Hybrid working is still causing businesses cybersecurity concerns more than two years after home working became commonplace, with CyberArk research indicating that 89% of senior UK security professionals believe the practice has increased security risk for organisations.
Its study assessed how security teams are adapting to evolving threats, revealing security teams are struggling to keep up with new working habits and their repercussions.
Widespread – and often unrequired – access to sensitive information is a prime characteristic of the post-pandemic cyber threat landscape: 50% of workers within organisations have access to their employer’s sensitive corporate data, showing why there is mounting evidence hybrid workers have become a compelling target for threat actors.
Similarly, the adoption of cloud-based apps and services have seen renewed growth in shadow IT: 77% of security professionals polled highlighted this as a significant security risk.
The findings suggest organisations are struggling to keep their security policies up to date with the latest working patterns, especially the rapid acceleration to digital organisations have invested in since 2020.
There are signs advice is beginning to be heeded however, with 87% of UK organisations having adopted an ‘assume breach’ mentality as they seek to put in place defences that reduce the risk of attackers moving laterally once inside networks to access sensitive data and assets.
Commenting on the findings, David Higgins, Senior Director at CyberArk’s Field Technology Office said: “Ways of working have adapted dramatically over the last few years. But periods of huge change are now commonplace and can no longer be an excuse for outdated security practices.”
Recommended
- Tech Nation to Cease Operations
- UK Gov Sets Out Crypto Regulations
- Hackathon Aims to Encourage Girls into Scotland’s Tech Sector
“As cyber techniques evolve and threat actors become more sophisticated in how they target remote and hybrid workers, organisations need to prioritise the most effective steps they can take to protect themselves. Staying ahead of well-funded, innovative attackers means implementing Zero Trust principles combined with a least privilege approach to what human and machine identities can access.
“We need to ensure users access only the information necessary for them to perform their job functions, and only when they need it, authenticating them each and every time. So, wherever they work from, high-value data and assets are better secured.”
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





