SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Project Management

Protecting the mobile workforce

Protecting the mobile workforce

By:  Gareth Maclachlan  On: 29 Feb 2008 For: CIO Canada Creator

With the malware threat to mobile devices growing larger and the need to protect corporate information essential, now is a good time for IT executives to think about putting a comprehensive mobile security policy place. Here are some points to consider.

The productivity benefits of smart phones and other mobile devices are difficult to ignore, and enterprises will continue to role them out across their workforce. For CIOs and other senior IT personnel the time to consider and implement a comprehensive mobile security policy is now.

Security measures should take into account security threats that are both external and internal while enabling a holistic approach that encompasses personalization and other access controls. The mobile environment has numerous weaknesses, and specialized threats are growing increasingly severe. Currently, there are over 300 mobile virus variants loose globally. The latest versions are more sophisticated and attack a device with the purpose of generating revenue or stealing confidential stored data. From an employee’s credit card information to his Outlook appointments, every stored piece of data can be vulnerable.

Sophos’s Security Threat Report 2008 indicated that the wider use of new mobile technologies and Wi-Fi enabled devices may be opening up new vectors of attack for hackers. As personal Wi-Fi devices grow in popularity, the report states, the risks will no doubt increase. Sophos experts also note that low cost ultra-mobile PCs, such as the popular Linux-based ASUS Eee laptop, are likely to gain the attention of the cyber underworld as sales continue to grow.

My own company’s research in cellular operator networks indicates that while infection rates are low overall, corporates are the most vulnerable to viruses for three reasons: firstly, companies tend to use one or two phone types; secondly, employees have similar address books so are more likely to trust an MMS or email from a colleague; and thirdly, few individuals are made to check their bills so high MMS and SMS spend is ignored.

Leaving aside the threat of mobile viruses, which is still early, CIOs are also having to look at the impact of anti-harassment, data protection and industry-specific regulation. An employee who texts an inappropriate joke or sends an offensive picture from his company camera phone to another colleague may place the company under the same liabilities as if he had used email from his work PC. One proof of concept virus downloaded pornographic pictures and sent them to all the contacts on a user’s phone – embarrassing for the sender and potentially damaging for the company if sent to customers.

Legislation has forced CIOs for years to ensure that email and voice communication is logged and archived for future auditability or risk management. But what proportion of a company’s communications occurs over mobile devices, rather than from the office PC and desk phone? Savvy cellular operators are looking at providing message archiving services for corporate customers, moving from being just a carrier to a provider of security services for corporates. Acceptable Use Policies for Web browsing from the office are expected, but Internet-enabled phones and high-speed data cards for laptops allow employees to breach these policies without fear.


Sign up for our Newsletters












Print |  Views: 675   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Gareth Maclachlan Gareth Maclachlan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Why Gen Y workers bypass IT usage policies
Why Gen Y workers bypass IT usage policiesAn IT World Canada/Harris-Decima report looks at the generation gap and shows younger employees don't take the rules around office computing very seriously. Get the stats about the demographic shift
Mobile attack via SMS messages under spotlight
Mobile attack via SMS messages under spotlightAll mobile phones may be open to a simple but devastating attack that enables a third-party to eavesdrop on any phone conversation, receive any and all SMS messages, and download the phone's address book.
Security: Keeping mobile workers safe from highway robbery
Security: Keeping mobile workers safe from highway robberyWhether a mobile device is stolen, forgotten or merely misplaced, it can pose a serious threat to enterprise security. Yet studies show that many Canadian organizations don’t seem to recognize the risk posed by these roaming devices. Here’s an update on this growing problem – and some advice on what you can do to help solve it.
Dave DeWalt and the mission for McAfee
you didn’t have to know that dave dewalt is the ceo of

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.