IT decision-makers’ top concern revealed‌
We recently polled a number of IT decisionmakers to get a better understanding of what’s sitting at the top of their IT security agenda. The results of our survey will not come as a surprise to many, with third-party file sharing services being seen as the biggest threat to security*. One of the reasons that third-party file sharing
We wanted to explore how much of this concern is
solutions are becoming increasingly popular is due
anxiety and how much is legitimate. Should the IT
to the rapid adoption of mobile devices both at
department be active in stopping the use of these
home and, increasingly, at work. The majority of
services, or should it embrace the services and do
solutions are free and easy to set up. The plus for
more to ensure they’re used safely?
users (and main concern for the IT department) is that they bypass many of the barriers that protect a business’s networks, data and files. *Based on a survey from the August edition of the Smart Talk newsletter.
Scary story or real threat? Are third-party file sharing services an actual risk to IT security? The short answer is yes. We’ve all read the recent news stories about celebrity selfies, and government and corporate data loss, so we know these platforms can be compromised. But are they any less secure than your own business servers, hard drives or memory sticks? Recent statistics suggest that the answer is… probably not. 61% of cyber-attacks last year were targeted though email, with 36% a direct result of phishing scams. Even when looking at data loss, it may surprise many to know that 38% are still a result of hardware theft, with a further 13% attributed to corporate espionage*. There is also a compelling argument to suggest that the organisations behind these services have infinitely tighter security and a much larger resource than any (if not all) of the individuals and businesses who use them. This argument does ignore one vital factor though – the user.
61% of cyber-attacks last year were targeted though email, with 36% a direct result of phishing scams.
80% of the workforce now uses a mobile device. And an estimated 65% of organisations are yet to implement a BYOD policy**.
Here to stay? File sharing services are almost certainly here to stay. The main players in the market already store millions of files every minute, with the total number of users estimated to be in the high hundreds of millions. The service providers are usually large, high-profile technology organisations, with robust physical and virtual security to match. Taking this into account, the likelihood is that the services that are gaining momentum will continue to focus on service security and availability, making them among the most secure on the market. What’s more, your colleagues are probably already using them – either for personal use and/or for business use. 80% of the workforce now uses a mobile device. And, with an estimated 65% of organisations yet to implement a BYOD policy**, the focus now is on how businesses manage this use rather than on whether they can stop it.
* http://cloudtweaks.com/2014/05/cloud-infographic-corporate-security-stats/ ** http://www.securedgenetworks.com/secure-edge-networks-blog/bid/87987/10-Surprising-BYOD-Stats-You-Need-to-See)
User awareness Human error, bad practice and personal ignorance over security threats lead to many of the threats faced by the IT infrastructure. In fact, human error came a close second in the IT decision-maker poll. A business can help to reduce these issues by stating what best practice is and what each employer is responsible for. Most of this best practice will be common sense and widely observed by most users – strong passwords, avoiding files from an unknown
source, virus scans for every download. But it’s a good idea to provide a clear set of principles that can be agreed by everyone. Therefore, having these practices written into business policy can protect the business and ensure that all users are fully aware of their responsibilities and how they are expected to behave when it comes to file access and sharing.
Multi-level security There’s no such thing as partial security, so we designed Lumia with Windows Phone devices with business security top of mind. We believe that it makes sense for businesses that operate within a Windows environment to use mobile devices that also run on a Windows platform, as this makes the estate more secure, consistent and manageable. Windows Phone 8.1 shares more than 80% of its APIs with the Windows Operating System, which means that making and deploying apps on the Windows ecosystem has never been easier, and security considerations are reduced. Additional Windows Phone 8.1 security features range from a bullet-proof secure boot process and code signing, to full device encryption and unique Information Rights Management capability. IT can also force S/MiME policies to comply with company policy, all without installing additional software to enable it.
Reviewing security One of the biggest fears associated with thirdparty file sharing is to do with a loss of control. The file sharing solutions mean that files can be transferred outside of a business’s safety net and holes can be punctured in its existing defences. On the surface, this sounds like one big ticking time bomb. However, it is, in fact, a series of smaller (yet still important) challenges for IT security.
Encryption Devices beyond the control of a business (such as mobile devices and home PCs or laptops) are an obvious challenge because they can be lost, stolen or compromised without a business even being aware of the breach. One option is to put restrictions on files or folders so they can be controlled on a more granular level. This can be achieved with Information Rights Management solutions, which use encryption and keys or passwords to protect file access and sharing.
Digital policies While education does undoubtedly provide more of a deterrent, it relies on people doing – or not doing – things that could compromise a business’s network or files. There are ways that policies can be enforced on devices so that, for example, setting strong passwords, limiting a device’s ability to download or install certain file types, or controlling the types of applications available to them, are managed and controlled centrally by the IT department.
Device access One option is to add a level of control to devices so that the service which is perceivably punching a hole through a business’ defences is restricted or managed. A device with file sharing could be seen as creating a virtual bridge into a business’s internal network that bypasses its existing defences. In this case, ignorance is not bliss. An internal review of services being used and how they allow files to be accessed and shared may help you make firm decisions about their use. Vetting each service – including their security and file management capabilities – means you are aware of the potential risks to your networks and data, so you can gate them or add additional security procedures.
Device management Another key requirement to help prevent the loss of files, data and gateways on mobile devices is Mobile Device Management (MDM). MDM enables organisations to centrally control access to files by locking down or wiping devices (or areas of devices) that have been lost, stolen or compromised, restricting the apps and configuration settings to help maintain security.
Bringing it all together Third-party file sharing is a real concern for IT decision-makers. But the reality is that these services are increasing in popularity and being used by people for personal and business use, both with and without the awareness of the IT department. In summary, in order to control the threat, businesses need to approach security on a number of different levels: • Users need to be better educated of the potential risks and consequences – both business and personal – when using these sites. • This should be written into business policy and deployed as digital policies, so that everyone is clear on their responsibilities when it comes to keeping networks, files and data secure.
• Finally, security must be periodically reviewed to ensure it can sit alongside these services and continue to protect your organisation in line with evolving technologies, solutions and threats. For remote workers in particular, this means safeguarding devices, and the information and gateways that they hold.
For more information, a detailed Windows Phone 8.1 Security Overview is available to download.
© 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows and the Windows logo are trademarks of the Microsoft group of companies.