Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Going Away? Don’t Forget to Pack Your SunScreen and Cyber Security
News & Analysis

Going Away? Don’t Forget to Pack Your SunScreen and Cyber Security

ISBuzz TeamBy ISBuzz TeamAugust 30, 20136 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

During the summer months many of us look forward to a couple of weeks away from the office. However, in reality, complete radio silence from those left behind is not always an option. Easily affordable technology, such as smartphones and tablets, means keeping in touch while away is not just expected, but increasingly the norm.

According to our recent survey conducted by OnePoll, 41% of respondents said they’d be taking their phone with them. While that might seem a fairly normal event given the technology age we live in, those phones are unlikely to be supervised 100% of the time – leaving them vulnerable to theft. With just 50% protected by a password or other security controls, many could be revealing confidential personal or business information.

Here are a few simple things to keep in mind while out and about:

InSecure WiFi

Often, it is all too tempting for holiday makers to pull out an electronic device and check a few things from the hotel’s poolside free Wi-Fi service.  Unfortunately, convenience doesn’t always equate to security.  That’s why it is very important to use a secure connection when accessing sensitive information, especially if it is on the corporate network.

When sending an email, think of it as sending a postcard – everyone can read it. If unauthorised eyes shouldn’t be reading your message then standard email is perhaps not the best method to send the information. Instead, either use an encryption solution or call the information through.

Establishing a VPN before utilising free Wi-Fi is also highly recommended.  The secure SSL tunnel created helps to secure the session and keep corporate network resources safe.

But remember that, even when using a secure connection, make sure to always and completely log out of sensitive sites. While it might seem all a bit James Bond – including the shaken not stirred martini, it is possible for an attacker to hijack a session that has been left open. Of course, some sites will perform an automatic log-out after a period of inactivity, or when the browser closes, but those few moments still present attackers with a window of opportunity to get in if the session hasn’t been purposefully terminated.

Closing down other, non-related Web browser tabs is not a bad idea either. Wi-Fi utilises radio waves to communicate; these waves are accessible to anyone who wants them.  It is for this reason Wi-Fi can be so dangerous.

If set up properly, private Wi-Fi connections can be a viable remedy to surfing Wi-Fi spots.  And at the very least, WPA2 encryption should be used.

Additional security measures that can be put into place include MAC address filtering (though this can be a bit advanced and can lead to device lockout if not done correctly) and users certainly can’t count on the encryption being provided when using a public network.

Mobile’s on Tour

The mobile market has grown exponentially with two major mobile operating systems leading the way in the smartphone market, iOS and Android. Back in the day when every phone had its own operating system it was usually a less than fruitful endeavour for malware authors to bother targeting any one of them. But now that we’ve narrowed down the playing field, mobile devices have become a much more appealing target.

One simple rule of thumb everyone should heed is safe browsing habits regardless of network or device. Remember, the same dangers that exist on the Web (i.e. black hat SEO poisoning, social media, email and SMS) can also exploit a mobile device.

SMS and voicemail are common vectors of attack for phishing scams today.  That’s why it is so important for users to first reach out directly to an institution, organisation or individual and verify information before responding to a questionable voicemail or text.  Or, simply delete suspicious messages since responding to them can end up in text charges or possibly even more.

Padlocks

Another rule for safe mobile device usage is security on the device itself.  As our survey found, only half of the people questioned had any type of security on their phone, meaning many are at risk of losing more than their device if it goes AWOL – whether at home or abroad. In fact, 12% confirmed their devices contain sensitive information with just 23% able to wipe the device were it lost or stolen.

The functionality of phones today means many are likely to contain personal information (such as stored logins to banking or social media sites) and could provide someone access to sensitive information were the device to be lost or stolen.  To minimise this threat, something as simple as activating a password means this information is afforded at least some protection.

However, while a password will thwart the opportunistic thief, someone who is targeting the device because of what it might offer a stronger defence is needed. For those who carry confidential business material, or who are serious about their privacy, additional security needs to be deployed. Encryption software on the device will help protect data in the event that the device becomes lost or stolen. Using a remote wipe to brick the device completely is one way to ensure sensitive information doesn’t fall into the wrong hands.

App Security

Finally, while launching a favourite app or trying out some new games may keep us, and even the kids, entertained, it isn’t without some risks.  Always make sure these applications come from a reputable source, while keeping aware of the permissions they ask for during the install.  Read reviews and learn what others say about them before downloading.

Just like we need to take precautions with our skin – or pay the price with painful sunburn the same applies to CyberSecurity.  A little thought before we travel can avoid a holiday becoming far more expensive than first planned.

Fred Touchette | www.appriver.com| @phreadphread

Fred Touchette - AppRiverFred Touchette joined AppRiver in February 2007 as a Senior Security Analyst.  Touchette is primarily responsible for evaluating security controls and identifying potential risks.  He provides advice, research support, project management services, and information security expertise to assist in designing security solutions for new and existing applications.  During his tenure at AppRiver, Touchette has been instrumental in accessing critical IT threats and implementing safeguard strategies and recommendations.

Touchette holds many technical certifications, including CCNA, COMP-TIA Security+, GPEN – GIAC Network Penetration Tester and GREM – GIAC Reverse Engineering Malware through the SANS initiative.  He is highly regarded as an expert on email and Internet-based cyber threats, and has been referenced in several top technology publications including USA Today, Forbes.com, Dark Reading and more.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}