Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

5/24/2011
05:28 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Half Of Lost Or Stolen Mobile Devices Store Sensitive Company Data

Carnegie Mellon, McAfee report finds that one-third of lost mobile device cases resulted in financial loss to the organization

Mobile devices are coming to work in droves, and they're being lost or stolen en masse, too: Four in 10 organizations say some of their mobile devices have been lost or stolen, half of which housed business-critical information, a new study says.

The study includes findings from surveys of senior IT decision-makers and end users worldwide, conducted by Vanson Bourne on behalf of Carnegie Mellon University and McAfee on the mobile security and consumerization of IT. About half of the 1,500 respondents across 14 countries say they are "very" or "extremely" reliant on mobile devices, and nearly seven in 10 organizations say they rely more on these devices now than 12 months ago.

The good news is that 95 percent of organizations have mobile security policies, but the bad news is that only one in three employees are "very aware" of these policies. And 63 percent of these laptops, tablets, external drives, smartphones, netbooks, and USBs are employed for personal use as well as business use. The breakdown: Seventy-two percent use personal laptops for work; 48 percent, personal smartphones; 46 percent, personal USBs; 33 percent, personal external hard drives; 19 percent, personal netbooks; and 10 percent, personal tablets.

Jamie Barnett, senior director of mobility product marketing for McAfee, says mobile devices will be the next frontier for malware and other attacks. The report did not go into any abuse of data on the lost or stolen devices.

"There's a ton of concern both from individual users and IT organizations about mobile devices being lost [or stolen] and what happens to the corporate data on them," Barnett says. Around 75 percent of the end users surveyed for the report say they are somewhat or very concerned about data loss due to theft, while some 54 percent of IT staffers were, she says.

Security policies for these devices are all over the map, Barnett says. "Policies are both set and enforced differently," she says. Among the typical policies are rules for what a device can be used for; how the company monitors the end user's communications on the device; device parameters for accessing the corporate network; and technical specifications, such as encryption and password complexity.

The report says more than one-third of the lost device cases came with a financial loss to the organization, and two-thirds of those companies have upped their device security in the wake of a lost or stolen one.

Around 50 percent of users store passwords, PIN numbers, or credit card information on their mobile devices, and less than half say they do weekly backups of data on their mobile devices.

"We're transitioning from the notion of a lifelong, long-term employee to more of a contractor type of employment: I'm an individual employee coming in with my 'kit' of stuff -- my personal database, my knowledge, my own technology, and my own [mobile] devices. Organizations need to welcome them in with their 'kit,' and then at the end of the relationship let those employees go with their kit intact, but also be able to claw back the corporate data that belongs to the organization."

The full report, "Mobility and Security: Dazzling Opportunities, Profound Challenges" is available here (PDF) for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13545
PUBLISHED: 2019-10-18
In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.
CVE-2019-13541
PUBLISHED: 2019-10-18
In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code.
CVE-2019-17367
PUBLISHED: 2019-10-18
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.
CVE-2019-17393
PUBLISHED: 2019-10-18
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and pa...
CVE-2019-17526
PUBLISHED: 2019-10-18
** DISPUTED ** An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an __import__('os').pop...