Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Beyond Boundaries: Smartphone Security Borderless Society
Articles

Beyond Boundaries: Smartphone Security Borderless Society

ISBuzz TeamBy ISBuzz TeamMay 29, 2019Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Median and technology
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With greater connectivity, comes a greater risk.   

This can be a cause of concern and stress for many of us. In a world that expects us to be connected anywhere and at any time, we often fail to understand that this means we are also at risk – everywhere and at all times.   

As our work and personal environments become increasingly blurred, the challenge for organisations today is to achieve the correct balance between security and openness to staff working flexibly – especially when using mobile devices. A huge variety of ‘things’ are being connected to the Internet – and with data being stored in multiple environments, the risk factor is increasing. Smartphones are becoming one of the biggest risk tools – and businesses need to understand how to minimise this as a potential vulnerability.    

Who’s on your phone right now? 

According to research from McAfee Labs, more than 16 million mobile malware infestations were detected in the third quarter of 2017 alone. This is nearly double the number from the prior year.  Gartner forecasts a third of all malware will be mobile by 2020.  It’s clear that as more of us join the digital revolution, the bait for malware authors to attack our mobile devices is heightened. 

Malware can take many forms including spyware that monitors a device’s content, programs that harness a device’s internet bandwidth for use in a botnet to send spam, or phishing screens that steal a user’s logins when entered into a compromised, legitimate app. 

With all this evidence, you would think that companies would ensure that any device which touches their network is checked and verified? But unfortunately not, and you’ll find that most are only secured using simple password-based security measures, and this is simply no longer fit for purpose. Fraudsters have had an easy life gaining access to corporate data via poorly secured devices, apps missing strong security protection and masquerading as genuine services such as public Wi-Fi hotspots. 

The boundaryless society 

For too long, companies have assumed that securing the boundary with a good firewall will provide the required protection. The issue is that we don’t know where the boundary is anymore.  

Let’s take flexible working as an example. In today’s increasingly connected society, flexible working has become more widespread and is steadily being implemented more successfully. In fact, according to our research, 73% of employees believe they have a good flexible working policy.  In order for these employees to work remotely, they are relying heavily on mobile technology. This means that there is no physical boundary but instead, the employee becomes the boundary, and any individual can form the edge of the network.     

We therefore now live in a borderless society. With employees capable of connecting to workplace tools, apps and information via any unsecured network, anyone can infiltrate the connection. What’s more – if we were to lose our mobile devices, most of us have our sensitive apps readily logged in and available for anyone to steal and wipe the data they want.    

The battle to achieve greater smartphone security   

In order for business leaders to protect their most valuable asset – company data – they must develop strategies that establish trust through the processes that collect, capture and transfer sensitive information between those, both inside and outside of the organisation. They can do this by ensuring they’re Secure by Design and implementing a security methodology which takes into account all aspects of the solution.   

Our Secure by Design methodology has 4 key principles: 

  • Defence in depth – using a series of different defences together rather than a single point solution. There’s a wide range of Commercial Off the Shelf or COTS solutions, but the key is to understand how these can be combined together with traditional network security to provide a truly holistic solution. This is where you need a managed security service provider (MSSP) to deliver security solutions across multiple products and services. 

     

  • The weakest link – you can’t secure what you can’t see, meaning companies need to know who is connecting to the network. We see a lot of discussion around zero trust but often we suffer from zero visibility. Identity and Access management not only checks that you can see who’s connecting to what, but it can even monitor behaviour to see if the end user or device is acting suspiciously. Was that a sudden unplanned trip to a foreign country or has someone stolen your account details?   
  • Security is a process – security is not a product or a one-time goal, it should continue throughout the lifetime of the service and constantly evolve to meet and defeat the latest threats.  Next generation technology can now be deployed to mobile devices, ensuring that they are protected with a multi layered defence. This allows for updates and adaptions as required, without needing to suffer the big bang change that so often restricts many.   
  • Keep it simple – security should never compromise usability. Solutions need to be secure enough, then maximise usability without the need for extensive configuration. ‘Keeping it simple’ means we can keep tech flexible and are able to adapt to changes in the way we work.  Where before we saw every device a liability and everyone with them a security issue waiting to happen, initiatives like BYOD no longer result in nervousness.    

With the principles understood and the security design created, businesses can then roll this out to employees and ensure all security policies are communicated back to staff. By communicating and listening to staff, employers can explain the rationale behind the business’ security plan, and employees will respect and adhere to the plan if they understand the reasons for doing so.   

Security is still trying to catch up with new working practices – we’ve embraced the latest technologies, without fully taking into account the risk. With our workplaces situated very much in the mobile world, it’s time to prioritise security and protect the edge of our networks, wherever that may be. 

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}