Remote Management Survey

**Remote Management Survey** According to the survey, one in every five IT employee says remote workers are not secure. Important conclusions from the 2022 Remote Management Survey by Hornetsecurity: - 18% of IT experts believe that remote workers are not working securely and that company data is at risk. - Eight out of ten IT experts believe that remote work definitely reveals cyber security risks that would not otherwise exist. - Three out of four IT experts say employees are using personal devices to access sensitive company data. - One in every three companies does not provide cyber security awareness training for remote workers. - One in every six companies has been directly affected by a cyber security incident related to remote work.

9 Feb 2024 SintelSedat Akfidan 16 min read
Remote Management Survey

Remote Management Survey

According to the survey, 1 in every 5 IT workers says that remote workers are not secure.

Key findings from the 2022 Remote Management Survey by Hornetsecurity

  • 18% of IT experts believe that remote workers are not working securely and that company data is at risk.
  • 8 out of 10 IT experts believe that remote work definitely exposes new cyber security risks that would not otherwise exist.
  • 3 out of every 4 IT experts say that employees use personal devices to access sensitive company data.
  • 1 out of every 3 organizations does not provide any cyber security awareness training to remote workers.
  • 1 out of every 6 organizations has experienced a cyber security incident directly related to remote work.

About the 2022 Remote Management Survey

As part of our efforts to stay in touch with the current state of the IT industry and monitor the frequent and intense changes that come with it, our team at Hornetsecurity conducts surveys every few months. Each survey is focused on a specific topic that we believe is essential for the industry and commercial organizations around the world.

No change has affected the way companies operate more than the shift to remote work and the subsequent need for remote management. Although the concept of remote work is not new, the 2020 pandemic accelerated its adoption worldwide across sectors. This forced many organizations to shift overnight to remote work setups, revealing a series of cyber security concerns that had previously not been seen as threats.

Our 900+ survey participants come from a variety of sectors, regions, years of experience, and company sizes.

Remote Work in 2022

Initially introduced as a pandemic precaution, remote work has become a fundamental part of the modern workplace, along with remote monitoring and remote team management. As more companies adopt fully remote or hybrid approaches to work, the transition to remote work has been well documented over the past few years, with all evidence pointing towards it being a permanent fixture for the future.

Therefore, remote work has become one of the most fundamental elements of the workplace for both employers and employees. A recent survey by Buffer showed that 97% of remote workers would like to continue working remotely for the rest of their careers, yet 72% of employers in the United States prefer employees to work in an office environment, and only 12% of leaders believe that employees are just as productive when working remotely as they are in the office, despite the contrary evidence.

Other employers cite security concerns as their primary motivation for bringing back office workers, with a 37% increase in data breaches during the third quarter of 2022, according to statista.com. However, this represents a significant decrease from the 125 million data breaches reported shortly after the start of widespread remote work, proving that companies that invest in good cyber security practices and remote team management tools can have an immediate impact on reducing risk within their organization.

No matter what the employer's perspective is, the overwhelming response from employees towards remote work has been positive. Over 57% of employees would leave their jobs if remote or hybrid work was not an option, and 84% of them would take a pay cut to work for a company that allows them to work from home. The biggest benefit of remote work for employees is the flexibility it offers, with 67% of them claiming that it leads to a better work-life balance.

Despite the challenges remote work presents for employees, such as having to fight for the balance of work-life, it is clear that remote and hybrid work are here to stay, and therefore organizations need to be prepared to face the challenges that remote management brings in terms of security.

The initial spike in cyber security breaches at the beginning of remote work, followed by a decrease as companies shifted their investments to better security education and cyber security measures, proves that remote work can be just as secure as working from the office, provided that both employees and employers follow stricter measures.

Nearly one in five IT professionals (17.9%) say workers are not secure when working remotely

Close to 1 in 5 I.T. Professionals say Workers are not secure when working Remotely

According to our remote management survey, a significant number of IT professionals are aware of the security gaps in remote work and have a good understanding of both the security issues arising from the increase in remote work and the lack of proper solutions to these threats, despite the significant global increase in remote work.

The reason for this is likely due to the rapid and sudden expansion of remote work over the past few years, forcing businesses to adapt to all the infrastructure and operational changes that came with it. Unfortunately, IT security has been given a lower priority compared to the fundamental tasks needed to ensure business continuity - at least until a cyber security breach occurs.

Three out of every four IT professionals (73.8%) say employees can access sensitive data through personal devices

3 in 4 Remote Workers can access Sensitive Data

One of the most surprising pieces of information collected from this survey is the extremely high usage of personal devices for accessing sensitive data among employees. It's likely that many of these cases involve users who access emails and documents via personal smartphones while using systems like Microsoft 365, Google Workspace, or other cloud-based office applications - this situation significantly complicates remote management.

Although not necessarily directly related to the increase in remote work, it highlights that a significant amount of sensitive data is at risk due to various technical methods targeting end users' personal devices. Endpoint configuration / management, along with the legal and ethical issues that come with providing these services on non-company devices, is quite rare. Furthermore, it emphasizes the importance of cloud-based security features rather than device-specific features.

14 percent of repondents said their organization suffered a cybersecurity incident related to remote working

As we have discovered in previous surveys over the past few years, there has been an increase in cyber security incidents. Although the situation is slightly less dire than immediately after the pandemic, the incident rate remains high. Therefore, this finding should not be surprising, although it is still somewhat concerning. This means that one in every six organizations has experienced a cyber security incident specifically related to remote work.

While the exact cost of each incident is unknown, IBM's industry data shows that the average cost of a major data breach in 2022 was $4.35 million, an increase of 2.6% from the 2021 average of $4.24 million. This includes potential ransom payments, the cost of significant downtime caused by a data breach, and possible industry fines for failing to protect sensitive data.

Sources of Remote Work related Cybersecurity Incidents

28.1% of respondents to our remote management survey indicated that the main cause of security incidents was 'compromised endpoints' and 'compromised credentials'.

When it comes to compromised endpoints, the explanation is quite clear - as users travel and work from different locations, the risk of losing devices containing sensitive data is higher. Given that a relatively high number of personal devices have access to sensitive data without any endpoint configuration, this risk increases further.

Credential theft through social engineering threats and email phishing attacks is just as common. Remote work increases this risk because users are more isolated and have a lower chance of identifying threats on their own. In contrast, office workers can quickly reach out to other colleagues for verification before sharing sensitive information. This particular issue has a two-pronged solution. First, a robust email security package can eliminate a significant portion of threats before they reach end users. For threats that do reach their intended targets, programs such as cyber security awareness training provided by Hornetsecurity can significantly impact the potential for a data breach.

15.7% of respondents also cited uncontrolled file sharing as the source of cyber security incidents. Cloud storage platforms have become essential for remote work operations, but sharing access to files on these platforms with third parties brings significant risks. User error that allows unauthorized individuals access to sensitive company data is a serious risk and relatively common. Strict access and authorization processes must be implemented to prevent such occurrences.

Slightly more than one in ten respondents (11.6%) who reported a cyber security incident related to remote work indicated that the primary cause was unsecured or public networks. While endpoint security is mostly under the control of IT departments, the networks users connect to add another layer of risk that is often overlooked. Although relatively rare, users can become victims of attacks like public Wi-Fi spoofing. For example, a cybercriminal could mimic a local café's Wi-Fi access point with the same name, trick users into connecting to it, and compromise their endpoints.

According to this survey, the least frequently reported source of cyber security incidents was lack of physical security or privacy in public places. This is an extremely low-tech form of cyber attack, yet it was still reported by approximately one in ten victims. This serves as a reminder that some security aspects cannot be addressed through any digital remote management tool and rely solely on users' awareness of their surroundings.

Remote Work Cybersecurity Incident Frequency by Company Size

The data collected through this survey clearly shows that the larger the company, the higher the likelihood of experiencing a remote cyber security incident. In fact, companies with over 500 employees have three times the likelihood of experiencing an incident compared to small businesses with fewer than 50 employees.

This shows that while cyber security can be practically scaled infinitely, the size of a company always increases risk. Additionally, it shows that black-hat hackers are significantly more interested in attacking larger companies - probably due to the much higher potential return of their efforts and the excitement of successfully attacking a well-known company.

Nearly half of employees in respondents' organizations work remotely

Almost half of Employees in the Respondents

When asked what percentage of their workforce works remotely, the average response from our respondents was almost half - 47.6%. Although not surprising, this is a very high percentage, especially considering that this rate is expected to increase in the coming years.

This also shows that larger companies need to adopt a slightly different approach towards cyber security to accommodate the nuances of remote work and invest more in ensuring that remote employees are aware of the increased risks. Cyber security has always required users to play a role in preventing incidents - now that security managers have less general control over the environment where users work, the increase in remote work and remote team management has expanded this role.

Four out of every five IT professionals (79.5%) believe that remote work introduces cyber security risks

4 in 5 I.T. Professionals think that Remote Work introduces Cybersecurity risks

Our cyber security experts at Hornetsecurity are firm in their belief that remote cyber security introduces additional risks compared to on-premises security. Approximately 80% of respondents agree with this, but the survey also reveals that around 12% of IT professionals disagree and an additional 8.5% are unsure.

Considering that some sources of cyber security incidents identified in this survey are practically unique to remote workers, this is somewhat surprising. This could indicate that IT professionals are not fully aware of or understand these potential risks. However, the majority of respondents are aware of these risks.

One in three organizations does not provide any cyber security awareness training to remote workers

1 in 3 Organizations do not provide any Cybersecurity Awareness Training to Remote Workers

Although IT professionals are generally aware of the additional risks associated with remote work, this survey reveals that organizations have not yet invested enough in user awareness. One out of every three organizations does not provide any cyber security training to remote workers, and considering that the main sources of reported cyber security incidents in this survey are user-related, this is a significant oversight.

Data from many of our previous surveys, especially those related to cyber security incidents such as ransomware attacks, consistently show that while the security tools and remote management services used by an organization are necessary, the weakest link in the security chain is often the users themselves.

Our latest ransomware survey showed that one in every four organizations has been a victim of a ransomware attack, and three out of every four of these attacks were due to user errors (phishing/email attacks or compromised endpoints). The importance of user training cannot be overstated.

How confident are IT professionals in their remote management security measures?

94 Percent of I.T. Professionals said they are Moderately Confident in their Remote Management Security Measures

Despite the clear risks associated with remote work and remote team management, IT professionals reported a high level of general confidence in their remote security measures. On a scale of 1 to 5, the average level of confidence among respondents was ranked at 3.6. Considering that 20% of respondents believe that remote work does not introduce additional security risks, this confidence is likely misplaced.

Confidence of Remote Management Security Measures

What are the most commonly used security features for remote management?

Most commonly used Security Features for Remote Management

When asked about the most commonly used security features for remote management, VPN was ranked at the top. However, it is important to note that while a VPN provides more security, its primary function is often to allow remote workers to access internal systems and storage through the company network, which explains its high usage rate.

The most common security feature specific to security was Multi-Factor Authentication (MFA) - it is not surprising that platforms like Microsoft 365 and Google Workspace provide this feature natively. While over four out of every five respondents indicated that they use this feature, it should be noted that a motivated black-hat hacker could potentially find a way to bypass this relatively easily. In fact, two of the most significant sources of cyber security incidents reported in this survey - compromised endpoints and compromised credentials - should theoretically be prevented by MFA, but clearly are not. However, it would be unwise not to have MFA in place, as it provides protection against low-level attacks.

Endpoint detection software was the third most popular security feature, used by 55.5% of respondents. This software is practically essential for users who have direct access to network systems or storage and is an indispensable tool for large organizations that need to monitor a near-infinite number of devices.

Endpoint activity monitors are a bit more complex. While these monitoring tools provide useful data for IT security teams, they can also be seen as intrusive to remote workers. Employers often use them as a pretext for monitoring employee activities to ensure they are working properly. According to the results of this survey, this is the most common practice in North America, with around half (47%) of respondents using remote monitoring and remote team management, compared to 39.7% of European respondents. This data point confirms the more stringent institutional culture and current sensitivity towards employee flexibility in the United States.

41% of respondents indicated that their IT teams use conditional access and password management software to reduce risks for remote workers. The former prevents users from accessing certain systems or data based on specific criteria related to device status or identity. This system is particularly useful for IT teams that want to reduce the risk of users accessing data from unusual locations or unapproved devices.

However, more complex conditional access configurations can often lead to frustration among less technically knowledgeable employees who may not understand why they are being prevented from accessing data under certain conditions. It also increases the time IT teams must spend configuring devices and managing users. Password management software is another user-centric solution, and considering that this survey found compromised passwords to be a major source of cyber security incidents, it should be used more frequently.

The least reported cyber security measures were endpoint data transfer restrictions and application whitelisting, with respondents reporting usage rates of 27% and 22.3%, respectively. While both measures add more restrictions on endpoints and thus on users, they may be unwelcome for users who require more flexibility, especially in smaller organizations. However, these measures should be used more frequently in larger organizations with well-defined user roles and responsibilities.

How do organizations handle device management for remote employees?

23 percent of Respondents said their Organization does NOT Procure, Configure and send Endpoints to Remote Employees

As discussed in the previous section, for nearly all cyber security and remote management features mentioned, endpoints must be configured by the IT department before they are distributed to users. However, this survey shows that approximately one out of four organizations does not fully handle endpoint configuration before providing devices to remote employees.

15.3% of respondents said that their employees use personal devices for remote work with some endpoint configuration. 6.4% of respondents said that their employees use personal devices for remote work with no configuration at all. While not having endpoints procured, configured, and sent to users may be more cost-effective in the short term, a significant cyber security incident is much more likely when no security measures are used to protect sensitive data.

Most popular Endpoint Management Tool used for Remote Employees

Endpoint management tools significantly improve the efficiency of IT teams when managing the security and monitoring of multiple endpoints. Group Policy has long been a go-to tool, and this survey shows that it is