Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

1/13/2014
11:00 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Feds Failing To Secure Their Mobile Devices

New study finds one-third of government workers use public WiFi and one-fourth don't password-protect the devices

The federal government may have specific policies for security, but many of its users aren't adopting secure mobile practices and behaviors, according to a new study by the Mobile Work Exchange.

The public-private partnership's study, which was commissioned by Cisco Systems, is based on data gathered from the Mobile Work Exchange's self-assessment tool for organizations to measure the security of their mobile workforce. The report focused on tablets, smartphones, and laptops, and found that 90 percent of government users who were assessed by the tool use at least one of those devices for work.

More than 40 percent of government users are putting their agencies and devices at risk, according to the report, which encompassed 155 users and 30 different government agencies, mostly civilian. On the flip side, 86 percent lock their computers when they leave their desks and 78 percent store files in a secure place.

More than 30 percent use public wireless networks, the study found, 52 percent don't use multifactor authentication or encrypt their data, and 25 percent don't use passwords for their mobile devices. Those that do are employing weak passwords, however: One in three create "easy" passwords, such as "1234" or "password." Around 15 percent of the government users say they have downloaded a personal app on their work mobile devices, and 10 percent say they have opened either an email or text from a sender they didn't know.

"The 2014 Mobilometer Tracker study shows that 6 percent of government employees who use a mobile device for work say they have lost or misplaced their phones. In the average federal agency, that’s more than 3,500 chances for a security breach. Organizations need to take the necessary steps to protect their data and minimize the risk of data loss," says Larry Payne, Cisco vice president for its U.S. Federal group.

Close to 60 percent of feds don't secure their agencies' data properly, and more than one in four are not getting any security training for mobile. About half say their agencies have official mobile device programs. The good news: Government users scored better than users in the private sector, where 60 percent of users say they have downloaded a nonwork-related app on the mobile devices they use for work. And more than half of agencies require users to register their mobile devices, while only 21 percent of private industry organizations do so.

“While the government is significantly safer than its counterparts, there is still much work to be done,” says Cindy Auten, general manager of Mobile Work Exchange. “Ensuring policies are being enforced is the best way to secure critical government data. Closing this gap equips government employees with the knowledge to thwart potential security breaches.”

The full report is available here for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Breaches Are Inevitable, So Embrace the Chaos
Ariel Zeitlin, Chief Technology Officer & Co-Founder, Guardicore,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14345
PUBLISHED: 2019-11-15
TemaTres 3.0 allows remote unprivileged users to create an administrator account
CVE-2019-14343
PUBLISHED: 2019-11-15
TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.
CVE-2019-14869
PUBLISHED: 2019-11-15
A flaw was found in all versions of ghostscript 9.x before 9.28, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could esc...
CVE-2019-18987
PUBLISHED: 2019-11-15
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.
CVE-2019-18986
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.