Showing posts with label BYOD. Show all posts
Showing posts with label BYOD. Show all posts

Tuesday, 16 August 2016

How to protect against mobile threats [Link - Information Age]

I was asked to provide an insight into mobile threats, and this is the article that appeared in Information Age: http://www.information-age.com/technology/security/123461862/how-protect-against-mobile-threats

==============

Cybercrime is on the rise, and with the increasing mobility of today’s workforce, it is not just PCs that need to be protected but a whole range of mobile devices.

Whether owned and managed by the company itself or brought in by employees, all mobile devices now need to be considered in businesses’ security plans.

This is especially true when implementing bring your own device (BYOD) policies, where companies can have less control over their employees’ phones.

With 72% of organisations across the financial services, technology, healthcare, government and education sectors now supporting BYOD for all or some employees, it has never been more crucial to ensure company data can remain secure while allowing easy access for employees.

So what are the threats to mobile devices that businesses face and how can they mitigate them?


Public networks


One of the biggest threats facing businesses – especially those with employees travelling abroad – is the use of free Wi-Fi networks to avoid having to use up mobile data allowances or pay costly roaming charges.

Public, password-free Wi-Fi lacks sufficient encryption, which provides hackers with an opportunity to access and steal almost all information on a user’s device.

The Wi-Fi Pineapple, for example, makes man-in-the-middle attacks easy. In this type of attack, a hacker sits in between the device and the Wi-Fi it is connected to in order to extract information from the device while the user remains unaware.

By educating employees of the dangers posed by using unsecured Wi-Fi, organisations can help to mitigate at least some of this threat.

Also, teaching employees to check if the website uses a HTTPS protocol, and ensuring that they have access to encrypted data storage are two more methods that help in keeping valuable corporate information safe from unsecured Wi-Fi.

Apps and channels


It is important to consider where employees are storing data, and what apps they are using on their device.

Apps present a risk to businesses as potentially confidential data is entrusted to a third party’s security protocols. For example, employees storing data from their mobile phone have to rely only on the strength of passwords for protection, rather than robust end-to-end encryption.

Using the appropriate channels for storing information, such as an encrypted VPN that is available to employees’ mobile devices, is one step towards protecting business assets.

While most app stores vet malicious apps, a user can still download apps from third-party stores that appear harmless on the surface but contain malware. Once downloaded, these have the potential to lock users out of their device, install malware, or carry out other activities, as illustrated with the recent case of fake Pokémon Go apps.

Companies that issue a fleet of managed devices can place restrictions on what apps can be downloaded. But with BYOD, employees are free to download what they want.

By creating a separate, corporate app store on the device through an enterprise mobility management (EMM) platform, IT departments can ensure only approved apps can access corporate information, while still allowing employees the freedom to download whatever they wish to use on their device.

Mobile malware


Just as with a PC or laptop, mobile devices are susceptible to malware attacks.

The recent proliferation of HummingBad malware on Android devices is a prime example of highly-sophisticated malware affecting mobile users.

By attaching itself to infected versions of trusted apps, it puts in place applications that generate fraudulent advertising revenue, collecting personal data to sell on along the way.

The key here is prevention rather than cure. There are many anti-virus, anti-malware and firewall products on the market which can be distributed across a whole network of corporate devices, ensuring they can protect against the latest threats.

For BYOD, EMM platforms can mitigate the risk and protect corporate data by creating a ‘wall’ around sensitive information to prevent infection from compromising data. Meanwhile, robust security policies can be put in place on an employee’s personal phone without invading their privacy or forcing too much control over a personal device to an employer.

None of these are 100% fool proof, however, so educating employees has to be a priority.

Part of this process should involve advising employees of the dangers hacking poses, the reasoning behind approved corporate channels for storing information, and clearly defining the role they need to play in securing their device.

IT departments need to be working with the HR team and heads of departments to create a corporate culture around security, and convey that the protection of company data is as much their responsibility as it is for IT professionals.

OS vulnerabilities


While Apple is known to have complete control over its iOS update system, the same is not true of Android, which has to rely on vendors to patch issues.

This was highlighted in the StageFright attack in 2015, which exploited weaknesses in the Android source code and allowed hackers to execute malicious code remotely.

Therefore, it is imperative that IT departments enforce a strong update policy. With a fleet of corporate devices, these can be managed centrally and updated on a regular basis – however, it is also necessary to advise employees using BYOD to ensure their personal device is up to date with the latest patches for the best protection.

There are as many solutions as there are threats in the corporate mobile landscape, but educating staff is the key to preventing the loss or infiltration of corporate data.

This needs to come from the top down. IT professionals need to be sitting round the same table as the C-suite when discussing mobile, and working closely with all departments of a business to create a ‘culture’ around mobile security.

Friday, 9 May 2014

BYOD Revisited

I wrote a piece on a pipedream called “Bring Your Own Device” back in November 2011 (http://blog.andytang.com/2011/11/embracing-bring-your-own-device-byod.html)

Like with all new concepts, I believe my attitude has changed and mellowed as I see it being used in the real world.  I still have a number of conversations about BYOD or CYOD (Choose Your Own Device), but more around people still being unsure what to do.

I remember being asked by an ex-boss, “What BYOD solutions do we sell?” to I replied “None… We sell solutions to support BYOD policies, not BYOD Solutions!”  If we consider this for a moment, your policy could be to not allow personal devices, it could be to only to allow personal devices on the guest wireless, or it could be full access to the corporate network where the administrators can remote wipe your device.  These are different policies, and would require different types of solutions to enforce these policies.

Previously I talked about network infrastructure, endpoint security, network access, compliance and device compatibility, I don’t feel they are as important any more.  The issues I believe we need to focus on are as follows.

Wireless Security
My stance has changed from whether the wireless network cope, to whether the wireless network be secure enough?  Can the organisation deal with rouge access points, denial of service attacks, or unauthorised devices connecting to your network?  Most people can’t say this about their wireless network, which in my opinion is not good enough!  There are Wireless Intrusion Prevention Systems out there that can offer wireless access, as well as act as an overlay to your existing wireless network.

Enterprise Mobility Management (EMM)
There was a time when the concern was how we can wipe a device if it’s lost or if the employee leaves.  This led to an employee pushback around it being their device and not the company’s.  This is where MDM (Mobile Device Management) was good enough, it started to get coupled with MAM (Mobile Application Management) and more recently MCM (Mobile Content Management).  This then provides comprehensive device and data management to the mobile devices.

Protecting the Data
I only care about the data!  As an organisation, should I worry if my employees loses their device, if the wireless connection they are on is insecure, what type of device they are on, or whether they run any security on their device?  The answer should be no…

My only concern as an organisation is, is my data safe? We should be protecting the data.

Find out which data is critical to the organisation and protect it.  There are many DLP (data leakage prevention) solutions, but these need to be coupled with means with which the data can leave your organisation.  Primarily, organisations will look at the web and email vectors, before considering that ActiveSync (the protocol most mobile devices use to collect their email from corporate email servers) is also a vector with which data can leave.

Conclusion
If you feel you have to protect the device, then look at a full EMM solution and not just an MDM.  If you have to provide wireless, please secure with a WIPS.  Although the key in my opinion is to protect your data!  

Companies rarely make the news for losing a device, but they do if they lose data!

Wednesday, 18 April 2012

iOS and Android in the workplace (aka Replacing your computer with an iPad/Android Tablet?)

With iOS and Android becoming more popular in the home environment, I am often asked how these devices can be used as the endpoint to connect to a work network.  I would like to separate the use of these devices as a work device, rather using them as an access point for the occasional remote access session.

Irrespective of whether the tablet or mobile is a company or personal device, the issue with connecting it to your network is software support, so we have to look at what applications are required in the workplace.  With email, most mobile and tablet devices will support Exchange, and most of these devices will have the ability to create, read and edit Microsoft Office documents.  There may be some issues with legacy applications, or Windows only applications, which would render the device useless for those applications.

I’ve read in some places, where the solution is the replace the applications with something that will work on these mobile devices, or on other computer operating systems.   This seems a little bit extreme, especially in the current economic climate, where IT budgets are being cut and hardware refresh rates being increased from three years to up to five years.  Embracing BYOD (Bring Your Own Device) will also bring the same challenges, as the organisation may save hardware costs in not having to purchase and maintain devices, but will have to alter the backend infrastructure to support these new devices.

I’ve always liked the concept of VDI (Virtual Desktop Infrastructure) but in the past, it has been both complicated and expensive.  There are now solutions which can give you a virtual desktop for less than the cost of a new PC.  By manipulating budgets, it would be possible to deploy a VDI solution, instead of carrying out a hardware refresh of the desktop/laptop infrastructure.  The VDI solution would be able to create a Windows desktop environment that can run on any endpoint that supports RDP (Remote Desktop Protocol).  This would enable the old hardware, the mobile devices, the tablets, the BYOD equipment and home devices to connect to the VDI solution using RDP.  This solution can run on the network, and allow these devices to connect assuming they are on the network. 

The next challenge would be allowing these devices to connect to the VDI solution when they are away from the office.  If there is an SSL-VPN solution in place, you may be out of luck!  Most SSL-VPN solutions allow you to connect to your office, via an internet browser.  By installing some software components, via ActiveX or Java, it will give your Windows and Apple (and sometimes Linux) computers the ability to connect to the network and allow your applications to run remotely.  The issue comes as most of these solution providers have not written software components for the mobile and tablet devices to connect natively to the network.  Although web applications will work on these devices, any application requiring more than a web browser will not run.

The way to allow these devices onto the network will be to use a “traditional” VPN, utilising PPTP, L2TP or IPSEC.  This type of connectivity is normally configured on a firewall or VPN concentrator and once configured with the appropriated settings and authentication (we will have to think about security); these devices will connect and can interact with your network as if they were a computer on the network.

Once connected, the VDI solution will be available to the device, and then allow your Windows desktop to run, even though the device is not in the office and may not be running a traditional operating system!


Wednesday, 2 November 2011

Embracing the “Bring Your Own Device” (BYOD) culture?


Quite a few people I speak to tell me that BYOD is next “big thing”, and we need to embrace it as it will be a way of life for all IT environments.  The argument is that it will reduce capital expenditure (CAPEX) and it makes for happier employees by giving them choice, allowing them to use a variety of devices, such as laptops and tablets, as well as a variety of operating systems, including Windows, Apple and Android.  Much as I understand these statements, I don’t necessarily agree with them

Network Infrastructure
The common assumption will be that a majority of your machines are desktops, but with a BYOD policy, a majority of the devices will be laptops.  One of the major technologies driven from a domestic to commercial environments is wireless, so the expectation will be the requirement for wireless at work with their new BYOD.

Anyone who has felt the pain with a badly configured or deployed wireless solution will know there will be a struggle with either getting a large number of devices on the same wireless network, bandwidth and throughput issues, as well as struggling with coverage in a large or distributed building.

Security must be considered, ensuring the wireless network has the appropriate level of encryption and access.

This can be solved with solutions such as Xirrus, which uses innovative ways to solve the capacity, coverage and throughput issues, while coupling this with coverage guarantee.

Endpoint Security
I’ve read a number of comments from the big AV companies, suggesting that AV alone will not secure your system from malware.  It should be a layered approach, with a number of solutions working in conjunction to tackle all the possible threat vectors.

As minimum anti-virus software should be on the device, but how do you ensure this on a BYOD.  There are several AV solutions that can be managed centrally, but a number of employees will not agree to this as it is “their device” and don’t want the company controlling it.  The company policy may stipulate that anti-virus software must be installed, updated and running, but how do you check?

Network access
Having implemented a wireless network, a consideration is to ensure that only the trusted devices can access the network.  A Network Access Control (NAC) solution will be required to ensure that the devices can be checked, and then either quarantined or allowed access. 

These checks may be the type of device, the software installed, the software running, or the MAC address, then allowing the appropriate access, be it full access to the network, or only internet access to allow the device to update the anti-virus software.

IT Support
What happens to the IT Support function within your organisation with a BYOD policy?  Do they now have to support a vast array of devices?  Do you get rid of them and move the onus of the support function to the user and their chosen solution provider?  Who will ensure that the applications used by the organisation will function on the BYODs?

The cost saving efficiencies from the BYOD policy may be lost several fold, if the IT Support team now have to support devices they are not familiar with.  Although getting rid of the team will not help as they are the team who have ensured that the company applications work on the devices.

Compliancy
We have read in the news about organisations losing personal data and run the risk of up to a £500,000 fine from the Information Commissioners’ Office (ICO).  The onus is on the organisation to prove either the data was not on the device, that the data was wiped or that the device is encrypted. 

As the company is responsible for the data, the “it’s my device” attitude will not work with ensuring information security.  The viable options will be to ensure the data is not stored on the device, effectively making the device a “dumb terminal” or to ensure the device is encrypted.

Device Compatibility
What devices will your users choose?  It shouldn’t matter as long as it enables them to do their job.  So the device will probably be a Windows laptop, an Apple laptop, a Linux laptop, a Windows tablet, an Apple tablet or an Android tablet.

The issue you will have is whether the operating system or form factor selected by your users is compatible with the applications run by your organisation.  Although there has is much talk about cloud solutions and web-based applications, there will still be a number of applications that will only work with Windows devices.

The only way to make some of these Window solutions work, is to either use Terminal/Citrix server or VDI solution.  With these solutions the application will run on the server, and the device will have a view to either the application or a full operating system.  Something to bear in mind is that these solutions will require client software to be installed, so ensure that the solution you use is supported by the devices that your users are using.

Conclusion
The initial thoughts about reducing CAPEX are quickly removed, when considerations around the network and security are taken into account.  I don’t believe that BYOD is a pipedream, but there must be a level of understanding and planning before embarking on a BYOD policy.