Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityTechnologies & SolutionsLogical SecuritySecurity & Business Resilience

Mitigating security risks with an evolving workforce

By Mike Wilson
group working together at table

Image via Pixabay

February 3, 2023

It’s no understatement to say the past few years have been challenging from a workforce management perspective. COVID-19 presented companies with an unprecedented situation, which gave rise to the Great Resignation and quiet quitting. And just as the pandemic is finally in the rearview, political and economic uncertainty have many worried about a potential recession and widespread layoffs. 

While there have been examples of the latter in the tech sector, overall the country’s jobless rate is near the lowest level in more than half a century. The coming months will determine whether the labor market will slow, but in the meantime, companies must find a way to deal with the productivity gaps introduced by these recent challenges.

Increasingly, organizations are looking to consultants and other external groups for help but it’s imperative that they are cognizant of the security vulnerabilities that often accompany this approach. The following are common threat vectors hackers are only too eager to exploit: 

Use of public or unsecure Wi-Fi 

Freelancers and consultants tend to be fairly mobile, often working on the road, at a coffee shop or from an industry conference. It’s also relatively common for these individuals to rent office space or work from a shared collaborative workspace. Most, if not all, of these locations offer public or unsecured Wi-Fi which can provide threat actors with an easy access point into an enterprise network should a consultant be utilizing the connection for business activities. Whenever possible, consultants should avoid using a public Wi-Fi network but if they must do so it’s essential that they utilize a VPN to access any sensitive corporate resources. 

Mandating the use of a VPN is also a good security practice even if consultants are operating solely out of their home. Connected devices like smart TVs or baby monitors can introduce numerous vulnerabilities, and there is also the chance that other residents could unintentionally download malware on the home network. 

“Keys to the kingdom” access 

Companies must be cognizant of access permissions and ensure that external groups can only use systems and applications they need — and nothing more. Shadow IT can complicate this issue for many organizations, as various departments may be granting consultants access to systems without IT’s knowledge. That’s why companies should first take steps to mitigate shadow IT and educate department heads on the importance of having IT manage access permissions for external groups. It's also essential that organizations immediately cut off access after parting ways with a freelancer or consultant and periodically audit to confirm that no former contractors still have access permissions. Single sign-on (SS0) systems can help enterprises address these issues, as they make it much easier to globally disable access and control/audit what access employees and consultants have. 

Poor password hygiene 

Poor password practices such as selecting weak, easily guessable passwords and reusing them across multiple accounts is another vulnerability organizations must combat. Studies have documented that at least 71% of people engage in this security misstep, which is one of the reasons why credentials have enjoyed enduring popularity as a threat vector. Case in point, the most recent Verizon Data Breach Investigations Report found that over 80% of hacking incidents involved the use of stolen credentials. If just one of the sites associated with a reused password has been breached, then all other accounts secured by that password are at risk. Even more common is when users use variants of the same root password, with small changes, across multiple websites. These are just as problematic since an attacker can easily discern a pattern and fuzz through variants to find a match.

Addressing password hygiene is challenging enough in a traditional workplace setting, but it becomes even more difficult when companies are employing various consultants and other third parties. These individuals are more likely to use the same credentials across all client accounts and networks, making it imperative that enterprises implement a credential screening solution. By vetting passwords at every login against a database of exposed credentials, organizations can eliminate the threat of poor password practices, both among their employees and also among all external groups who have access to enterprise systems. 

With today’s workforce management challenges showing no sign of abating, companies are understandably eager to onboard contractors. But in their rush to get new talent up to speed it’s essential that organizations don't overlook the unique security concerns that accompany this practice. Taking the time to ensure secure authentication will pay dividends, providing external groups with the appropriate access to corporate systems without leaving the company exposed to opportunistic hackers. 

This article originally ran in Today’s Cybersecurity Leader, a monthly cybersecurity-focused eNewsletter for security end users, brought to you by Security magazine. Subscribe here.

KEYWORDS: access management data breach response hybrid workforce password protection WiFi security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Mike WIlson is the founder and CTO at Enzoic.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Digital, tablet and hands

The 2025 Annual Guarding Report: Unrest Inspires Upgrades in Training, Technology

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity predictions of 2026

5 Cybersecurity Predictions for 2026

Water faucet and cup

High Water Mark: CISA Shares Foundations for Effective Cybersecurity and Risk Management

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

January 14, 2026

Is Your Organization Prepared to Navigate Interconnected Threats in 2026?

The 2026 threat environment will be louder, faster, and more interconnected. The most pressing risks, from global political volatility to emerging tech disruptions, will challenge organizations to act amid ambiguity and protect credibility in an era of accelerating uncertainty.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • mobile device usage

    Managing risks in an evolving cybersecurity environment

    See More
  • 5 mins with Prout

    5 minutes with Jeremy Prout - How to protect the workforce against security risks in 2021

    See More
  • Mitigating Background Fraud Risks with Biometrics

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • A Leaders Guide Book Cover_Nicholson_29Sept2023.jpg

    A Leader’s Guide to Evaluating an Executive Protection Program

See More Products

Events

View AllSubmit An Event
  • February 20, 2025

    Ideological Tensions in the Workplace: Understanding and Mitigating Risks of Violence

    ON DEMAND: Organizations face evolving threats, including workplace violence stemming from ideological tensions, political polarization, economic disparities, and other factors.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing