Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

5/24/2011
05:28 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Half Of Lost Or Stolen Mobile Devices Store Sensitive Company Data

Carnegie Mellon, McAfee report finds that one-third of lost mobile device cases resulted in financial loss to the organization

Mobile devices are coming to work in droves, and they're being lost or stolen en masse, too: Four in 10 organizations say some of their mobile devices have been lost or stolen, half of which housed business-critical information, a new study says.

The study includes findings from surveys of senior IT decision-makers and end users worldwide, conducted by Vanson Bourne on behalf of Carnegie Mellon University and McAfee on the mobile security and consumerization of IT. About half of the 1,500 respondents across 14 countries say they are "very" or "extremely" reliant on mobile devices, and nearly seven in 10 organizations say they rely more on these devices now than 12 months ago.

The good news is that 95 percent of organizations have mobile security policies, but the bad news is that only one in three employees are "very aware" of these policies. And 63 percent of these laptops, tablets, external drives, smartphones, netbooks, and USBs are employed for personal use as well as business use. The breakdown: Seventy-two percent use personal laptops for work; 48 percent, personal smartphones; 46 percent, personal USBs; 33 percent, personal external hard drives; 19 percent, personal netbooks; and 10 percent, personal tablets.

Jamie Barnett, senior director of mobility product marketing for McAfee, says mobile devices will be the next frontier for malware and other attacks. The report did not go into any abuse of data on the lost or stolen devices.

"There's a ton of concern both from individual users and IT organizations about mobile devices being lost [or stolen] and what happens to the corporate data on them," Barnett says. Around 75 percent of the end users surveyed for the report say they are somewhat or very concerned about data loss due to theft, while some 54 percent of IT staffers were, she says.

Security policies for these devices are all over the map, Barnett says. "Policies are both set and enforced differently," she says. Among the typical policies are rules for what a device can be used for; how the company monitors the end user's communications on the device; device parameters for accessing the corporate network; and technical specifications, such as encryption and password complexity.

The report says more than one-third of the lost device cases came with a financial loss to the organization, and two-thirds of those companies have upped their device security in the wake of a lost or stolen one.

Around 50 percent of users store passwords, PIN numbers, or credit card information on their mobile devices, and less than half say they do weekly backups of data on their mobile devices.

"We're transitioning from the notion of a lifelong, long-term employee to more of a contractor type of employment: I'm an individual employee coming in with my 'kit' of stuff -- my personal database, my knowledge, my own technology, and my own [mobile] devices. Organizations need to welcome them in with their 'kit,' and then at the end of the relationship let those employees go with their kit intact, but also be able to claw back the corporate data that belongs to the organization."

The full report, "Mobility and Security: Dazzling Opportunities, Profound Challenges" is available here (PDF) for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29450
PUBLISHED: 2021-04-15
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It...
CVE-2021-21405
PUBLISHED: 2021-04-15
Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This method accepts signatures in 2 forms: "serialized", and "compressed", meaning that BLS signatures can be provided as either of 2 un...
CVE-2021-29430
PUBLISHED: 2021-04-15
Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service. Sydent also does not limit response size for requests it mak...
CVE-2021-29431
PUBLISHED: 2021-04-15
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform a...
CVE-2021-29432
PUBLISHED: 2021-04-15
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.