The issue here is the IT department allowing employees to install personal software or games on work computers, or access work-related materials on personal machines directly, without a VPN or similar security measures.
The issue here is the IT department allowing employees to install personal software or games on work computers, or access work-related materials on personal machines directly, without a VPN or similar security measures.
(To be fair, I also have a browser-window opened to corporate Slack on my home computer, but that's partly related to issues with VNC/RDP and wanting to use my multiple monitors.)
Did Real Media rebrand again?
The VPN encrypts the network traffic and can serve as a way to let access the internal network only to authenticated devices. But once a device is compromosed by a malware, the VPN doesn't give any extra protection: the malware just needs to wait for the user to activate the VPN, and then can access the company's network just like any other application running on that machine.
In theory, you are correct, and it does increase the risk compared to never having it connected. However, it doesn’t mean it’s automatically compromised, since the initial point of infection happened through a user action (installing the mod), not through an unknown exploit that spreads through a specific network protocol. So just connecting it doesn’t mean infection, not to mention the VPN settings. Maybe they have file transfer disabled or similar, different OS, protection, etc., where it makes it harder to infect. The worst scenario is he was infected with a RAT type (remote access trojan), where the attacker actively tries to scan other hosts connected to the network through VPN to find vulnerabilities.
That being said, accessing the company network through VPN is still the best practice. After all, you need to access the network remotely for a lot of reasons.
It sounds like this employee should have known better than to install a game, and a random mod for the game on a work machine.
I think unfortunately there's a lot of software developers who (and I'll happily include myself in this), think they know better and that they don't have to worry about malware because they use 'common sense'.
One of the biggest issues that I find people tend not to understand is that, even if you find the malware very quickly, and remove it, it only takes a matter of seconds for it to steal credentials / sessions / other sensitive data and send them to who only knows where.
It’s bad recommendations like that which create bad security in the first place.
Edit: practically, the line is getting more and more blurry. I have to install (multiple, ugh) MFA apps on my phone in order to authenticate to various work services. I've always been a strict work/personal separation devotee, but short of buying and carrying a separate phone, it's difficult.
This might actually be even more secure way as on my work laptop there is no personal things. Very rarely I might pay for a train ticket, but that is it.
So MFA is separate from accounts and passwords. Meaning both would need to be compromised at same time...
It starts with the two-factor authentication. Why spend $25 per employee on a yubikey, or several hundred bucks per employee on a company smartphone, when they can use their personal smartphone for free?
Then it's the business travellers, some of whom are very senior people. The CTO is spending the night in a hotel for work, it's well outside of work hours, he'd like to log into his personal netflix account on his work laptop.
Then it's the all-hands meeting about the big reorg - 9am US time, but 8pm for the team in Poland. Of course they're not going to stay in the office to watch that on company equipment, frankly they're doing us a favour by watching it at all.
Then the people wearing headphones in the office want to connect to spotify....
IMHO any large company whose security strategy relies on nobody doing work on a personal device or personal stuff on a work device is destined for failure. You can follow the rule yourself if that's your preference - but if you try to make it mandatory and enforce it effectively, you'll find there are a lot of stakeholders who are unhappy about it...
Every place I've worked for ~25 years has restricted the installation of software on work devices. If the CTO wants to watch netflix, they'd need to take their own laptop or use their phone. Same with Spotify at work.
There has been more allowance for accessing work resources from personal devices in some orgs, though in many places that has also been strictly banned. At my current place, Slack sits in a grey zone where we use it for work but have to maintain discipline around what we discuss. IMO we shouldn't be using it at all.
MFA is almost a separate category - while technically "work stuff" it is reducing attack vectors rather than increasing them.
also, he could be remote working?