CYB210_Week3Discussion Cybersecurity Issues for Business Travelers_post20

Is there anything else you׳d like to ask?
Our top-rated tutors can help you.

Click here to post a question
Related Documents
1 / 3100%
Padgett-Beale, Inc. is committed to protecting and securing
company and employee data. c This is an ongoing process that
requires continuous adjustments and changes. c Employees,
managers, and executives of Padgett-Beale are all vulnerable to
potential exploits and breaches of critical information and data,
especially, when traveling on company business. c Updates to the
company’s security policies, processes, and plans, along with
improved cybersecurity awareness training, are integral to the
protection of Padgett-Beale assets.
c c c Padgett-Beale staff required to travel for company business
require a more comprehensive degree of protective measures and
training. Emerging issues that must be addressed are the
safeguarding against Whaling, the use of unsecure public Wi-Fi
networks, and mobile device security. Padgett-Beale understand the
vulnerabilities and inherent risks associated with conducting
business while traveling as well as the daily use of information
technology. Accountability and responsible use of this technology
lies on the individual user and the company. Padgett-Beale requires
full compliance with the prescribed IT policies and procedures when
traveling, teleworking, and working in the office.
c c c c Padgett-Beale’s senior leadership team is the most vulnerable
to being a victim of Whaling. This is a phishing scheme designed to
affect senior staff of an organization by appearing as a legitimate
and valid email in their inbox. Often this scheme will employ tactics
that appear to be coming from other members of the organization or
from business partners. There is usually and urgent requirement to
approve a financial transaction mixed in with specific information
about the organization while using appropriate business language to
masquerade as legitimate business communications between known
associates. An estimated 96% of chief executives are vulnerable to
these types of attacks, (PR Newswire, 2015). The senior leadership
of Padgett-Beale will have a significantly lower vulnerability
percentage. c This needs to be accomplished through thorough
executive specific cyber-awareness training, updated IT policies and
procedures, and signed non-disclosure statements (NDAs) from
every member of the senior leadership staff.
c c c c Any Padgett-Beale staff traveling on business or pleasure
using company IT resources must take additional precautions when
using any public Wi-Fi as means of connection to the internet.
Public Wi-Fi is a widely exploited and vulnerable network access
medium targeted by attackers seeking to gain access to traveler’s
devices and private information. This is often accomplished by
creating a false Wi-Fi network with a strong signal that appears to
be a genuine connection point. Once a user connects the attackers
implement software capable of capturing and reading sensitive date,
(LeTellier, 2017). If the use of public Wi-Fi cannot be avoided, all
PBI staff shall take the following precautions when using a public
Wi-Fi network; refrain from accessing sensitive data, use a PBI
recommended Virtual Private Network (VPN), or create a Wi-Fi
hotspot from a cellular network with a PBI issued smartphone.
c c c c The use of mobile devices is not immune to cyberattacks and
requires precautions and security measures when in use. c Mobile
devices are also susceptible to physical theft. Padgett-Beale will
benefit from implementing a comprehensive mobile use policy that
includes encryption protocols, multi-factor authentication, and safe
security practices. PBI needs to train any mobile user on best
practices to maintain physical security of any mobile device, while
also implementing a Mobile Device Management Software (MDM)
system. Combining physical security practices with MDM software
is an integral building block to incorporating mobile technology into
everyday business practices, (Kleiner, Disterer, 2015).
c c c c Padgett-Bealle, Inc. requires a critical update to the IT
policies and procedures for any staff member using company IT
assets when traveling on business or pleasure. This can be
accomplished through incorporating quality training on topics
related to the use of mobile devices, best practices when using
public Wi-Fi, and mitigation measures to reduce vulnerabilities from
Whaling phishing schemes.
References
Kleiner, C., & Disterer, G. (2015). Ensuring Mobile Device Security
and Compliance at the Workplace. Procedia Computer Science, 64,
274–281. https://doi-
org.ezproxy.umgc.edu/10.1016/j.procs.2015.08.490
LeTellier, V. (2017). Cybersecurity for Travelers. Security, 54(12),
39–41.
PR Newswire. (2015, May 6). Phishing in the C-Suite: 96% of
executives vulnerable to attacks. PR Newswire US.
Students also viewed