Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Working on the Go – But Securely
Articles

Working on the Go – But Securely

ISBuzz TeamBy ISBuzz TeamNovember 9, 20157 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Working on the Go – But Securely
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The increase in the number of high-quality Wi-Fi connections has made it easier to work from anywhere. Even just a few years ago, the fixed desktop with an Internet connection was still the norm. Today, various mobile devices enable company staff to work in different locations so they no longer need a permanent desk. Mobile staff can share data with their coworkers – but this process needs to be secure.

Accessing data from anywhere

The physical location is not the only aspect of work that is becoming more flexible. Bring Your Own Device (BYOD) is standard practice in many areas today. Staff can work on the devices they are familiar with – meaning that personal laptops, tablets and smartphones will need to be integrated into the corporate network. However, this brings a security risk with it, as each employee may be working with company data on their own personal device. These devices may have security vulnerabilities that enable unauthorised people to access the data – or even the corporate network.

Despite this, it is possible for staff to work securely with their own devices. First, the company should clarify the legal questions, such as the extent to which its employees are allowed to access internal network services and whether they can work with and save company data on their devices. The firm may also want to enforce technical security measures. In these cases, it needs to ensure security wherever the data is being used and stored, and secure the data transmission itself.

For example, a company could stipulate that the only devices permitted are those that access the internal network using a secured VPN connection and that hard disks are encrypted. It could also limit access to certain services. Users’ devices would then act as a terminal for a trustworthy cloud application that provides staff with a secure dataroom.

Practical but non-secure apps

A particularly sensitive point is the use of the mobile apps that are in widespread use on smartphones and tablets. Many of the free, business-oriented storage applications advertise the fact that they offer modern file management with a generous amount of storage space that centralises documents in the cloud. There are also so-called productivity apps that let users sketch out ideas, collect information and make notes that can be shared and worked on with coworkers.

But how secure are these cloud applications? Who has access to the data stored on the cloud servers? Is the data transmission secure between the cloud computer and the mobile device? And does the app only use the data it really needs?

These questions are justified, as recent research results show. Researchers at the Fraunhofer Institute for Secure Information Technology (SIT) found that three-quarters of the most popular business apps do not meet companies’ security requirements. And IT specialists at Germany’s University of Bremen found out that many apps require more permissions than they need. When researchers at the Fraunhofer AIESEC institute tested 10,000 of the most popular Android apps, they found that 91 per cent require permission to connect to the Internet without the user being told why. Most of the apps tested sent personal data to servers around the world as soon as the app was started and without asking the user. The researchers were also surprised to note that two-thirds of the apps sent the data in unencrypted form.

So what can companies and users do to control this unwanted data leakage from mobile apps? A new study by DIVSI (the German Institute for Trust and Security on the Internet) examined the four main mobile operating systems. It concluded that apps running on a standard Android operating system have the most flexibility in terms of accessing data, whereas with iOS and BlackBerry users can withdraw access permissions from the apps and reinstate them later as required. Android and Windows do not offer this option.

These limited control options show that companies operating a BYOD strategy must make it a priority to provide staff with a secure collaboration and communication tool.

High risk

The risk of data misuse is not trivial. A new, representative survey on industrial espionage by the management consulting firm Corporate Trust estimates the losses to German business at €11.8 billion per year. Two years ago, the estimated figure was only a third of what it is now. “We’re probably already in Cybergeddon,” says the study leader Christian Schaaf. “We can only hope that companies react soon and implement the appropriate security measures.”

No less than half the 6,800 companies surveyed said they had been victims of hacker attacks on their systems. And 41 per cent had discovered interceptions or eavesdropping on their electronic communications. The third greatest risk at 38 per cent was customers or partners asking staff leading questions to extract information, and at fourth place with 33 per cent came data stolen by companies’ own staff. Innovative midsized companies are the worst affected of all – yet midmarket firms have limited awareness of the risks and few of them implement an effective protection strategy. Some companies are starting to react by separating private and business use within mobile apps. That’s an important step but is not sufficient to protect documents.

Companies need to provide good alternatives

Information security is available in the cloud as elsewhere, but it requires the implementation of a series of measures. In view of the precarious situation, it is important for companies to make their staff aware of the risks and provide them with secure applications. Employees should never be tempted to find a time-saving or more practical workaround – such as quickly sharing a document on popular but non-secure applications. This means that the security tools their companies provide must meet all important usability criteria for convenience and flexibility as well as security and reliability.

Checklist for collaboration tools that are flexible and mobile yet secure

Chief information security officers (CISOs) and data protection managers should focus on the following areas when looking at how people should work with business-critical data:

  • The cloud application should be flexible and easy to use, support a variety of user devices, and integrate seamlessly in the company’s existing infrastructure.
  • It should include encryption based on the latest standards for communication between the user and the cloud, between the cloud and the administrator, and between the individual cloud servers.
  • The documents stored and edited on the servers should be encrypted. This includes encrypted storage of passwords and permission concepts.
  • The cloud application’s security level should be proven with a certification.
  • Access to the data should be limited to authorised users. This should also cover an expiry date for access to certain types of data and two-factor authentication using different communication channels. For example, a user should only be able to access a document link after entering a password or code texted to their mobile phone.
  • Users should be able to control access to files, such as by stipulating that a document is read-only. Changes to content should always be logged.
  • Documents must be encrypted on users’ devices and protected from being forwarded to others.

[su_box title=”Mark Edge, Country Manager UK, Brainloop” style=”noise” box_color=”#336588″]Mark EdgeMark Edge joined Brainloop in September 2014 and brings over 20 years of sales experience in the IT, security and networking industries. In his current role he is responsible for building out Brainloop’s UK team and driving the company’s growth across the region.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}