Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

Companies Having Trouble Translating Security to Mobile Devices

As more enterprise work takes place on mobile devices, more companies are feeling insecure about the security of their mobile fleet, according to a new Verizon report.

RSA CONFERENCE 2019 – San Francisco – As more enterprise work takes place on mobile devices, more companies are feeling insecure about the security of their mobile fleet. That's one of the big takeaways from Verizon's "Mobile Security Index 2019," released here this week.

The report is based on responses from 671 enterprise IT professionals from a wide range of business sizes across a broad array of industries. The picture they paint in their responses is one where mobile security is a major concern that's getting worse, not better, as time goes on.

More than two-thirds (68%) say the risks of mobile devices have grown in the past year, with 83% now saying their organizations are at risk from mobile threats. Those risks have changed in the year since the first edition of the "Mobile Security Index."

"In the first iteration, organizations were more nervous about losing access to the device itself" through theft or accidental loss, said Matthew Montgomery, a director with responsibilities for business operations, sales, and marketing at Verizon, in an interview at the RSA Conference. This time, they are worried about " ... having a breach or losing access to the data, because the device became very centric to businesses in the way they work."

Those worries, though, don't necessarily translate into effective security efforts. "There's still this big perception — they think they're secure, that they're doing things to help them with mobile security, but yet they're still telling us that they're sacrificing mobile security to get the job done faster," said Justin Blair, executive director of wireless business products at Verizon.

Montgomery said the sacrifice and inability to put effective security in place is not because the organizations don't understand how to make systems secure. "Most of these organizations have really strong or world-class security in their traditional framework. Their networks, their Windows machines, their firewalls — they take very good care of the cybersecurity," he said.

The breakdown comes in applying those security practices to mobile devices. Part of the problem has to do with the way employees work, Blair said. "It's 10% of the time these devices are showing up on corporate networks, while 90% of the time they're either on a cellular network, on a public Wi-Fi network, or on a home Wi-Fi network," he explained.

And those remote connections contribute to the way organizations think about their employees as threat actors. According to the report, "At 38%, employees topped the list of actors that respondents were most concerned about."

Unfortunately, it's not just accidental employee-driven data loss that worries companies; 46% say personal gain is the leading motivator for employee security breaches, while accidents come in second, at 36%.

How can companies get better? An easy step forward would come from strong policies. The survey results show that less than half of companies (45%) have acceptable use policies (AUPs). Of those that do have such policies, only 21% have policies that could be considered comprehensive, with sections that deal explicitly with mobile devices, external network connections, and acceptable content on enterprise-connected devices.

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8423
PUBLISHED: 2020-04-02
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.
CVE-2019-14868
PUBLISHED: 2020-04-02
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those env...
CVE-2019-20635
PUBLISHED: 2020-04-02
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.
CVE-2020-11452
PUBLISHED: 2020-04-02
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the f...
CVE-2020-11453
PUBLISHED: 2020-04-02
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and, while it is not possible to pass parameters in the SSRF request, it is still possible to exploit it ...