Risk
8/30/2007
04:00 PM
Keith Ferrell
Keith Ferrell
Commentary
50%
50%

Mobile Computing Makes For Risky Business

Here's one we all already know -- mobile computer users take more security risks than office-bound computer users. A new survey shows just how risky their behavior is.

Here's one we all already know -- mobile computer users take more security risks than office-bound computer users. A new survey shows just how risky their behavior is.The Trend Micro survey polled 1800 mobile computers users worldwide, and while it drew its respondents from the corporate world the results offer insights -- and concerns -- for small to midsize businesses.

For one thing, 58 percent of mobile users admitted to sending confidential material in e-mail or by IM, as opposed to 42 percent connecting via company networks.

One "no duh" result is that mobile users, being likelier to connect through public or unsecured networks, get more spam, receive more phishing baits, etc.

Being away from the boss's -- or even their co-workers' -- eyes makes mobile users likelier to visit social networking sites and download movies or executable files, again by a large margin over deskbound staff.

Curiously, Trend Micro suggests "that mobile users are often more technically savvy and better educated regarding esoteric security threats such as pharming and phishing." Good news, since they're exposing themselves to more attacks.

Curious because the company's CTO also observed that, "Mobile workers may often be unaware of the risk they pose to the corporate network and that their behavior is increasing the risk to corporate security."

How technically savvy is that?

A certain amount of risky computing practices away from the office is probably unavoidable. "Unwareness" is inexcusable.

The risky behavior of mobile computer users is matched, in my opinion, by the behavior of a company -- of any size -- that issues mobile devices to employees without first putting that employee through a rigorous security training and awareness program that includes signing a detailed computer security and usage policy that has real teeth.

Giving employees a notebook and sending them out into the world without taking such measures? Now that's risky business.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-2977
Published: 2015-07-29
Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors.

CVE-2015-2978
Published: 2015-07-29
Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as demonstrated by an "unintentional reservation."

CVE-2015-2979
Published: 2015-07-29
Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2015-4286
Published: 2015-07-29
The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377.

CVE-2015-4290
Published: 2015-07-29
The kernel extension in Cisco AnyConnect Secure Mobility Client 4.0(2049) on OS X allows local users to cause a denial of service (panic) via vectors involving contiguous memory locations, aka Bug ID CSCut12255.

Dark Reading Radio
Archived Dark Reading Radio
What’s the future of the venerable firewall? We’ve invited two security industry leaders to make their case: Join us and bring your questions and opinions!