Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Business
    3. >Security risk from remote workers is a problem for HR as well as IT
    Business

    Security Risk From Remote Workers Is a Problem for HR as Well as IT

    Published by Gbaf News

    Posted on May 28, 2020

    6 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    An illustration depicting the cybersecurity risks posed by remote workers in the banking and finance sector. The image highlights the importance of HR and IT collaboration to address data breach threats.
    Remote workers facing cybersecurity challenges related to data breaches - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    By Jon Fielding, managing director EMEA, Apricorn

    Human error and apathy still present a major threat to the security of data when employees are working remotely. This is despite valiant efforts from organisations to educate their workforces in cybersecurity risks, and the practices they must follow.

    In a recent survey carried out by Apricorn, more than half (57%) of UK IT leaders said they expect remote workers to expose their organisation to the risk of a data breach, up from 44 percent in 2018. More than a third believe their remote workers simply don’t care about security.

    For those organisations that had experienced a data breach in the last year, employees unintentionally putting data at risk was the leading cause (33%), followed by lost or misplaced devices – cited by 24% of respondents, a rise from 17 percent a year ago.

    These findings highlight a continued and growing ‘insider threat’ that organisations must address. Given the increased numbers of people working remotely due to the COVID-19 outbreak, any weaknesses in the security strategy will be amplified. Increasing volumes of sensitive and confidential data are being accessed from outside the traditional corporate network perimeter, from a combination of work devices and personal devices. And regulations such as GDPR certainly haven’t gone anywhere.

    Malicious actors are seeking to take advantage of any chinks in an organisation’s armour – and the human being is often the target. According to research from KnowBe4, for example, phishing email attacks relating to the pandemic rose 600 percent in the first quarter of the year, as hackers sought to profit from disrupted businesses and distracted individuals.

    A lack of buy-in

    The growing human risk uncovered by Apricorn’s survey suggests that organisations are still struggling to get employees to buy into the security strategy, and that’s a problem which cannot be addressed by IT alone. Different functions of the business – in particular HR, but also communications and the executive team – need to collaborate to ensure a consistent and effective approach to cybersecurity across a highly distributed workforce.

    Not only do organisations need to protect their data, but they need to do so while enabling staff to be productive and efficient.

    The approach taken must combine the right technology and tools with policy, education and culture change. 

    Find and address the vulnerabilities

    IT first needs to identify exactly where the organisation’s cybersecurity vulnerabilities lie, encompassing both technology and human factors.

    This must include an audit of all software to determine whether the latest updates and patches are in place, and a check of all security controls currently applied to on-premise network infrastructure, databases and systems, as well as any parts of the IT estate that run in the cloud. Any gaps where infrastructure, hardware or software are exposed to a breach must be immediately addressed.

    In addition to technology, weaknesses in security policies, procedures and processes must also be addressed, particularly those that cover remote working and employees’ use of their own devices for business purposes. IT, HR and the internal comms team should work together to update policies and create new ones where appropriate, setting out clearly how employees are expected to behave, the best practice protocols they must apply, and the devices they’re allowed to use and how.

    Strict policies around the use of removable media such as USBs and hard drives are also essential.

    All policies then need to be communicated effectively to the entire workforce, in a way that ensures they understand what they must do differently and how to comply. An effective education programme is essential, which again demands collaboration with HR and comms teams.

    Build a culture of accountability

    Nearly two thirds (63%) of respondents to Apricorn’s survey said their remote workers are willing to comply with security measures, but don’t have the necessary skills to do so. Comprehensive training programmes must be designed and rolled out to all employees, including temps, contractors, part-timers and senior executives. These should be both informative and engaging in order to secure buy-in.

    In addition to being trained in good cybersecurity practice, to build a security-focused culture employees should be educated in the specific risks and legislation that apply to the organisation, why certain requirements are in place, and the consequences of failing to follow procedure.

    More than ever before, protecting data from loss or theft is everyone’s responsibility, and senior teams must lead by example, modelling best practice behaviour. They should be involved in communicating key messages directly to employees, perhaps via video.

    The risk of human error will always remain, and enforcing policies is a challenge when the workforce is so dispersed. To mitigate this risk, IT should implement a safety net of technical controls that will protect data if employees make mistakes or decide to cut corners.

    Strengthen endpoint controls

    Securing the endpoint will protect data and systems wherever the employee is working, and whatever device they use, allowing the organisation to have complete confidence in the integrity of its information.

    This can be done through, for instance, only allowing remote workers to use devices that have been provisioned or approved by corporate IT, and putting in place a policy that requires hardware encryption of all data as standard – whether it’s being stored or is on the move. Encryption creates the all-important ‘last line of defence’ which will keep information safe whatever else is happening around it.

    One way to guarantee that remote employees work in the best and safest way is to provide highly secure portable hard drives and USBs with in-built encryption capability. All data is automatically hardware encrypted as the user uploads it, so that if the device does end up in the wrong hands the information on it will be inaccessible.

    IT can also use such USB devices to roll out a secure remote working environment to the entire workforce, by loading them with the corporate ‘desktop’, featuring all standard applications, operating systems, configurations and security settings. Employees simply boot this up on whatever computer they’re using, and work within a trusted environment that has the same approved settings and controls they would get in the office.

    Tightening up access control will also mitigate the insider threat. Establish who has permission to access each data set and each corporate application. What devices are they using for this purpose? Do they really need to be able to access everything? Next, restrict employees’ access to systems and databases according to ‘least privilege’ principles, and implement a privileged access management (PAM) solution.

    A long-term solution

    This current situation is likely to trigger a more sustained shift to hybrid office/home working models for many organisations. Collaborating across departments to facilitate secure and productive remote working should therefore be seen as a long-term approach.

    Increased collaboration will help to equip employees with everything they need to access their work data and systems seamlessly and securely from wherever they’re working, while ensuring that their need for productivity and flexibility is not compromised.

    The outcome will be an engaged and committed workforce, made up of individuals who use the right tools in the right way, and take personal responsibility for protecting corporate data when they are out of the office.

    More from Business

    Explore more articles in the Business category

    Image for Nominate Now: Chairman of the Year 2026
    Nominate Now: Chairman of the Year 2026
    Image for Submit Your Entry Today for CEO of the Year 2026
    Submit Your Entry Today for CEO of the Year 2026
    Image for Submit Your Entry Today for Best Management Team 2026
    Submit Your Entry Today for Best Management Team 2026
    Image for Nominate Your Team: Best Innovation Management Team 2026
    Nominate Your Team: Best Innovation Management Team 2026
    Image for Submit Your Entry for Years of Excellence Awards 2026
    Submit Your Entry for Years of Excellence Awards 2026
    Image for Nominations Open for Travel & Hospitality Awards 2026
    Nominations Open for Travel & Hospitality Awards 2026
    Image for Submit Your Entry Today for Telecom Awards 2026
    Submit Your Entry Today for Telecom Awards 2026
    Image for Submit Your Entries for The Next 100 Global Awards 2026
    Submit Your Entries for the Next 100 Global Awards 2026
    Image for Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Image for Nominations Invited for Real Estate Development Awards 2026
    Nominations Invited for Real Estate Development Awards 2026
    Image for Submit Your Entry: Process & Product Awards 2026
    Submit Your Entry: Process & Product Awards 2026
    Image for Call for Entries: HR & Recruitment Awards 2026
    Call for Entries: HR & Recruitment Awards 2026
    View All Business Posts
    Previous Business PostInsider Threats Should Remain a Real Concern for Businesses as Criminals Look for ‘easy Access’
    Next Business PostTips for an Eco-Friendly Facility