Four Days Left to Get an iPad (32G), Galaxy Tab A, or $250 Off Online Training!

Press

Subscribe to SANS Newsletters

Join the SANS Community to receive the latest curated cyber security news, vulnerabilities and mitigations, training opportunities, and our webcast schedule.






Cloud Looms Large Over Workforce Transformation—Initiatives Bring Security Risks, Rewards in New SANS Institute Survey

New Study Examines Globalization, Work Styles and Technology, and Handling Risks and Challenges with Movement to Cloud Services as a Leading Issue

  • Bethesda, MD
  • Dec. 10, 2019

The rapid evolution of the workforce, from remote and contract workers to BYOD to non-human workers, will have significant impacts on security, according to new research from SANS Institute.

The survey, sponsored by RSA, identified those security practitioners working in workforce transformation and queried them about the issues, challenges, risks and mitigation strategies for dealing with the rapidly evolving workforce. Fifty-four percent of respondents identified increased reliance on cloud-based applications and data as the leading challenge; the next two major challenges identified were workforce knowledge gaps due to the rapid changes in technology (46%) and 24/7 access to data and resources (26%).

Respondents told SANS that they’re supporting a number of initiatives to support workforce transformation, including a transition to cloud-hosted infrastructure (51%), increased use of collaboration tools (46%), a shift to software-as-a-service (32%) and adoption of the remote office and related capabilities (29%).

“The data collected reinforces the continued growth of and increasing focus on cloud usage for infrastructure, data, and applications,” noted SANS analyst and author David Hazar. “However, consistent with our other research, we see that the rapid shift to the cloud and other third-party services, along with the increased mobility and transitory nature of the workforce, is increasing risk for many organizations. We encourage organizations to build and maintain strong prevention, detection, and response capabilities tailored to each operating environment to protect themselves. We also encourage organizations to leverage the shared responsibility models inherent in cloud and third-party services appropriately to reduce the overall IT, security and privacy burden and allow internal staff to focus on the highest risk workloads.”

SANS also asked respondents about what capabilities are most useful for mitigating the security risks of workforce transformation. The most effective controls, as rated by those surveyed, included vulnerability, patch and configuration management; centralized identity and access management; and endpoint detection and response.

To learn more about workforce transformation risks and opportunities, register for the webcast December 18, 1:00 p.m. Eastern, at https://www.sans.org/webcasts/workforce-transformation-risk-survey-111960 and be among the first to get the associated report of the data and SANS recommendations.

About SANS Institute

The SANS Institute was established in 1989 as a cooperative research and education organization. SANS is the most trusted and, by far, the largest provider of cyber security training and certification to professionals at governments and commercial institutions world-wide. Renowned SANS instructors teach over 60 different courses at more than 200 live cyber security training events as well as online. GIAC, an affiliate of the SANS Institute, validates a practitioner's qualifications via over 35 hands-on, technical certifications in cyber security. The SANS Technology Institute, a regionally accredited independent subsidiary, offers master's degrees in cyber security. SANS offers a myriad of free resources to the InfoSec community including consensus projects, research reports, and newsletters; it also operates the Internet's early warning system—the Internet Storm Center. At the heart of SANS are the many security practitioners, representing varied global organizations from corporations to universities, working together to help the entire information security community. (https://www.sans.org)