Section outline

    • We all use digital devices to get work done, communicate with our colleagues and communities, and access the Internet. And, for organizations working remotely, we may be relying on our devices more than ever. So, how can we take appropriate steps to secure the devices we use for work? 

      In this webinar, the CAT team explores best practices for organizations to protect their devices, data, and networks, starting with the basics and increasing in complexity. We discuss how both individuals and teams have roles to play in safeguarding their devices from theft, malware, ransomware, and more. 

      💡 We recommend you pay special attention to the section discussing why you should use separate devices for work and personal use if possible. 

  • Cybersecurity Academy 2025: Social Engineering, Ransomware, and Malware

    Please Click Here to View The Slides From This Session » 

  • Cybersecurity Academy: Device Security and Policies

     

     

    • SLIDES

       

    • SLIDES

       

    • In today’s evolving world of technology, most nonprofit employees use digital devices for work. This often makes them a target of malicious actors trying to find sensitive data they can use for criminal activities. The widespread use of mobile devices for work also puts organizations at risk of cyber attacks such as tampering, denial of service, spoofing and many more. 

      Cyber criminals target mobile devices because, in most instances, users fail to secure their devices. This is why device security is critical.

       

      What is Device Security?

      Device security can be defined as the measures your organization takes to safeguard sensitive information that is stored on portable devices such as laptops, tablets and smartphones. The main goal of device security is to prevent unauthorized access to your data and network. Securing your devices is an important part of protecting your organization against a myriad of threats, most of which come from the internet.

      This document provides some steps you can take to protect your devices.

      Foundational Steps For Stronger Device Security

      If you’re just getting started with device security, review these foundational steps that address many common threats.

       

      Use Password Managers 

      Good passwords are always critical to your digital security. For a device owner, there are so many reasons to protect your device using a password, but the most common reason is to prevent the information stored in your device from falling into the wrong hands. 

      Using a unique, hard-to-guess password is important for any device, product or platform that requires authentication. Ensure that the passwords you use include both lowercase and uppercase letters, as well as numbers and symbols, and that they are at least 10 characters long.

      It can be difficult to remember unique, strong passwords for all the sites and devices you use. Password managers come in handy because they can randomly generate and store different passwords for all your accounts. Using a password manager, you are only required to remember the master password as all your other passwords will be generated, stored and even autofilled for you by the password manager.

       

      Enable Multi-Factor Authentication

      While using a password manager is the first step to secure your passwords, it is always important to add an extra layer of security. This is where Multi-Factor Authentication, or MFA, comes in. With MFA, you are required to take another step to authenticate yourself and access your data. Enabling MFA means that even if an attacker discovers your password, they would still be required to complete the next authentication step in order to access your account.

      This additional step could include the use of a hardware device such as a YubiKey or a one-time code generated on your phone through an authenticator app. 

      Verification using SMS is another way to implement MFA. However, for high-value targets such as NGOs working in hostile environments, SMS is not considered secure enough. 

       

      Enable Disk Encryption

      Encryption is the process of converting plain text into secret mathematical code to hide the true meaning of data, text or other information. Encryption allows for information to be saved in the form of encrypted algorithms and requires a decryption key for access. 

      Whole disk encryption encrypts your device’s entire disk so that when the device is lost or stolen, no one except an authorized user is able to access the contents of the disk. 

      While powerful, encryption does not protect against malware and spyware. Encryption also won’t protect your data if someone grabs your device while it is powered on and unlocked. This is why we recommend you always lock your device when you’re not using it, even when you have encrypted the entire disk. 

      Encryption can also be used to protect external storage devices such as USB sticks and external drives. While these portable tools are valuable for transferring data between devices, they are easy to misplace. This can put the content in external drives at risk of falling into the wrong hands. Encrypting your external drives ensures that only authorized users can get access to the information stored inside. 

      You can turn on encryption on most laptops, desktops, tablets and smartphones by entering a password or by using software such as BitLocker and VeraCrypt.

       

      Use Licensed Software and Apps

      It can be challenging for smaller organizations, especially in developing countries, to access licensed software due to budgetary constraints. Unfortunately, using unlicensed software and modded applications can bring about a variety of threats. 

      Besides the fact that these software packages are illegal, they also contain vulnerabilities that cannot be patched due to a lack of official updates. In the case of modded applications, as enticing as they are due to their extra features, they may contain malicious services running in the background, or in some instances, even share your data with third-party applications. It is therefore important for organizations and individuals to download applications and software only from official sources. 

       

      Install Software Updates

      Software updates help to patch vulnerabilities before an attacker can exploit them. Using unsupported versions of software, including outdated operating systems, puts you at risk because those versions no longer receive security patches. 

      While it is easy for most device owners to ignore software updates, it’s important to apply them whenever there are new updates released. This makes it harder for cybercriminals while also ensuring that the applications in your device are protected from looming threats. You can also use cloud-based software, such as Microsoft Office 365 and G Suite, that automatically updates without any manual input.

      Note: Sometimes a software update notification might be malware. Ensure it’s genuine before clicking it. You can check if a software update is legitimate by visiting the software’s official website. For mobile devices, you can check for software or security updates in the settings.

       

      Using Personal Devices for Work 

      We strongly recommend individuals not use their personal devices for work. Doing so can increase their vulnerability to both personal and professional threats. However, in some cases, individuals must use personal devices for work. If so, we recommend following these steps:

       

      Use Software as a Service (SaaS)

      Google’s G Suite and Microsoft Office 365 are two of the most commonly-used platforms for day-to-day operations within organizations. These tools are typically accessed over the internet, meaning you don’t have to manually install and update the applications themselves. Typically, the service provider manages access to the software and also the availability, performance and security of the application. As a result, the software is always up-to-date. For additional security, users can also use encrypted cloud-based drives that can be built into existing services, such as Cryptomator, or use an external encrypted cloud provider such as Tresorit.

       

      Consider Encrypted, Zero Knowledge Cloud Storage

      Encryption allows data and text to be saved in a secure format in cloud storage. When encrypted, data can only be read using decryption keys. This means that if a malicious actor accesses your device, they won’t be able to read the contents of an encrypted file unless they have access to the decryption key.

      For added security, you can use software with “zero knowledge” of your data. This means that they store your data but do not have access to it. A good example of such software is Tresorit, an online cloud storage provider which provides data encryption for both individuals and organizations. However, with a zero knowledge provider, if you lose the encryption key, they cannot provide you with a backup of your data.

       

      Use a Virtual Private Network (VPN)

      Another way to protect your devices is by setting up a Virtual Private Network (VPN). VPNs allow you to safely access data whether it’s over the internet or stored on your work network. VPNs can also minimize threats such as Man-in-the-Middle attacks by making it difficult for attackers to intercept your traffic. If you’re new to VPNs, this is a good resource

       

      Device Management for Work Devices

      If you are already requiring work-specific devices, there are additional steps you can take to improve your device security. Here are a few ways to get started. 

       

      Consider Mobile Device Management

      Mobile device management refers to any software that offers centralized remote management of devices. Organizations can opt to enroll staff devices into an MDM software to allow IT administrators to automate security policies on devices that are connected to the organization’s network. Using MDM, the administrators can also perform actions such as updating the device, remotely wiping data from the device and troubleshooting the device without needing physical access to the device itself. You can learn more about MDM in this module.

       

      Install Antivirus Software

      Antivirus software is designed to protect computing devices, systems and networks by preventing, detecting and removing malicious programs. With ever-evolving cyber threats, antivirus protection is an essential defense from a wide array of threats and malicious software such as spyware, ransomware, adware, and keyloggers. 

      Typically, antivirus software runs scans to detect malicious software as a background process while you work. Antiviruses can detect real-time threats and act fast to mitigate the spread of the threat while also protecting your device, system or network against potential vulnerabilities. Some operating systems, such as Windows and Mac OS, have built-in antivirus software, namely Windows Defender and XProtect respectively.

       

      Create a Remote Work Policy

      The opportunity to work remotely has helped most organizations reduce costs while increasing productivity. Whether employees are using work-issued devices or personal devices for remote work, it is important to have a policy that will protect the organization’s data, network and devices. A proper remote work policy should include specific examples of device usage, such as how employees can compartmentalize devices to make incident response easier (for example, only using dedicated work devices or not allowing family members to use the same device used for work).

    • If you're just getting started with device security, start with these foundational steps:

       

      Use Password Managers and Multi-Factor Authentication

       

      Enable Disk Encryption

       

      Use Licensed Software and Apps

       

      Install Software Updates

       

      We strongly recommend you do not use personal devices for work, but if you must...

       

      Use Software as a Service (SaaS)

       

      Consider Encrypted, Zero Knowledge Cloud Storage

       

      Use a Virtual Private Network (VPN)

       

      Already using work-specific devices? Good. You can improve your security with these steps.

       

      Consider Mobile Device Management

       

      Install Antivirus Software

       

      Create a Remote Work Policy