Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Security risks of personal business in the workplace

By Brian Parks, Sanjiv Kalkar
email security
February 2, 2021

The typical company culture of today is less of a strict clock-in/clock-out mentality than in years past. Company expectations on methods of work have morphed over the years, and employees checking personal email or performing some personal business on “company time” is often ignored or overlooked as long as it doesn’t interfere with the employees’ job performance.

The risks in today’s connected world are also significantly different than they were even 10 years ago. While employees may have checked personal emails or performed other personal business on occasion then as they do now, the risks of those activities when utilizing corporate resources today have increased dramatically. Web-based email services, such as Gmail and Yahoo, create additional holes in the security perimeter that many companies take such pains to protect. Malicious actors are well aware of these “attack vectors” and look for any opportunity to exploit them.

File-sharing services, such as Google Drive, DropBox and personal OneDrive folders, also pose significant risk to the corporate network. The additional layering effect of file-sharing service — such as multiple shares of a potentially malicious file through a chain of services — create an additional layer of complexity and risk.

It’s Not Just an Email

Corporate email systems have robust security technologies to monitor email, such as highly customized spam filters, attachment sandbox checking and URL sandboxing to name a few. Accessing web-based email bypasses most of these corporate security protections.

Users may download malicious attachments or click on phishing links from personal web-based emails that allow malware to enter the corporate network. These transfers occur from the personal email service directly to the corporate computer on a secured channel using HTTPS, so corporate firewalls and email filters are not able to scan and filter the attachments as they are being downloaded onto a computer tied directly to the network.

Downloaded files from an email or file-sharing service or links clicked from emails could contain malicious code that exposes the corporate network to a ransomware attack or other malware that could cripple the corporate network and bring business to a halt, significantly impacting patient care in a healthcare organization.

Personal email could also be used (either intentionally or unintentionally) in the execution of official company business. This could bypass any Data Loss Prevention (DLP) logic that may be in place and lead to possible exposure or leaks of sensitive company information, intellectual property and even Protected Health Information (PHI) or Personally Identifiable Information (PII) – exposure a corporate email filtering platform would be more apt to identify and stop. There are also potential legal ramifications of corporate business being conducted over personal email services, even if unintentionally.

Best Practices

Access to personal web-based email and file-sharing services on corporate devices should be prohibited by company policy and blocked by corporate firewalls. If required, access should be allowed only on an exception basis. One example: Utilization of web-based email services required for a third-party contractor to exchange information with their parent corporation.

A risk-based approach should be used to determine the business need to allow access. There must be clear and concise policies and procedures for granting access to web-based email and file-sharing services. Procedural controls like signed Acceptable Use Policies, along with robust awareness training on the risks associated with using these services, will foster a culture of mutual acceptance for these restrictions.

Technical controls can be leveraged to restrict access to web-based email and file-sharing services. For example, next generation firewalls and Active Directory (AD) groups can enforce role-based, exception-only access to these services when required. Anyone not in this group will be blocked from accessing such services. Some firewalls will also allow granular controls to prevent uploading files to file-sharing sites via application level controls.

These measures may see draconian, but there are fairly simple solutions to satisfy employee needs. The prevalence and extensive use of personal devices in today’s culture, connected either via cellular networks with liberal data plans or even via the corporate guest network, provides a clear and simple path for employees to conduct needed personal business using their own devices without significantly exposing the corporate network to the inadvertent download of malware/ransomware from non-company-controlled environments.

KEYWORDS: cyber security email security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Brian Parks is Senior Vice-President of Information Security Services at Intraprise Health, LLC.

Sanjiv Kalkar is a Senior Security Consultant at Intraprise Health. He specializes in Penetration Testing, Vulnerability Assessments and Security Risk Assessments.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • remote work

    Addressing security risks of personal business in the workplace

    See More
  • world-risk-freepik1170x658.jpg

    Top global security business risks in the next year

    See More
  • SEC0221-Cyber-Feat-slide1_900px

    In the shadow of SolarWinds: Personal reflections

    See More

Related Products

See More Products
  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products

Events

View AllSubmit An Event
  • February 20, 2025

    Ideological Tensions in the Workplace: Understanding and Mitigating Risks of Violence

    ON DEMAND: Organizations face evolving threats, including workplace violence stemming from ideological tensions, political polarization, economic disparities, and other factors.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing