CIOs See Smartphones As Data Breach Time Bomb

Nearly half of employees can use their personal devices to connect to enterprise networks despite security risks, finds Ovum study.

Strategic Security Survey: Global Threat, Local Pain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full slideshow)

Eight out of 10 CIOs think that using smartphones in the workplace increases the business's vulnerability to attack, and rank data breaches as their top related security concern. Yet half of organizations fail to authenticate their employees' mobile devices, among other basic security measures.


More Hardware Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Those finding come from a report released Wednesday conducted by market researcher Ovum together with the European Association for e-Identity and Security (EEMA).

The study found that the so-called consumerization of enterprise IT, meaning employees who bring ostensibly consumer devices to work, continues at full pace. According to the report, 48% of employees are allowed to use mobile devices that they own to connect to corporate systems. Meanwhile, 70% of employees can currently use corporate-owned computing devices for personal activities.

"Employees will want to use their devices, no matter who owns them, for both their work and personal lives," said Graham Titterington, a principal analyst at Ovum, in a statement. "It is unrealistic to delineate between these uses for employees who are mobile and working out of the office for a large part of their time."

Interestingly, 90% of organizations provide -- or will soon offer -- mobile devices to their employees. A majority said those devices would be BlackBerry smartphones, which mirrors the continuing market dominance of the BlackBerry platform -- with a 37% market share, ahead of Apple (24%) and Android (21%).

But mobile device security controls remain a weak point, with only half of organizations authenticating their mobile device users. Among those, about two-thirds rely on usernames and passwords, while 18% use public key infrastructure (PKI) certificates, and only 9% employ two-factor authentication with one-time passwords. Furthermore, only about 25% of organizations ensure that employees' mobile devices are running antivirus and anti-malware software.

"As this new study bears out, putting a smartphone security strategy in place is now a business imperative," said Roger Dean, director at EEMA, in a statement. "But how many organizations have the in-house expertise required to develop and implement a mobile strategy that fits seamlessly with their overall security profile?"

According to Titterington, "organizations must establish a holistic security strategy that addresses the consumerization of this fast-growing channel into corporate networks and data."

Unified communications isn't just for the big guys; it can be extremely useful for smaller companies looking to streamline operations and improve productivity. Read our report and find out more. Download it here (registration required).

Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links