CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Digital Experience (DX)

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Salvador Caetano Group

Jose Santos, Director of IT Infrastructure and Operations

Importance of Integrating Security Measures in On-boarding Candidates for Remote Work

It’s pretty much undeniable that the pandemics acted as a catalyst for digital transformation. We (digital leaders) led the processes of finding, deploying, and providing connectivity, collaboration, and support solutions to organizations that saw their office spaces empty, and had no clue on how to face this desertion. Then, two amazing things happened:

• It seemed that we pressed the fast forward button on the organization side in what comes to the digitalization of business processes.

• The end-user was accepting - let me repeat – accepting (and even embracing) the change. The end user became grown up and learned how to deploy, connect, and troubleshoot its own IT equipment and its connectivity. No more than spoiled children sitting at the office blaming the field support technician about their lack of productivity.

This has happened like that because THERE WAS NO OTHER WAY!

Yet, a lot of things just got behind. Today, we face more security issues and data breaches than ever, and there is hype in all IT and Business communities about cybersecurity. The cybersecurity budget and initiatives are the ultimate benchmark object in networking events and business lunches. And while everyone seems to agree on the human factor as the weakest link, I sense a lack of creativity in countermeasures to increase the security maturity level of the end user. Security awareness training is, in most cases, too generic, provided in e-learning modules, and has a very automated progress track. I have seen several colleagues sending emails, chatting with friends, cooking, etc., while the training videos were playing, just to be able to mark them as completed. Why does this happen? Because, unlike the above, they do not have the feeling that THERE IS NO OTHER WAY! We (leaders) are failing on that. In Gartner’s report on top trends in cybersecurity for 2022, we find in top seven: “Human error continues to feature in most data breaches, showing that traditional approaches to security awareness training are ineffective. Progressive organizations are moving beyond outdated compliance-based awareness campaigns and investing in holistic behaviour and culture change programs designed to provoke more secure ways of working.”

We are failing in the recruitment processes since we are letting the talent shortage shape the process. We compete for the attention and preference of the candidate in a way that we tend to accept the unacceptable. How many of us hired people that we only have seen in a blurred image in a ViCo interview? Based on an unverified CV and some storytelling? Big risk!

In the shoes of a manager of some cloud provider, as an example, I would not feel comfortable hiring a 100 percent remote Infrastructure Specialist with access to bridgehead servers without doing some vet! Remember the “Cloud Hopper” case? The first two steps from a high-level analysis (by Reuters) are:

• Infiltrate the service provider, usually via a so-called “spear phishing” email designed to trick employees into downloading malware or giving away their passwords;

• Once inside, map out the environment, establish footholds and find the target: the system administrator who controls the company ‘jump servers’, which act as a bridge to client networks.

These two steps were easily achieved. Several employees were easily lured!

That’s why vetting is a must! Remote hirings, for 100 percent remote jobs, have an increased risk. Take it into consideration. Put a risk score tag in every role and direct your initiatives accordingly.

We must compete for the attention and preference of the candidate in a way that we tend to accept the unacceptable.

In “Cost of a Data Breach Report,” conducted by Ponemon Institute, we find some figures to understand the leverage factor of this - “when remote working was a factor in causing the breach, costs were an average of nearly $1 million greater than in breaches where remote working wasn’t a factor — $4.99 million versus $4.02 million. Remote work-related breaches cost, on average, about $600,000 more compared to the global average. “Some strategic topics to consider that help mitigate this:

• A zero-trust security model. Adopt it. It helps to prevent unauthorized access to sensitive data and resources. By adding context to the access requests, we gain deeper insights and better incident response. Also, in most cases, there is no need to move or reallocate data. It fits into hybrid, multi-cloud environments.

• Protect sensitive data. And don’t overprotect non-sensitive or public data. It comes with a cost. Adopt strong encryption policies for data at rest and in transit at or to cloud infrastructures;

• Identity access management, endpoint detection and response, and unified endpoint management (IAM, EDR, UEM) are tools that help with the visibility that the security team has on suspicious activity. Blocking, or quarantining the source of the suspicious activity for deeper inspection, can save your day. Also, BYOD policies are easier to deploy and secure.

• SOAR, XDR, and SIEM are also terminologies to consider. All these strategic initiatives need to be tuned and correctly orchestrated, or else there the big risk might be the excessive amount of information generated from events and turn into a flood.

• Be creative in the definition of security awareness programs. Keeping in mind the increased risks we just mentioned, redesign your programs. There are a lot of tools and tactics to consider, like gamification and role-playing. Whatever the approach, the need is to transmit the feeling that there is no other way because there isn’t.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://digital-experience-dx.cioapplicationseurope.com/leadership-perspective/importance-of-integrating-security-measures-in-onboarding-candidates-for-remote-work-nid-3403.html