High-stakes security setups are making remote work impossible
wired.com
wired.com
This is not the time to do sweeping IT architecture changes.
That being said, I think lots of normal companies have horrible IT security infrastructures that focus on compliance and covering peoples asses in case things go wrong as opposed to actual security. Those usually also make it hard for remote workers (vs BeyondCorp), which is now coming back to bite them.
What you want is separation, though for real work it quickly becomes impractical. So there are special rules for something, and suddenly, everybody are running on those not-so-special rules anymore.
IT security is still mostly about people and awareness at this point.
Fact of the matter is that some things you don’t ever want remotely accessible. No security is perfect, and if your worst case scenario costs human lives, you simply cannot tolerate any level of risk.
That being said, there are probably companies out there with security that poses more of a barrier to employees than it does protection to the organization. In those cases it’s important for orgs to do their own disaster planning (there are many scenarios where office become unavailable) and make appropriate plans to deal with that.
Some orgs will not be able to function without an office depending on the nature of the work. Many can if they take the time to set up secure ways for people to work remotely beforehand.
The risk decisions (implied or explicit) being made here are sensible. These organizations simply aren't set up to operate in anything like a "BeyondCorp" all-remote model.
The middle of a national crisis is the absolute worst time at which to try to make sweeping changes to facilitate new models of work. In a very plausible worst case, you end up with IT disasters that not only force people to work on site, but force everyone to come in and work extra hours using paper and ad hoc spreadsheet processes, while essential services are compromised for customers.
The concern that "opening up" these organizations would pose security threats isn't just sensible, it's obvious: most large enterprises are set up in the same perimeterized model we used in the 1990s, line-of-business internal applications are almost never hardened against attacks, and most internal segmentation is handwaving; internal site-wide pentests never fail against big companies.
"It's not open to the world" is quite often justification for some really poor security decisions.
Yeah I'm good with that.
† I agree with the cool kids that it's a good thing!