Showing posts with label Bring your own Device. Show all posts
Showing posts with label Bring your own Device. Show all posts

Thursday, February 21, 2013

TEN things you can do to boost your BYOD security

To everything there is a season and this is the season of BYOD. Bring your own device isn't a particularly new phenomenon but it certainly is hotter now than ever before.
tablets-workers-byod


People have always smuggled in their own laptops and mobile devices into corporate networks. There's always a sympathetic IT guy around who will help the wayward BYOD renegade get setup to use corporate assets. But these days, it's a thing. You're now in the minority if you don't bring your own device into your corporate network. Some companies post FAQs on how to setup your chosen device to download email, connect to the VPN and to share documents with other users.

The one thing that's lacking in all this BYOD goodness is security. Security breaches aren't as rare as they used to be. The spread of malware has made sure that absolutely no one is immune and no platform is safe from malware hell. Windows users know this all too well. Android users are finding out quickly what it means to be paranoid about security. Apple users, once isolated from widespread malware attacks are now also on the receiving end of the security badness that affects us all.

If you think you're safe, you're wrong. If you think that you haven't been compromised in some way, you're probably also wrong. Security problems plague companies of all sizes and configurations

But you aren't helpless. Far from it. There are things you can do to minimize your attack surface--other than unplugging or going analog, that is. In fact, there are ten things that you can do to boost your BYOD security. This list of ten is in no particular order, except for the first one, which should be first on your list
  1. Hire a security consultant who has mobile device security experience - 92% of all security breaches are discovered by third parties. A good security consultant will not only audit your security but he will also find any compromises that you may know nothing about.
  2. Setup MDM/MAM software to manage mobile devices and security - Mobile device management and mobile application management software is very sophisticated and can manage your security in very fine detail. Since there are so many different MDM/MAM vendors, get some recommendations from other companies and security consultants. Watch for a post on selecting MDM/MAM software coming soon.
  3. Require VPN connectivity for all devices - Requiring a secure connection into your network is standard practice. If it isn't in your company, make it so. Your security consultant should be able to guide you in selecting the VPN hardware and software that's right for you.
  4. Require device passwords - In what should be a "duh" moment, you'd be surprised how many people don't use basic password protection for their devices. If you don't know how to setup a device password, ask a teenager, they all know how to do it.
  5. Require device encryption - Before users store or access corporate data on their devices, they must use encryption software. Generally speaking, you can choose between data or device encryption. Data encryption means that any corporate data that you download to your device is stored encrypted. If you encrypt your device's storage, then anything that lands on the device will be encrypted. The difference is at the app level or at the device level. For example, you can store an encrypted file on an unencrypted filesystem or store a file (encrypted or unencrypted) on an encrypted filesystem. Either method has its strengths and weaknesses.
  6. Require anti-malware software - This is another almost obvious recommendation. You wouldn't setup a new laptop without antivirus software and you shouldn't setup a new mobile device without some sort of antimalware software. In fact, your MDM/MAM suite should check for antimalware software and either deny access for those devices without it or make a mandatory installation of corporate-approved antimalware software.
  7. Implement ACLs and Firewalls - Access Control Lists and Firewalls might sound complex but they aren't. Again, a good security consultant can get you setup or train your staff to lock down access to your valuable data and files.
  8. Audit data files - Your most valuable files should be audited. To audit a file means that any access to the file is logged. This includes automated access by service accounts or other processes such as SFTP.
  9. Setup alerts on logfiles - Related to #8. You should setup alerts on audit logs, system logs and event logs to notify security of any unauthorized or suspicious access attempts on files, shares or accounts. Often hackers will remove logfiles in an attempt to cover their activities. Checking for the existence of the logfile will alert you to this type of behavior as well.
  10. Limit app downloads to a single trusted site or internal app store - Legitimate app stores have some sort of rigorous approval process for apps. Part of the process is checking for malware. Some sites don't check or check as thoroughly as they should. Your best defense is to whitelist approved app stores for your users or to create your own internal app store from which your corporate users may select apps to use.
97% of all security breaches are preventable by employing basic (passwords, antimalware software) or intermediate (Firewalls, VPNs) practices. There's no excuse for allowing any low-hanging fruit to exist in your network. Regular security sweeps and audits will provide you with feedback on your status. Remember that the best security defense is that third party security consultant.

BYOD shouldn't be something to be afraid of. It should be something that's done to enhance a work environment. But don't let security issues destroy a good thing like BYOD. Do your part by educating your users and getting a good security consultant to assist you.

What do you think? Do you have other suggestions to help with BYOD security? Talk back and let TURNkey know.

Monday, February 18, 2013

BYOD?? What does that mean?

Is your staff bringing their own devices and gadgets to the workplace? There are pros and cons that you need to know before you decide to adopt this practice for your business.


You may have noticed more and more of your employees or colleagues bringing their own computing devices to work—be it their mobile phone, tablet, or laptop. Or perhaps in your company or in other companies you may have seen, they have let people decide which device they prefer because they are used to it at home. You may not realize it, but this is all part of a large trend called the "consumeriztaion of IT", in which the influence of consumer technology is being increasingly felt in the workplace. With the wide availability of cheap but powerful mobile devices and online services, a growing number of people are being exposed to the latest technology at home first—adopting them at a rate faster than most businesses are able to manage. This flips on its head the old paradigm in which traditionally new technologies would be rolled out to businesses first, before they would find their way to consumers.

This trend, plus the increasing sophistication of young workers today and their frustration with the tools available to them at the office, is pushing some companies to adopt a "bring your own device" or BYOD policy at work. They are not alone. According to research by technology group Garner,  end users, not the IT department, will soon be responsible for 50 percent of business IT procurement decisions—ultimately bringing and running their own systems on company networks. Meanwhile, according to management consultants Accenture, around one-third of today's younger generation of workers (a group called "millenials") not only wants to use the computer of their choice at work, but also wants control of the applications they use too.

The benefits companies cite to adopting a BYOD policy are many, among them:
  • Savings on capital expenses and training costs in using company equipment—compensating employees instead via other means such as flexible work hours, subsidized purchases, insurance, and other benefits.
  • Less management headache—effectively letting employees decide what to use releases the company from some overhead and management responsibilities.
  • Improved employee satisfaction—by giving employees the freedom to use devices and applications that they prefer.
However, before you consider letting employees bring their own personal technology to the work place, be aware that there are also disadvantages, and sometimes very real dangers in doing so. These include:
  • Non-standardization of hardware, operating systems, and applications. If your business operations require that some equipment is integrated with others, then BYOD can in the long run actually increase IT management costs and decrease efficiency.
  • Exposing your network to malware or security vulnerabilities and breaches. When your employees bring their own devices to work, you lose important control over their security. Consumer devices often don't employ comparable bullet-proof security technologies mandated by businesses.
  • Leakage of confidential or proprietary information. Employees will naturally do what they want with the data on their devices, even if it doesn't belong to them, or it's against company policies. Employees can also lose precious company data when they misplace or damage their personal devices.
  • Lower economies of scale in procurement. Essentially because everyone is buying devices on their own, you miss out on the chance to consolidate purchases and lower purchase costs for everybody.
Have you adopted a BYOD policy at work? Thinking about it? Worried about this trend? If you need to understand BYOD better so you can define a policy for your staff, contact us at TURNkey IT and see how we can help.