Showing posts with label MDM. Show all posts
Showing posts with label MDM. Show all posts

Saturday, 16 July 2016

Euro 2016: A lesson in BYOD security best practice [Link - ITProPortal]

I was asked to write some thoughts around the security during Euro 2016 for ITProPortal: http://www.itproportal.com/2016/07/16/euro-2016-a-lesson-in-byod-security-best-practice/

==================================

One of the stories away from the pitch at this year’s Euro 2016 event was the significant spike in cybercrime on mobile devices.

Attending football fans, trying to keep on top of work or attempting to access tournament information, became victims to cyberthreats as hackers took advantage of insecure public Wi-Fi networks and applications.

Reports suggest that the host country was targeted in a highly calculated way by hackers during the event, with 72 per cent of malicious websites and 41 per cent of exposed passwords were detected on smartphones in France alone.

The UEFA EURO 2016 Fan Guide App, one of the official UEFA mobile applications, was a prime target for hackers during Euro 2016, having been being downloaded onto more than five million devices.

Designed to provide practical tourist information for fans travelling to France for the tournament, the app leaked user data including usernames, addresses, phone numbers, and passwords due to an insecure connection.

The BYOD threat is real

The scale of the attack during the event highlights just how strong the threat is for businesses, especially for companies operating BYOD policies, as employees are free to access malicious websites, fake apps and connect to unsecured Wi-Fi on the same device they store corporate data.

An additional report also suggests business travellers are more likely to be mugged of valuable private and corporate data than of their travel money. The report found that 59 per cent of staff in senior roles claim to log on as quickly as possible upon arrival abroad, while 48 per cent of senior managers and more than 43 per cent of mid-level managers use unsecure public access Wi-Fi networks to connect their work devices when abroad.

So how can businesses protect themselves against mobile threats and prevent mobile hardware and apps from leaking corporate data, and what are best practices around BYOD security?

Mobile management

With company owned mobile pools now rapidly becoming out of date and workplace bring your own device (BYOD) policies steadily growing, controlling what an employee does on their device has become far more difficult and complex.

Enterprise Mobility Management (EMM) platforms have become crucial in protecting corporate data. Apps and documents can operate separately from the rest of the device, allowing employers to create a ‘wall’ around sensitive information to prevent infection from compromising data.

EMM also allows for robust security policies to be put in place on an employee’s personal phone without invading privacy or forcing too much control of a personal device to an employer.

Right apps, right channels

It is also important to consider where employees are storing data. Some cloud-based storage applications can present a risk as the data is often entrusted to a third party. This means businesses have to rely on the strength of an employee’s password for protection.

Using the appropriate channels for storing information, such as an encrypted VPN, and making these available to employees’ mobile devices is another step towards protecting business assets. This ensures all information is properly encrypted through storage managed by the company itself, rather than entrusted to a separate party.

Another consideration for most businesses is how to prevent staff downloading apps that can leak data. Companies that issue a fleet of managed devices can place restrictions on what apps can be downloaded, but with BYOD, employees are free to download what they want.

By creating a separate corporate app store on the device, IT departments can then ensure that only approved apps can be used to access corporate information, while still allowing employees the freedom to download whatever they wish to use on their device.

Public dangers

One of the biggest threats during the Euro 2016 tournament was the use of free Wi-Fi facilities.

Public, password-free Wi-Fi is a particular threat to both individuals and businesses due to the lack of encryption which allows hackers to access almost all information on a user’s device.

The Wi-Fi Pineapple, for example, makes man-in-the-middle attacks easy. In this type of attack, a hacker sits in between the device and the Wi-Fi to which it is connected in order to extract information from the device.

These type of attacks are especially dangerous for travelling football fans and business people alike, as users often try to avoid having to pay expensive data roaming charges while in foreign countries.

By educating employees of the dangers posed by using unsecured Wi-Fi and unauthorised applications, organisations can help to mitigate at least some of the potential threat.

Part of this process should involve advising employees of the dangers hacking poses, the reasoning behind approved corporate channels for storing information, and clearly defining the role they need to play in securing their device.

IT departments need to be working with the HR team and heads of departments to create a corporate culture around security and convey that the protection of company data is as much their responsibility as it is for IT professionals.


Thursday, 7 July 2016

Euro 2016 breaches [Link - Professional Security Magazine Online]

I was asked some questions around around breaches due to Euro 2016 mobile applications by Professional Security Magazine Online: http://www.professionalsecurity.co.uk/news/commercial-security/euro-2016-breaches/ 

==================================

During the 2016 UEFA European Championships, the SmartWire Labs Team at Wandera has been analysing the mobile data traffic patterns across its enterprise customers in the European countries that make up this year’s tournament. Wandera said that during the research period, the number of data leaks observed increased. The IT firm predicted this number will continue to rise as the tournament goes on as a result of more people travelling across Europe and using unfamiliar apps and websites to access match information. The company suggested that data leaks will peak in late June towards the end of Euro 2016, before going back to normal levels in late July.
The firm summed up that the increased data usage for the beginning of Euro 2016 was no surprise to anyone. The risks associated with this increase in traffic have implications. With more people travelling across Europe, using unfamiliar websites and apps, as well as the discovery that the official UEFA app is leaking data could all lead to serious security breaches with thousands of fans’ data being put at risk, according to the firm.

Comments
Andrew Tang, Service Director, Security at MTI Technology, spoke of two ways organisations can protect corporate data. The first is through a fleet of corporate devices, which can control what apps are installed and which websites can be visited. However, with fleets of devices becoming old-fashioned and bring your own device (BYOD) policies ever more common in the workplace, controlling what an employee uses their device for, has become more complex. Enterprise Mobility Management (EMM) platforms are key to protecting corporate data. By separating company information from the rest of the phone; including apps, emails and documents; employers can ensure that a ‘wall’ is created around sensitive information and as a result, can prevent infection from compromising data.

Can organisations prevent downloading of apps that leak data?
With a fleet of managed devices, this is less of a problem as companies can place restrictions on what apps can be downloaded. With BYOD however, employees can be free to download what they want to. Through a EMM platform, businesses can create a corporate app store that restricts what employees can use through the platform. This allows IT departments to restrict access to certain apps on Google Play or the Apple Store, ensuring that only approved apps are used to access corporate information, while still allowing employees are free to download whatever they wish to use on their device.

What are the best practices for protecting infrastructure during major sports events?
Public Wi-Fi is a particular threat when it comes to malware penetrating a mobile device. Open, password free Wi-Fi connections are not encrypted, which means that they are easy targets for hackers. For example, the WiFi Pineapple makes man-in-the-middle attacks easy. In this type of attack, a hacker sits in between the device and the Wi-Fi it is connected to in order take information away from the device. This is especially dangerous in foreign countries as some users try to make the most of avoiding having to pay roaming charges through free Wi-Fi. Education is key here. By informing employees of the dangers free and open Wi-Fi connections can pose, organisations can hopefully mitigate some of the threat. However, this is far from foolproof.

Friday, 9 May 2014

BYOD Revisited

I wrote a piece on a pipedream called “Bring Your Own Device” back in November 2011 (http://blog.andytang.com/2011/11/embracing-bring-your-own-device-byod.html)

Like with all new concepts, I believe my attitude has changed and mellowed as I see it being used in the real world.  I still have a number of conversations about BYOD or CYOD (Choose Your Own Device), but more around people still being unsure what to do.

I remember being asked by an ex-boss, “What BYOD solutions do we sell?” to I replied “None… We sell solutions to support BYOD policies, not BYOD Solutions!”  If we consider this for a moment, your policy could be to not allow personal devices, it could be to only to allow personal devices on the guest wireless, or it could be full access to the corporate network where the administrators can remote wipe your device.  These are different policies, and would require different types of solutions to enforce these policies.

Previously I talked about network infrastructure, endpoint security, network access, compliance and device compatibility, I don’t feel they are as important any more.  The issues I believe we need to focus on are as follows.

Wireless Security
My stance has changed from whether the wireless network cope, to whether the wireless network be secure enough?  Can the organisation deal with rouge access points, denial of service attacks, or unauthorised devices connecting to your network?  Most people can’t say this about their wireless network, which in my opinion is not good enough!  There are Wireless Intrusion Prevention Systems out there that can offer wireless access, as well as act as an overlay to your existing wireless network.

Enterprise Mobility Management (EMM)
There was a time when the concern was how we can wipe a device if it’s lost or if the employee leaves.  This led to an employee pushback around it being their device and not the company’s.  This is where MDM (Mobile Device Management) was good enough, it started to get coupled with MAM (Mobile Application Management) and more recently MCM (Mobile Content Management).  This then provides comprehensive device and data management to the mobile devices.

Protecting the Data
I only care about the data!  As an organisation, should I worry if my employees loses their device, if the wireless connection they are on is insecure, what type of device they are on, or whether they run any security on their device?  The answer should be no…

My only concern as an organisation is, is my data safe? We should be protecting the data.

Find out which data is critical to the organisation and protect it.  There are many DLP (data leakage prevention) solutions, but these need to be coupled with means with which the data can leave your organisation.  Primarily, organisations will look at the web and email vectors, before considering that ActiveSync (the protocol most mobile devices use to collect their email from corporate email servers) is also a vector with which data can leave.

Conclusion
If you feel you have to protect the device, then look at a full EMM solution and not just an MDM.  If you have to provide wireless, please secure with a WIPS.  Although the key in my opinion is to protect your data!  

Companies rarely make the news for losing a device, but they do if they lose data!