threats, backed by increased vigilance and innovative technology. But in a sector that is renowned for its global reach, the drive to offer convenience and ease of access to corporate and client data for staff on international assignments has changed the risk landscape forever.

    REMOTE WORKING STRATEGY REQUIRED TO STRENGTHEN CYBER RESILIENCE

    REMOTE WORKING STRATEGY REQUIRED TO STRENGTHEN CYBER RESILIENCE

    The ubiquitous nature of smartphones and tablets has transformed the workplace, creating greater scope for flexible and remote working. But as the barriers to the use of personal devices have come down, the threat to corporate systems and confidential information has risen exponentially. Cyber criminals are eager to tap this rich seam of data and access gateway.

    A sharp rise in the use of personally-owned devices in the workplace, dubbed ‘bring your own device’ or BYOD, has seen many organisations implementing policies for the use of non-corporate hardware. This trend is likely to continue, with some analysts forecasting a doubling of the current number of consumer devices in the workplace, reaching 350 million globally by the end of 2014. An additional challenge is also emerging in the guise of ’bring your own application’ (BYOA), where staff being confident with the latest app want that installed in all places that they work. Inevitably, this is likely to include personal, home and corporate devices.

    With international assignments and remote working comes the risk of blurring the well-defined boundaries of a physical office, which goes well beyond the use of smart devices or the occasional day working from home. There is growing evidence to suggest that a greater focus is required to keep sensitive information away from prying eyes, while safeguarding the safety and well-being of staff.

    Tackling this challenge is one that requires the involvement of HR, IT and security teams, to allow the development of a strategy that effectively addresses security, personal safety and corporate governance.

    For any work in high risk areas staff should be issued with a ‘clean’ designated laptop, pre-loaded with a basic profile that does not contain company or personal data. This should have whole disk encryption installed, which renders the device unusable, should it fall into the wrong hands. In countries where stable internet access is available, some companies opt for ‘thin client’ type devices, which allow remote data storage over a secure connection, rather than held locally on the device itself.

    Some simple additional steps, such as restricting the use of removable USB drives; strengthening passwords; and restricting user privileges can build further barriers to unauthorised access.

    On location, the team must consider arrival and departure issues, particularly if carrying specialist kit and documents. Data storage and the possible removal of sensitive data from the jurisdiction can also prove challenging in some parts of the world.

    Martin Baldock

    Martin Baldock

    Whether working out of a hotel room, a hotel meeting room, space in the firm’s local office or a client’s site, each scenario will present different security risks. Irrespective of the location, issues such as room cleaning and access control should be considered, alongside the safe storage and disposal of documents, flipcharts and diagrams.

    Electronic devices are of particular concern and teams must remember working remotely means corporate security can only do so much; local security rests squarely with the staff on-site.

    Laptops should be turned off when work is completed or not in use and these should not just be locked using the screen saver or left unattended in sleep mode, which may prevent encryption from being switched on. In particular, any training should highlight the importance of keeping an eye on laptops immediately after power down, as the encryption key is temporarily retained in the computer’s memory.

    Public Wi-Fi hotspots have mushroomed in recent years and, while convenient, pose a particular security challenge for remote workers. If unavoidable, a secure connection, often referred to as a VPN, should be established before any sensitive data is transmitted or internet sites visited. Apart from the technical risks, there are also physical considerations, such as ‘shoulder surfing’ and eavesdropping. Likewise, if printing, copying or scanning a document on a digital device, including copy and fax machines in hotel business centres, an electronic copy is probably stored in that device and, therefore, vulnerable to unauthorised retrieval. For the same reason, electronic devices should not be lent or borrowed from anyone outside the organisation.

    Security measures used for work-related equipment should also be used on personally-owned devices. It is important to remember that location services on smart devices and posting information to social media can inadvertently generate risks. Meetings where sensitive issues are being explored should be held in internal areas of the building and it is sometimes a good idea to change rooms with minimal discussion and notice. For high risk countries, some organisations may even opt to bring their own security specialist or employ a trusted source for technical security countermeasures (TSCM), such as bug-sweeping.

    Mobile telephones pose a security challenge in their own right and should be protected, with particular attention to the SIM card. The same rules should apply to tablets, where appropriate.

    Once back home, devices that have been used outside the office should be reviewed. Best practice would suggest quarantining such equipment before connecting to the corporate network, as any digital media used or collected during the visit and files transferred electronically could contain malware. A forensic examination of activity, such as existing processes/services, open connections, auto run features, remotely opened files, mounted and un-mounted volumes and virus content, will identify anything unexpected. This information, in addition to a formal debriefing of travellers returning from high-risk locations, will be valuable for future assignments and help develop a profile of personal and information security risks for a specific country, client or project.

    International assignments, with or without smart devices, poses a particular security challenge. Preparation, investment in configuration and reporting procedures, along with training, vigilance and common sense, will help strengthen banks’ resilience to such threats.

    Martin Baldock, CISSP-ISSMP, is a managing director of Stroz Friedberg, a digital risk management and investigations company.

    More from Business

    Explore more articles in the Business category

    Image for Empire Lending helps SMEs secure capital faster, without bank delays
    Empire Lending helps SMEs secure capital faster, without bank delays
    Image for Why Leen Kawas is Prioritizing Strategic Leadership at Propel Bio Partners
    Why Leen Kawas is Prioritizing Strategic Leadership at Propel Bio Partners
    Image for How Commercial Lending Software Platforms Are Structured and Utilized
    How Commercial Lending Software Platforms Are Structured and Utilized
    Image for Oil Traders vs. Tech Startups: Surprising Lessons from Two High-Stakes Worlds | Said Addi
    Oil Traders vs. Tech Startups: Surprising Lessons from Two High-Stakes Worlds | Said Addi
    Image for Why More Mortgage Brokers Are Choosing to Join a Network
    Why More Mortgage Brokers Are Choosing to Join a Network
    Image for From Recession Survivor to Industry Pioneer: Ed Lewis's Data Revolution
    From Recession Survivor to Industry Pioneer: Ed Lewis's Data Revolution
    Image for From Optometry to Soul Vision: The Doctor Helping Entrepreneurs Lead With Purpose
    From Optometry to Soul Vision: The Doctor Helping Entrepreneurs Lead With Purpose
    Image for Global Rankings Revealed: Top PMO Certifications Worldwide
    Global Rankings Revealed: Top PMO Certifications Worldwide
    Image for World Premiere of Midnight in the War Room to be Hosted at Black Hat Vegas
    World Premiere of Midnight in the War Room to be Hosted at Black Hat Vegas
    Image for Role of Personal Accident Cover in 2-Wheeler Insurance for Owners and Riders
    Role of Personal Accident Cover in 2-Wheeler Insurance for Owners and Riders
    Image for The Young Rich Lister Who Also Teaches: How Aaron Sansoni Built a Brand Around Execution
    The Young Rich Lister Who Also Teaches: How Aaron Sansoni Built a Brand Around Execution
    Image for Q3 2025 Priority Leadership: Tom Priore and Tim O'Leary Balance Near-Term Challenges with Long-Term Strategic Wins
    Q3 2025 Priority Leadership: Tom Priore and Tim O'Leary Balance Near-Term Challenges with Long-Term Strategic Wins
    View All Business Posts
    Previous Business PostMONETIZING AN ONLINE FINANCIAL BLOG
    Next Business PostHOW BUSINESSES CAN HELP BRIDGE THE NORTH – SOUTH DIVIDE