The study includes findings from surveys of senior IT decision-makers and end users worldwide, conducted by Vanson Bourne on behalf of Carnegie Mellon University and McAfee on the mobile security and consumerization of IT. About half of the 1,500 respondents across 14 countries say they are "very" or "extremely" reliant on mobile devices, and nearly seven in 10 organizations say they rely more on these devices now than 12 months ago.
The good news is that 95 percent of organizations have mobile security policies, but the bad news is that only one in three employees are "very aware" of these policies. And 63 percent of these laptops, tablets, external drives, smartphones, netbooks, and USBs are employed for personal use as well as business use. The breakdown: Seventy-two percent use personal laptops for work; 48 percent, personal smartphones; 46 percent, personal USBs; 33 percent, personal external hard drives; 19 percent, personal netbooks; and 10 percent, personal tablets.
Jamie Barnett, senior director of mobility product marketing for McAfee, says mobile devices will be the next frontier for malware and other attacks. The report did not go into any abuse of data on the lost or stolen devices.
"There's a ton of concern both from individual users and IT organizations about mobile devices being lost [or stolen] and what happens to the corporate data on them," Barnett says. Around 75 percent of the end users surveyed for the report say they are somewhat or very concerned about data loss due to theft, while some 54 percent of IT staffers were, she says.
Security policies for these devices are all over the map, Barnett says. "Policies are both set and enforced differently," she says. Among the typical policies are rules for what a device can be used for; how the company monitors the end user's communications on the device; device parameters for accessing the corporate network; and technical specifications, such as encryption and password complexity.
The report says more than one-third of the lost device cases came with a financial loss to the organization, and two-thirds of those companies have upped their device security in the wake of a lost or stolen one.
Around 50 percent of users store passwords, PIN numbers, or credit card information on their mobile devices, and less than half say they do weekly backups of data on their mobile devices.
"We're transitioning from the notion of a lifelong, long-term employee to more of a contractor type of employment: I'm an individual employee coming in with my 'kit' of stuff -- my personal database, my knowledge, my own technology, and my own [mobile] devices. Organizations need to welcome them in with their 'kit,' and then at the end of the relationship let those employees go with their kit intact, but also be able to claw back the corporate data that belongs to the organization."
The full report, "Mobility and Security: Dazzling Opportunities, Profound Challenges" is available here (PDF) for download.
Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Spot Trouble In The Cloud: Adapting Security Monitoring & Incident Response.
Security monitoring, incident response and forensics are essential, even in the cloud. But the cloud by definition implies relinquishing at least some control, which can make these practices problematic. In this report, we identify the challenges of detecting and responding to security issues in the cloud and discuss the most effective ways to address them.
Dark Side of the Cloud Becoming Clearer
Recent high-profile breaches against cloud-based services have forced tougher security and closer scrutiny of what to put in the cloud.
Cloud Security: Understand the Risks Before You Make the Move
Security concerns give many companies pause as they consider migrating portions of their IT operations to cloud-based services. But you can stay safe in the cloud. In this Dark Reading Tech Center report, we explain the risks and guide you in setting appropriate cloud security policies, processes and controls. Plus: How to catch up when security is an afterthought to a cloud migration.
| Sponsored by: |
The State of Cloud-based Security
Taking a cloud approach to security can improve protection and lower costs. Download this exclusive UBM TechWeb research to explore why cloud-based security may be more effective in today's complex threat environment.
Turning Security Upside-Down
Organizations can no longer rest on their laurels when it comes to IT security. It is time the security industry took a different approach.
Security as a Service: Business Decision Factors
Better understand the business issues in SaaS: the value it unlocks, the costs-direct and indirect-it avoids, and the corollary benefits like efficiency and agility it supports.
How to Protect Your Business from the Coming Malware Storm
The malware storm will force the cost and complexity of premise-based protection to unsustainable levels. To survive, small and midsize businesses must move defenses outside their own walls.
MORE NEWSFEED >>>