Skip to main content
Research Paper Undergraduate 3,429 words

Cybersecurity in the COVID-19 Era: Remote Work Threats

~18 min read
Abstract

This paper examines the cybersecurity challenges that emerged during the COVID-19 pandemic, with a focus on how the shift to remote work created new vulnerabilities alongside existing threats. Drawing on guidance from CISA, the UK's National Cyber Security Centre, and academic literature, the paper outlines the surge in advanced persistent threat (APT) activity, phishing campaigns, and social engineering attacks targeting healthcare, government, and research organizations. It then presents frameworks for assessing and improving cybersecurity controls, discusses strategies for restoring operational normalcy after a disruption, and reflects on lessons learned from past information security failures. The paper concludes with recommendations for ongoing employee training, data backup protocols, and regulatory compliance.

Key Takeaways
  • The Current Situation and Its Impact on Cybersecurity: COVID-19's effect on cybersecurity threats and APT activity
  • The Basics of Cybersecurity Control: Frameworks for assessing and implementing security controls
  • Restoring Normalcy After Disruption: Disaster recovery strategies and data backup protocols
  • Learning from Past Failures: Lessons from ransomware, phishing, and social engineering attacks
  • Conclusion: Summary of findings and key security recommendations
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Integrates authoritative primary sources — including the joint CISA-NCSC Alert AA20-126A — alongside peer-reviewed and professional journal literature, giving the argument institutional grounding.
  • Uses two structured reference tables to translate abstract cybersecurity concepts into actionable, step-by-step frameworks that practitioners can apply directly.
  • Maintains a consistent applied focus throughout: each section moves from identifying a threat to describing a concrete organizational response, creating a clear problem-solution arc.

Key academic technique demonstrated

The paper demonstrates synthesis-driven argumentation: rather than simply summarizing individual sources, it weaves together government alerts, journal articles, and white papers into a unified analytical narrative. For example, the CISA-NCSC guidance is introduced as evidence of the threat landscape, then supplemented by audit and risk management literature to show how organizations should respond — a technique that shows readers how multiple sources collectively support a single claim.

Structure breakdown

The paper follows a classic problem-response-reflection structure across five sections. The opening section establishes the pandemic's impact on the cybersecurity threat environment. The second section presents assessment frameworks for evaluating and strengthening existing controls. The third section addresses disaster recovery and operational continuity. The fourth section draws lessons from documented past failures. The conclusion synthesizes key findings and reiterates the most critical recommendations for information security management.

The Current Situation and Its Impact on Cybersecurity

The number of COVID-19 cases and the death toll attributable to the virus steadily increased across the country in the months following the pandemic's onset, and companies of all sizes and types were hammered by a combination of a turbulent presidential election, an unrelenting economic downturn, growing civil unrest, and increasingly severe climate-related events that produced some of the worst unemployment rates in the country's history. While the situation remained highly dynamic and global case numbers continued to swell, at the time of this writing more than 40 million people worldwide had been infected by the virus and more than 1.5 million had died from it, based on statistical data compiled daily by Johns Hopkins University. From a strictly pragmatic perspective, one of the few bright spots on the economic horizon had been the growing demand for the accelerated domestic manufacture of personal protective equipment and therapeutic drugs by local, state, and federal government agencies (Meredith, 2020).

Against this grim backdrop, it is not surprising that the situation for cybersecurity also became increasingly challenging and threatening. According to Martinelli and Friedman (2020), "There have been several reports from the [information technology] community that there have been more attacks against cybersecurity infrastructures than in the past few years. Indeed, cybersecurity was a persistent threat before COVID-19, and not surprisingly, organizations continue to face increasing risks in this area" (p. 60). Unfortunately, although the risks associated with IT resources continued to accelerate, there was not generally a corresponding response on the part of the information security community.

A growing body of research confirms that nature imbues many predators with the ability to detect fear, and the current situation is analogous with respect to hackers sensing opportunity among their traditional prey. This sense of opportunity may help account for the increased cyberattacks experienced by the private and public sectors, but the threat had always been present — it simply became more intensified. One mainstream newspaper warned its readers that:

"The COVID-19 pandemic has changed our daily lives and routines dramatically. However, it seems that hackers remain undaunted and are still up to their old tricks, as the number of coronavirus-themed scams and security incidents related to it has been increasing steadily since January [2020]. Hackers are preying on people's fears by spreading disinformation and monetizing panic." (COVID-19 pandemic has hackers working OT, 2020, p. 13)

Given the enormous mental health burden exacted by the ongoing pandemic, these cautions are well timed and on point. Hackers and other malevolent actors — commonly referred to as "advanced persistent threat actors" — are also specifically targeting essential workers. National security authorities in the United Kingdom and the United States issued alerts warning public and private sector leaders that "actors are actively targeting organizations involved in both national and international COVID-19 responses [including] healthcare bodies, pharmaceutical companies, academia, medical research organizations, and local governments. Advanced persistent threat actors frequently target organizations to collect bulk personal information, intellectual property, and intelligence" (Martinelli & Friedman, 2020, p. 60).

What is known with certainty is that IT risk managers are confronted with many of the same cyber threats that emerged in recent years, together with novel applications that are successfully exploiting COVID-19-related fears and anxieties. In this regard, Martinelli and Friedman (2020) report that, "Despite the global pandemic, threat-actors continue to pose threats that require an internal audit to assess the organization's risk management program" (p. 60). Unfortunately, internal audits represent only part of the overall strategy needed to counter the growing threat from hackers and other state and non-state actors (Martinelli & Friedman, 2020).

In response to these emerging threats, the U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom's National Cyber Security Centre (NCSC) collaborated to formulate an appropriate strategy. The joint CISA-NCSC Alert (hereinafter "the Alert") was released in early April 2020 as reports of cybersecurity threats began to surge following the onset of the pandemic. The Alert provides the following timely guidance concerning malicious cyber activity specifically related to COVID-19:

There has also been a corresponding decrease in the number of IT employment opportunities available from American employers for prospective graduates and non-graduates alike. A recent editorial in The Washington Post cautioned that "the most talented scientists and computer engineers of the next generation are choosing Canada, Australia, China — anywhere but [the United States]" (Trump's America in 2024, 2020, para. 4).

Beyond these challenges, organizations with dedicated cybersecurity infrastructures are also scrambling to find ways to budget for the increased costs of maintaining order within both their organizations and their information security (InfoSec) teams. While every organization's cybersecurity situation is unique, many if not most have experienced various types of threats — including some that have only recently been deployed (Lanz & Sussman, 2020). Public and private sector organizations are thus facing not only conventional IT-related threats but also an expansion in their scope and severity, further exacerbating the current situation (Lanz & Sussman, 2020).

These trends mean that there is no room for complacency. IT security professionals must not only remain vigilant for known threats but also continuously survey the horizon for newly emerging threats. As Lanz and Sussman (2020) caution, "This understandable change in focus must still consider an environment more conducive to computer-facilitated frauds and increased cyber-threats" (p. 28). The harsh reality is that the nature of cybersecurity threats has changed and expanded substantively in recent years, and most especially in the months following the onset of the COVID-19 global pandemic.

Cybersecurity experts also warn that computer-facilitated frauds and increased cyber-threats have been further enabled by the proliferation of unstructured data of all types (Schultz, 2009). Unstructured data can refer to virtually any type of digitized document, including video files, graphic presentations, blueprints, and images. Regardless of the type of electronic information involved, these resources are highly vulnerable to unauthorized access, manipulation, and even destruction by malicious actors (Schultz, 2009). This is an especially important concern since the vast majority — over 85% — of all business information is stored in an unstructured data format. As Schultz (2009) concludes, "To make matters worse, the amount of unstructured data within companies is still growing. With email and file services being the biggest contributors, more and more information is becoming available electronically and easy to share" (p. 5). While unauthorized access to unstructured and other sensitive data cannot always be prevented, there are straightforward steps that can be taken to ensure that maximum cybersecurity controls are in place.

The Basics of Cybersecurity Control

The requirement for basic cybersecurity controls depends on a number of organizational variables, so assessing the adequacy of existing controls represents the first step in ensuring that appropriate IT protocols are in place. While the precise steps required may include additional factors, the general steps outlined below provide a useful framework for a cybersecurity control assessment (adapted from Mutune, 2019):

Assess the size of the organization. The details concerning interconnected systems, employee count, network size, and similar metrics should be reviewed. Assessing organizational size assists in financial planning and decision-making and helps identify which controls should be implemented to mitigate existing challenges.

Determine the scope of IT infrastructure. A company must identify all IT components within the scope of cybersecurity controls — including applications, information systems, network devices, servers, and cloud applications — regardless of whether they are contracted or owned. A thorough assessment will guide the organization in listing all assets within scope.

Determine the security levels of IT assets and information systems. Companies need to identify the information systems and IT elements requiring higher levels of security and assign value to various types of information and assets. For instance, personally identifiable information (PII) regarding employees or customers may require higher levels of protection, while confidential information such as intellectual property or competitive strategies requires adequate security to prevent breaches. Security assessments should address the integrity, availability, and confidentiality of critical IT systems and information. A scale of very low, low, medium, and high — with "high" representing assets requiring the greatest security — allows organizations to distribute cybersecurity controls according to need. This approach also assists in budget planning by directing more resources toward areas requiring greater controls.

Confirm investments in cybersecurity. Before planning for the acquisition and implementation of controls, security managers should confirm current investment levels in cybersecurity by reviewing expenditures allocated to IT security and data protection. Organizations should also factor in costs for intangible controls such as employee training.

The assessment of existing cybersecurity controls should also be measured against the essential security control elements described below to determine their adequacy and to identify opportunities for improvement (adapted from Mutune, 2019):

Maintain a comprehensive incident response plan. Using available technology such as artificial intelligence, cyber adversaries can commit stealthy cybercrimes. Every organization should implement and continuously update a plan for responding to cyber incidents, including measures for recovering from an attack.

Observe a strict patch management lifecycle. Organizations that rely heavily on IT support may implement varying technologies from multiple vendors, providing attackers with increased points of entry. Hardware or software may also contain security vulnerabilities that hackers exploit to gain system access. A rigorous patch management lifecycle is therefore essential.

Apply antivirus solutions. Antivirus products such as Malwarebytes, McAfee, or Windows Security Center provide measures for detecting and eliminating malware threats. Cyber actors trick system users into installing various families of malware, including spyware, ransomware, worms, and Trojan horses — all of which fall into recognized malware categories.

Implement perimeter defense. Perimeter defenses protect networks from attacks executed through the internet. Conventional network security controls include firewalls, which identify suspicious traffic and block it from entering the network. Businesses should establish dedicated firewalls — combining both hardware and software solutions — at the boundaries connecting a corporate network to the internet.

Secure mobile devices. The Internet of Things and mobile devices enhance work processes and productivity, leading many organizations to adopt them at scale. Whether company-owned or employee-owned under a bring-your-own-device policy, businesses must develop appropriate measures for safeguarding company data processed through or communicated by these devices.

Emphasize employee training and awareness. Training employees on cybersecurity basics is one of the most crucial controls, since attackers frequently exploit user ignorance to execute attacks. The success of phishing attacks, for example, largely depends on a user's inability to identify phishing emails. Employee security training provides the first line of defense and enhances overall security posture.

Implement strong user authentication. One of the leading causes of security incidents is insider threats — whether from employees assisting hackers or from users committing cybercrimes for personal gain. Malicious insiders may steal the login credentials of other users to cover their traces. Implementing strong user authentication is an effective control for mitigating insider threats.

Observe strict access controls. Access controls build upon the security that user authentication provides. They govern which authenticated users can access which resources and at what level. Different access control measures exist, and it is the organization's responsibility to choose an approach that meets its specific security concerns.

In the event that security-related threats are identified during the assessment process and solutions are implemented, it may be necessary to repeat the assessment to ensure that all related threats are also addressed. Assessing the adequacy and appropriateness of cybersecurity controls is an ongoing, iterative process that is essential for restoring normalcy in the event of disruptions caused by catastrophic events.

2 locked sections · 670 words
Sign up to read the full analysis
Restoring Normalcy After Disruption390 words
In this context, returning to "normalcy" may be a highly subjective and relative goal. For the purposes of this discussion, normalcy will be regarded as…
Learning from Past Failures280 words
Although the current "perfect storm" of multiple crises is unprecedented in scope and severity, there have been mistakes made both before and during COVID-19 that offer valuable lessons, including so-called "trap setters." Global firms were targeted in the past during the political tensions between the United States and Iran, and this potential has become even more pronounced as tensions between the two countries have continued to deteriorate. The Dharma ransomware operators targeted organizations within East Asian countries and…
Read the full paper →
Plus 130,000+ examples & all writing tools

Conclusion

The world has always been a hostile environment for humankind, but recent months have been characterized by a unique mix of anthropogenic crises and natural disasters that have taxed the ability of even the most sophisticated cybersecurity networks to protect vital information resources. The research showed that the optimal management of COVID-19 and comparable societal disasters requires ongoing diligence to assess the adequacy and appropriateness of existing security protocols and to weigh those resources against essential industry cybersecurity control benchmarks. The research was also consistent in showing that far too many organizations are unprepared for existing and evolving cybersecurity threats. There are, however, strategies available to help organizations of all sizes inform, educate, and train their employees concerning these trends and to emphasize the importance of consistently following security protocols. Finally, organizations must ensure that they have sufficient off-site data backups and security procedures in place to restore their operations to normalcy at the earliest opportunity.

References

Alert AA20-126A. (2020, May 5). Cybersecurity & Infrastructure Security Agency. Retrieved from

COVID-19 Cyber threat exploitation. (2020). National Cyber Security Centre. Retrieved from

COVID-19 pandemic has hackers working OT. (2020, April). USA Today, 148(2899), 13.

Davis, S. (2010, November 25). Effective training and policy takes the fear out of social networking. Illinois Institute of Technology White Paper: Author.

Lanz, J. & Sussman, B. I. (2020, June). Information security program management in a COVID-19 world. The CPA Journal, 90(6), 28.

Martinelli, M., Friedman, A. E. & Lanz, J. (2020, June). The impact of COVID-19 on internal audits. The CPA Journal, 90(6), 60.

Meredith, S. (2020, October 22). Learn to live with the pandemic: Physicians warn that a vaccine may not prevent Covid from becoming endemic. CNBC. Retrieved from

Mookerjee, V., Mookerjee, R., Bensoussan, A. & Yue, W. T. (2011, April 8). When hackers talk: Managing information security under variable attack rates and knowledge dissemination. Information Systems Research, 22(3), 410–420.

Mutune, G. (2019, August). Ten essential cybersecurity controls. CyberExperts. Retrieved from https://cyberexperts.com/cybersecurity-controls/.

Petrick, B. (2020, September). Stymie hackers with these six steps. Journal of Accountancy, 230(3), 79–83.

Schultz, A. (2009, December 23). Controlling the emerging data dilemma: Building policy for unstructured data access. Illinois Institute of Technology White Paper: Author.

Trump's America in 2024. (2020, October 23). The Washington Post. Retrieved from https://www.washingtonpost.com/opinions/trumps-america-in-2024/2020/10/23/f7be173a-14a6-11eb-bc10-40b25382f1be_story.html.

Key Concepts in This Paper
Advanced Persistent Threats Remote Work Security Phishing Attacks Data Backup Cybersecurity Controls Social Engineering Patch Management Incident Response Ransomware CISA Alert
Cite This Paper
PaperDue. (2026). Cybersecurity in the COVID-19 Era: Remote Work Threats. PaperDue. https://www.paperdue.com/study-guide/cybersecurity-covid-19-remote-work-threats-2181466

Always verify citation format against your institution’s current style guide requirements.