AFR: ‘New normal’ is a faster pace of change
AFR: 'New normal' is a faster pace of change
Australian Financial Review, 25 November 2020.
As organisations establish or accelerate their cloud strategy in response to COVID-19, a digital workspace offers a more robust and secure way for staff to work remotely — rather than cobbling together make-shift remote access, which can leave a business vulnerable.
The security finding
Remote working during the pandemic significantly increased the risk of a successful ransomware attack, according to KPMG.
Two factors drove the increase:
- Weaker controls on home IT networks — consumer-grade routers with default credentials and unpatched firmware, shared with personal devices, on networks with no segmentation and no monitoring
- A higher likelihood of users clicking on COVID-themed ransomware lure emails — attackers exploiting genuine anxiety about health information, government support payments and workplace policy
The need to configure access to various business systems and deploy remote-working capabilities within days, rather than weeks or months, also saw some organisations inadvertently compromise on security in their rush to respond.
What "make-shift remote access" actually meant
The AFR's phrasing is diplomatic. The specific compromises made in March and April 2020 are well documented, and they were made by competent teams under impossible time pressure:
- RDP exposed directly to the internet, sometimes without multi-factor authentication — the single most reliable ransomware entry vector of the period
- VPN concentrators scaled past their design capacity, or brought back from decommissioning with firmware years out of date
- Split tunnelling enabled to relieve bandwidth pressure, taking traffic outside inspection
- Personal devices admitted to corporate systems with no management, no encryption and no ability to wipe
- Conditional access relaxed because it was blocking people trying to work
- Local administrator rights granted so users could install what they needed without a helpdesk visit
Each of these was a rational decision on the day. Collectively they described a materially larger attack surface, and much of it stayed in place long after the emergency passed — which is the part that mattered most.
The digital workspace alternative
The AFR's argument is that a properly architected digital workspace is not merely a better remote working experience. It is a more secure one than the improvised alternative, and in several respects more secure than the office it replaced.
The architecture rests on four elements:
| Layer | What it changes |
|---|---|
| Unified identity and SSO | One authentication path, one place to enforce MFA and conditional access, one action to revoke everything |
| Application delivery and virtualisation | Applications and data are delivered rather than installed — corporate data need not reside on the endpoint at all |
| Unified endpoint management | Device compliance is evaluated and enforced, across corporate and personal devices |
| Experience analytics | IT can see how the environment performs for each user, rather than inferring it from ticket volume |
The second row is the one that most directly answers the ransomware risk. When data does not live on the endpoint, a compromised home network has considerably less to reach. And when access is mediated through a single identity with conditional access policy, an unmanaged device on an untrusted network does not simply get in because it has the right password.
Why the perimeter argument stopped working
The underlying shift the article describes had been under way for years; 2020 only removed the option of ignoring it.
The traditional security model assumed a defensible boundary: users inside an office, applications inside a data centre, and a firewall between that and everything else. By 2020 every part of that assumption had failed. Users were at home. Applications had moved to SaaS and public cloud. Traffic no longer passed through any single point where inspection could occur.
Identity became the perimeter, because it was the only control point every access request still passed through. That is why identity consolidation is the first step in a digital workspace programme rather than a later one — every other capability depends on it, and retrofitting it afterwards is considerably harder.
The pace-of-change point
The headline claim — that the new normal is a faster pace of change — held up.
Organisations discovered in 2020 that they could execute in days what they had previously scheduled in quarters. The uncomfortable corollary is that they also discovered how much of the previous timeline had been process rather than necessity.
What did not change is that speed executed on the wrong foundation produces debt. The organisations that came out of the period well were those whose platform choices already supported rapid change safely. blueAPACHE's emPOWER consumption-based model was cited specifically in the company's ARN Mid-Market Partner of the Year win for 2020, on the basis of documented examples of clients rapidly scaling services to support remote working — assessed by an independent judging panel rather than asserted.
What to review now
For organisations still carrying decisions made under 2020 time pressure:
- Is RDP or any management interface still exposed to the internet?
- Is MFA enforced on every remote access path, without exceptions granted during the transition?
- Were conditional access policies relaxed, and were they ever restored?
- Are personal devices still accessing corporate data without management or compliance evaluation?
- Were local administrator rights granted broadly, and have they been revoked?
- Is remote access infrastructure patched to current firmware?
Emergency measures become permanent by default. The review is the only thing that stops them.
Frequently asked questions
What did the AFR article say about remote working and ransomware risk? It reported a KPMG finding that remote working during the pandemic significantly increased the risk of a successful ransomware attack. Two factors drove it: weaker controls on home networks — consumer routers with default credentials and unpatched firmware, no segmentation, no monitoring — and a higher likelihood of users clicking COVID-themed lure emails that exploited anxiety about health information, support payments and workplace policy.
What does "make-shift remote access" actually mean? The specific compromises made under time pressure in March and April 2020: RDP exposed directly to the internet, sometimes without MFA; VPN concentrators run past their design capacity or recovered from decommissioning with years-old firmware; split tunnelling enabled to relieve bandwidth, moving traffic outside inspection; unmanaged personal devices admitted to corporate systems; conditional access relaxed; and local administrator rights granted broadly. Each was rational on the day. The problem was that they persisted after the emergency.
What is a digital workspace, and why is it argued to be more secure? It rests on four layers: unified identity with single sign-on, application delivery and virtualisation, unified endpoint management, and experience analytics. The security argument turns on the second: when applications and data are delivered rather than installed, corporate data need not sit on the endpoint at all, so a compromised home network has much less to reach. Access mediated through one identity with conditional access also means an unmanaged device does not get in merely by presenting the right password.
Why did the traditional network perimeter stop working? The model assumed users inside an office, applications inside a data centre, and a firewall between that and everything else. By 2020 every part of that had failed — users were at home, applications had moved to SaaS and public cloud, and traffic no longer passed through any single point where inspection could occur. Identity became the perimeter because it was the only control point every access request still passed through, which is why identity consolidation comes first in a digital workspace programme rather than later.
What should an organisation review if it still carries 2020 decisions? Six things: whether RDP or any management interface remains internet-facing; whether MFA is enforced on every remote access path without leftover exceptions; whether relaxed conditional access policies were ever restored; whether personal devices still reach corporate data without management or compliance evaluation; whether broadly granted local administrator rights have been revoked; and whether remote access infrastructure is patched to current firmware.
What was blueAPACHE's connection to this story? The emPOWER consumption-based model was cited in blueAPACHE's ARN Mid-Market Partner of the Year win for 2020, on the basis of documented examples of clients rapidly scaling services to support remote working. That assessment was made by an independent judging panel rather than asserted by the company.
Is this article still current? It was published on 25 November 2020 and describes the conditions of that year. The architectural argument about identity as the perimeter has held, but the specific pandemic context has passed. For current services see the linked pages rather than this article.
Related
- Security services
- emPOWER Security
- emPOWER SASE — identity-mediated secure access
- Human risk management — the phishing-lure layer
- Managed detection and response
- Microsoft practice — identity, Intune and conditional access
- Collaboration
- Cloud services
- Managed services
- Governance, risk and compliance
Source
Original article published by the Australian Financial Review, 25 November 2020. Ransomware risk findings attributed to KPMG.
Knowledge Base
What is the title of this blueAPACHE blog post and where was it originally published?
The blog post is titled 'AFR: ‘New normal’ is a faster pace of change' and it was originally published in the Financial Review on November 25, 2020.
What is the main topic discussed in the AFR article featured on this blueAPACHE page?
The article discusses how, as organisations establish or accelerate their cloud strategy in response to COVID-19, a digital workspace offers a more robust and secure way for staff to work remotely, compared to cobbling together make-shift remote access that can leave a business vulnerable.
What security risk does the article say increased due to remote working during the pandemic?
According to KPMG, as cited in the article, remote working during the pandemic significantly increased the risk of a successful ransomware attack, due to weaker controls on home IT networks and a higher likelihood of users clicking on COVID-themed ransomware lure emails.
Why did some organisations compromise on security when responding to the pandemic, according to the article?
The article explains that the need to configure access to various business systems and deploy remote-working capabilities within days, rather than weeks or months, led some organisations to inadvertently compromise on security in their rush to respond to the pandemic.
Who is credited as the author of this article on the blueAPACHE website?
The article is attributed to AFR (Australian Financial Review) and is categorized under 'Press' on the blueAPACHE site.
Where can readers find the full version of the AFR article referenced on this page?
The page provides a link to the full article at https://bit.ly/3funmKq.
What call to action does blueAPACHE present at the end of this blog post?
The page invites readers to 'Outpace Change' by partnering with blueAPACHE to improve performance, strengthen security, and simplify complexity through IT Operations Excellence as a Service, with options to speak to the team or get support.
What support contact options does blueAPACHE provide on this page?
blueAPACHE provides several support options: Remote Access, Client Portal, phone at 1300 135 548 (Australia) or +61 3 8696 9369 (International), Email Support at support@blueapache.com, and the option to speak to the team via the contact page.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a7021d24d727184e2179ce5_Mark-Bird_Service-Centre-Team-Leader2-1024x768.avif
AFR: ‘New normal’ is a faster pace of change
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a97bf808cd6fb2332032e62_blueAPACHE-ARN-Finalist-2026.png
blueAPACHE named 2026 ARN Innovation Awards finalist, setting sights on an eighth consecutive win
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a94ed426586d8f094e31f8a_cobrand_card_cinematic.png
blueAPACHE Expands Huntress Partnership to Accelerate Access to Enterprise-Grade Cybersecurity Across Australia
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a90d76875cc19d2f0222e6a_09_two_up_headshots_cinematic.avif
TechDay - blueAPACHE partners with ControlUp on managed services
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a8faffa0803d40169eebc40_01_executive_portrait_cinematic.avif
ARN - blueAPACHE takes services to the next level with ControlUp
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a70216e4d727184e21771f5_Website-Blog-Banners-11.avif
blueAPACHE launches managed human risk service with Mimecast
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a702187c4df8435ad3b6b58_Website-Blog-Banners.avif
blueAPACHE Ranked on 2026 MSP 501 – Tech Industry’s Most Prestigious List of Global Managed Service Providers
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a702187c4df8435ad3b6b53_Website-Blog-Banners-10.avif
blueAPACHE targets mid-market with human risk service
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.