Remote Work and Compliance Approaches – Alec Nuñez, Poll Everywhere
Alec Nuñez, director of business compliance at Poll Everywhere, explains while there may be more people than ever returning to the office the number of employees continuing to work from home (WFH) has fundamentally changed the way organizations need to approach compliance.
Transcript
This is texturong TV. Hey guys. Thanks for the throw.
We're here with Alex Nunez who's director of business compliance for poll everywhere, and we're talking about Security in remote areas working from home working from everywhere. It looks like we're all finally settling down to some reality post covid that says, maybe we're just gonna be working whenever in any chance we get no matter where we are Alec welcome the show. Thank you.
Thanks for having me. It seems like we had this intense debate after covid where how many people were going to go back to the office and how many people were going to be working from home? But from my perspective in reality everybody I talked to is working Here There and Everywhere.
So do we need a different thought process for our cybersecurity than just assumes that people are gonna connect it the oddest times in the honest places and we can't have everybody behind it firewall. That's true. And and I agree.
I think it definitely poses different situations scenarios. Not necessarily always bad and not necessarily always better I guess but it does change things and like anything related to technology. We have to be able to adapt and a timely manner when those things changes because they pose new typically new problems that we have to solve for definitely.
Are you seeing people kind of settle on some best practices for securing and working from everywhere? And what does that look like? Definitely definitely and speaking from poll everywhere is point of view.
We actually kind of were in a unique situation where we were basically like a third of our Workforce was already pretty hybrid. So our was hybrid or fully remote so we kind of got a head start I guess relative to other organizations or companies that are moving in this direction right now. So but yes, there's definitely a few things that every organization could could Implement some easier than others, but that would lay a great foundation for for basically making you a little more secure on your day to day especially with people all over the place.
I think that my starting point I guess would be is that I think that we need to focus on changing the culture of our Workforce as it pertains the security in the sense of we need Study to be aware of it not just hear about it from some specific it department. For example, they need to kind of make it second nature that of in their handling of the day-to-day business and because they're going to be interacting with a lot of data that comes through either directly to them from a customer or maybe that they have access to and so I think I'm training and educating your employees is going to be a huge thing moving forward and and not just, you know, like a once a year kind of thing it consistent basis to me to get to you that second nature kind of thing. I was referring to I I also think another important principle.
I guess people should Implement would be the principle of access at least privilege or the principle of least privilege where you are basically to Simply put you only have access to what you need to have access to do your job. So a lot of companies have a lot of different applications and different tools that they use in the day to day. That doesn't mean that everybody should have one the same access or access in general.
I think it's very important to probably audit what your tools you're using and who has access to what and why they have access to it and lock that down maybe on a more granular level if it's possible. So those are two things that I think are very important moving forward in the hybrid Workforce scenario that we're talking about The organizations need to find a way to enforce policies more aggressively because it seems to me we gave people a VPN and we said, you know, good luck and you can log in and access anything anytime and the VPN itself may not be all that secure and then it turns out that people don't turn on the VPN all the time because they forget or they are doing a zoom call and they want to blame the VPN for the jittery experience. How do we you know and for some level of consistency at a time when people aren't actually in the office.
Yeah, so so how we've approached it is this is an opportunity to bring in a new tool. I guess that you could say and I'm not going to say that every single piece of technology is going to be there's no absolute in solving these issues as you're probably fully aware. But what we can strive to do is mitigate the issues by by finding different tools and resources that we can do to implement and so in this case, I would say we have done things like Implement different mdms or mobile device management tools.
So with people working off of their lot laptops now and they're not Tethered to you know, some big desktop computer at their office is the only way they're they're accessing things anymore. Now that everybody is kind of working wherever quite honestly they can have the ability to work wherever you can Implement certain tools like an MDM or mobile device management tool and you basically can enforce across your entire device cache. I guess specific security settings.
And and requirements in order for them to even access anything that is customer or rather company data related. So for example, you can establish certain settings on there that require people to use complex passwords or they require that they encrypt their devices you require that to gain in order to gain access to other elements of I guess the company system or other tools that they have to have X Y and Z in place prior to even be able being able to work for that matter I guess is one way to put it that's one way that you can approach it to in order to enforce things remotely. They even have different services.
So like we in the event that somebody is working remotely and for example, you know, they leave their computer or their smartphone or something that they may access company data via if they if that happens to be stolen or lost you have the ability with the sense of devices to or rather tools to remotely wipe them in order to just Safeguard your company and your customers data and the event that's something like that happened. So hopefully that kind of answers the question that you had do you think people are moving more towards this zero trust model and that would be kind of the general direction that they should go in and with a more identity-centered approach, I guess so that if someone's using a machine you kind of have a sense of the machine the applications and the person Yeah, definitely. I think that is definitely the direction we're going and even to kind of take it further.
I think speaking back to that culture change that I was kind of alluding to I think that people should just have second nature to just kind of question anything that actually crosses their desk via their their device in the sense of be it from something as small as just an email that comes in through a customer that you've been interacting with and may contain a lake or some other attachment or whatever. They just have to kind of question any type of interaction that they're having online prior to accessing certain things so that in order to avoid in the event that either they're being fished or maybe they're downloading a virus or etc those types of situations. All right, so you have compliance in your title, and some people would say that compliance is both the best and worst thing that ever happened to cybersecurity and we are maybe going to see more regulations this year.
So do you think that those and more stringent regulations are a good thing or do they get in the way? So I'm speaking from the customers point of view. I think it's a great thing.
I think that you should as a customer is somebody who uses different tools. I always want to be able to know like what what and how is being used of my data or my personally identifiable information for that matter? I think that's a great thing.
I realize that as things change. There's gonna probably be some time that we need to work with the different regulations in order to make them better. It's probably it does definitely slow things down.
So for example, when the general data protection regulation came out from Europe back in at 2018, that was definitely something that I know that a lot of companies that have customers in Europe had to deal with and it seems like a big task a big load to to have to or rather a big a big hurdle to try and jump over and it's what wasn't something that was just easily done. So I would assume from the company's perspective. It's definitely gonna add a little more bureaucracy.
You're gonna have to a little a few more, you know logs or different things requirements. You have to implement on on the main maintenance side of things in order to be in compliance, for example, but generally speaking I think it is a good thing. I think we should always be protecting each other's data and be respectful of each other's data and not just take advantage of the situation that we might be in.
All right cybersecurity professionals everywhere seem to be freaking out about these new AI generative tools and chat GPT and all this other stuff in the bottom line on it is that they're gonna increase potentially the sophistication of the fishing attacks and the volume of those attacks. So somebody on the front line and this, you know, are you concerned are you looking at all this stuff? And you know, are you ready to just throw up your hands?
Are you gonna fight the fire? No, I think I don't want to I don't want to give up just yet. I think I think it's always worth it to fight the good fight.
And and again, this is why I think the it's so important that I think just generally as as a society I guess is we want to make it even bigger is that security is is obviously here to stay as a pertains to data privacy. I think it's very important that people educate themselves and that they're aware of what's going on. And again the default like mode should be I'm going to Question this thing that I got be it from you know, it might look like it's coming from my CEO or maybe the CFO or somebody's asking me for some information just using that as an easy example.
I think these are things that we can definitely mitigate the potential problem that would occur and and again technology is going to continue to advance like that. Rapidly. We we have to be vigilant stay vigilant on that front as well.
All right, folks you heard in here zero trust. It's not just a mindset. It's a way of life.
We're all going that way one way or another. So here we go, Alex. Thanks for being on the show.
Thanks for having me. All right back to you guys in the studio.