The COVID-19 pandemic caused an abrupt change — a sudden and lasting shift to remote work for the majority of knowledge workers. The number of people working remotely more than doubled in the span of a few weeks. Among the many challenges that security organizations faced during this transition was a change in user behavior. The behavior profile of a user working from home (and also working alongside all the other members of their household) is a stark contrast to the profile of the same user working from the office. Managed devices are now being used for more personal web browsing, which includes a 600% increase in visits to pornographic websites. Managed devices are also being shared among members of the household, evidenced by a 450% increase in education app usage aligned with the beginning of the school year. This post highlights the increase in personal usage of managed devices, risky web browsing, and device sharing to support remote learning.
Personal Usage
Those who switched from working in an office to working from home during the COVID-19 pandemic, found once well-defined lines between work and personal life suddenly blurred. Along with this blurring of lines came a change in browsing habits, a doubling of the amount of personal browsing on managed devices.
Figure 1 shows the trend in personal browsing habits for the first half of 2020. It shows the daily total number of visits to websites and cloud apps in the top 5 personal categories, normalized by the number of daily active users on the Netskope Security Cloud platform and displayed as a percentage of their median pre-pandemic levels. Overall, the amount of personal web browsing doubled, led by an increase in visits to “Consumer” and “Streaming & Downloadable Video” websites and cloud apps.
“Other” represents additional personal categories of websites and cloud apps, including:
- Abortion
- Alcohol
- Arts
- Automotive
- Dating
- Education
- Entertainment
- Fashion
- Financial Aid & Scholarships
- Financial News
- Forums
- Games
- Insurance
- Job Search/Careers
- Kids
- News & Media
- Pets
- Tobacco
- Weapons
Risky Usage
While the amount of personal browsing doubled, the amount of browsing to certain risky categories of websites and apps tripled. Figure 2 shows a breakdown of the top risky categories, led by increases in “Gambling” and “Adult Content”. Percentage increases in certain categories were even larger, with the number of visits to “Adult Content – Pornography” increasing 6-fold during the pandemic.
The risks associated with websites and cloud apps in these categories are typically easy to mitigate: organizations block them because their use is a violation of their Acceptable Use Policy (AUP). However, this is not always the case. Many of the malicious threats that the Netskope Security Cloud platform detects and blocks are hosted on websites that aren’t in these traditionally risky categories. For example, we detect more malicious content in “Personal Sites & Blogs” than in any other category. Traffic to this category doubled during the pandemic — as shown in Figure 3 — increasing the risk of exposure to potentially malicious content. This underscores the importance of inspecting web traffic for malicious content.
Device Sharing
The usage of “Education” apps increased 450% at the beginning of the school year, indicating that managed devices are being shared to support remote learn