Podcast
Root Causes 76: Implications of COVID-19 for PKI


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
March 20, 2020
COVID-19 is rocking all aspects of our daily and business lives. So what are the implications of lock-downs, office closures, and high employee absenteeism on the PKI world? Our hosts explore the implications of our new post-pandemic work culture on business continuity and security, and how PKI fits into this new way of working.
Podcast Transcript
Lightly edited for flow and brevity.
So, if you have staff that are not savvy IT-type thinking people, it could be anybody on your staff, those are the people who might get, it might be too big of a speed bump for them to be able to get into your operations securely, Tim.
So, beyond that, we still must do some hygiene which is if you are in fact using a VPN, the biggest problem with VPN, you are essentially creating an encrypted tunnel between your user’s computer and some other endpoint which is hopefully within a secure network such as your enterprise network. The problem with that comes in when, let’s say that user is tied to an Active Directory credential and that Active Directory credential is overprivileged. In other words, perhaps you’ve given that user admin privileges simply because it was easy. The problem is if that credential happens to be stolen in some way or form, that bad guy now is over prepared.

