Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

10/9/2019
03:00 PM
50%
50%

USB Drive Security Still Lags

While USB drives are frequent pieces of business hardware, a new report says that one-third of US businesses have no policy governing their use.

Though nearly nine out of 10 US businesses use USB drives in their IT operation, less than half use any monitoring or encryption to protect the data on those highly portable devices. And the trends are getting worse: Only 47% have a policy for lost or stolen drives compared with 50% with such policies in 2017.

A new report, sponsored by Apricorn, says that 36% of organizations have no written policy concerning USB devices at all. Employees of the companies, however, think that securing the devices is important, with 91% saying that all USB drives should be encrypted.

In one bit of positive news from the research, there was a significant drop in the percentage of companies making regular use of unencrypted USB drives, with 58% doing so in the most recent study compared with 82% in 2017.

For more, read here.

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "Can the Girl Scouts Save the Moon from Cyberattack?"

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
10/9/2019 | 3:44:12 PM
AntiVirius
Can block install of a usb devoce - McAfee - and if you are military, then seal t with epoxy glue, pat down of anyone entering a secure area.  Take the damn thing.  Use encrypt on corporate devices and generally DENY their usage at all except in special cases such as malware forensics.  Handy as hell for exfiltrating data off site.  And super easy to lose too.  Deny their usage 95% of the time. 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/28/2020
GDPR Enforcement Loosens Amid Pandemic
Seth Rosenblatt, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Can you smell me now?
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11018
PUBLISHED: 2020-05-29
In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound reads causing memory allocation with random size. This has been fixed in 2.1.0.
CVE-2020-13634
PUBLISHED: 2020-05-29
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xF1002558
CVE-2020-12675
PUBLISHED: 2020-05-29
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-202...
CVE-2020-11017
PUBLISHED: 2020-05-29
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.
CVE-2020-4306
PUBLISHED: 2020-05-29
IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 17...