Empowered workforce

Cybersecurity is no longer just an IT issue. It’s also an operational issue; a reputational issue; and, increasingly, a workforce issue.

In small businesses and midmarket organizations, where IT teams are lean and hybrid work is the norm, the risks are growing more complex. Employees work from home, airports, and coffee shops. User-focused cyberattacks, including phishing, are becoming more sophisticated. Mobile workers and advanced threats are a high-risk combination.

“Criminals will use whatever tactic they can to get to their targets,” says Kris Virtue, vice president of Cybersecurity at Qualcomm Incorporated. “That’s why securing user accounts and credentials, as part of a defense-in-depth strategy, is a priority.”

To that end, modern cybersecurity must be strong enough to protect the business but seamless enough not to slow it down by impeding employees from doing their work. Here’s a practical checklist of baseline security practices that modern workforces — regardless of company size — can adopt.

1. Multifactor authentication (MFA) everywhere

Passwords alone are no longer sufficient to protect user identities and sensitive data. Organizations should enforce MFA across their entire ecosystem of email, cloud apps, collaboration tools, and management consoles.

For non-IT staff, MFA is about changing habits. For leadership, it’s about enforcing policies that help protect the business. MFA can reduce the risk of credential-based breaches dramatically, with minimal impact on productivity.

“MFA is table stakes, not just for security teams but for individuals,” says Virtue. “Every person should be turning on MFA for all their accounts.”

The key is consistency. If it’s optional, it won’t be as effective.

2. Secure, automated cloud backups

Ransomware and accidental deletion of files and data remain two of the most common threats facing small businesses[ekl1]  and midmarket firms. Automated, encrypted cloud backups support business continuity if a device fails, is compromised, or is lost.

An effective backup strategy should cover all endpoints, not just centralized servers.

3. Simple, predictable patching routines

Outdated software is an open door to cybercriminals. Modern organizations should implement automated operating system and application updates, including security patches that require minimal manual intervention. The goal is to remove the burden from employees while maintaining compliance.

Security that depends on people’s remembering to click “update later” is not true security. “Especially for smaller businesses with smaller security teams, automated patching is critical,” says Virtue.

4. Hardware-rooted protection

Enterprise-grade security starts at the silicon, helping reduce attack surfaces before threats can gain traction. This approach matters, because many attacks today target firmware and low-level vulnerabilities.

“Attackers keep moving lower in the system, down to the hardware level,” says Virtue. “That’s why it’s important to start your security at the most fundamental level — the silicon — which becomes your root of trust for layering on additional security.”

Hardware-based defenses help mitigate risk without adding friction for end users.

5. Out-of-band management

Mobile teams and hybrid workers require the same seamless protection and support as in-office workers. Out-of-band management enables remote management and updating of devices, supporting tasks such as zero-touch provisioning, over-the-air configuration updates, and remote troubleshooting and support.

If a device is lost or compromised, administrators can track, lock, and wipe devices remotely, even when the device is off or doesn’t boot to Windows.

“Out-of-band management is a good example of how we can remove security as something that the employee has to constantly take action on and make it something that can be managed in an automated or centralized fashion,” says Virtue. “It’s less of a burden on the end user, who should be focused on the business processes, not trying to learn how to be a cybersecurity expert.”

Security without slowdowns

As organizations seek to strengthen cybersecurity controls without impeding how people work, they are finding that the answer is not necessarily more controls but, rather, security that’s built into each device, combined with clear, enforceable policies and supported by end user awareness training.

When devices are secure by design and manageable from anywhere, organizations can better protect endpoints quickly and efficiently, even in worst-case scenarios.

In modern work, security basics are not optional. With the right practices—and the right hardware foundation—security becomes an enabler of productivity, not an obstacle to it.

Bring premium and secure PC experiences to everyone in your organization with Snapdragon. Learn more.

Snapdragon branded products are products of Qualcomm Technologies, Inc., and/or its subsidiaries.

Share
Share