Mobile security

July 2011 Information Security

The issue of information security becomes more important with each new media report of hacking or stolen personal information. For most people, using mobile devices to send and receive e-mail that may be confidential is not an issue. Hi-Tech Security Solutions spoke to Sinisha Patkovic, director of BlackBerry Security at Research In Motion (RIM) about the realities of mobile security today.

Sinisha Patkovic
Sinisha Patkovic

Hi-Tech Security Solutions: There is much talk about the threats to business from mobile devices carrying sensitive information, but the problems we hear about (like Sony) do not seem to include mobiles. How serious is the threat to mobiles?

Sinisha Patkovic: Like any computing device, mobile devices may be prey to malicious programs, or malware. Protecting any computer system from malicious programmes such as viruses, Trojans, worms and spyware can be accomplished through detection and containment.

Detection is the process of determining whether a programme is malicious, something you typically see on any PC. It is not only a reactive way to deal with the problem, but effectively detecting malware on a smartphone is difficult because of constraints such as limited processing power, battery capacity, and storage space to cater for security solutions such as traditional antivirus software with large signature databases. There is also no guarantee that an attacker will not deploy a freshly written piece of malware onto your user’s device, which will be very hard to detect by the current generation of anti-virus scanners. Such malware will go undetected and provide stealthy access to your organisation information for unlimited time.

Containment, on the other hand, is more proactive. Here the system controls access to the information, APIs, and device software and other applications on the device. The malware cannot spread as it cannot gain necessary access to resources. Obviously, containment approach is much more effective as it not only provides protection against any potential threat in the system, but it also does it at a minimal expense; there is no extra software required to be deployed and managed, and there is virtually no impact on the smartphone’s memory, CPU and battery.

While containment is superior to detection in most aspects most manufacturers avoid doing it because it comes as an expense; it must be well designed into all layers of the software, and it must be well implemented.

HSS: Where do the greatest mobile threats come from – malware/stolen devices/hacked devices?

Patkovic: Since smartphones are very personal in nature, they can go everywhere your users go. This means that there is a good chance that some are going to be lost, stolen or left behind. There are a number of considerations for organisations to take when planning how to deal with these types of situations.

The business risks of an unsecured device falling into the wrong hands as a result of theft or loss can be enormous. The consequences may include public embarrassment and bad press; theft of sensitive financial and customer data or intellectual property, legal trouble and strained relationships with customers. Being able to remotely wipe and disable a rogue device is essential. However, it is even more critical to ensure that your mobile platform is not allowing unauthorised software to run on it.

HSS: More companies are allowing employees to use the devices (laptops, tablets and smartphones) they prefer. Would it not be better to limit the devices to those the company is sure it can secure?

Patkovic: The consumerisation of IT is one of the biggest challenges CIOs face today. What is at stake here is the reputation of their brand and their business. Such is the impact of security breaches where sensitive corporate or private customer information is lost, exposed or stolen. Although the impact varies with the type of attack, size and nature of breach and the industry, there is always a financial component and damage of reputation involved. This is why it is very important for organisations to take a good look at the risks associated with the consumerisation trends, and how to deal with them. With the right policies and technologies in place, organisations can feel confident in allowing the use of personal employee smartphones.

Here are the basic areas your policy for employee-owned devices should cover.

* Define which employees can access the corporate network with a personal device.

* Define the applications and services that can be accessed.

* Decide how the costs will be split.

* Decide which platforms and types of devices your organisation will support and what level of support will be provided.

* Consider the security measures and IT policies that will be enforced on employee-owned smartphones.

HSS: How do corporate risk managers need to adapt their security policies to incorporate remote and mobile work?

Patkovic: Making the right security decision for your organisation relies on striking the right balance. There are typically two extremes which manifest if the balance is not found.

* Too much security. Often due to a fear of the unknown and mobility not being completely understood within the organisation, all features and functions get locked down.

* Not enough security. In contrast, too little security stems from IT administrators looking for the path of least resistance, usually as a result of ignoring security questions when they arise.

This returns to the question of balance. Users will often willingly accept strict security measures provided that they are as transparent as possible, do not cripple functionality and enable them to be more productive. If a device is locked down too tightly, users will simply reject it, which then puts pressure on the organisation to introduce devices that cannot be secured or controlled; but if the device is left too open a potential risk is introduced.

HSS: What are the basic security measures/processes mobile workers should adopt?

Patkovic: Mobile workers using a smartphone should follow these easy tips:

* Use a strong password: Setting a reasonably strong password is the single easiest and most effective way to lock down your private data. Without a password, much of your data is accessible to prying eyes. With a password, you are far more secure.

* Set the number of password attempts: If a password is typed incorrectly 10 consecutive times, all of the information on the smartphone is automatically deleted. You can change the number of attempts to 3–10.

* Lock your phone automatically after a certain amount of time: You should set the security timeout feature to automatically lock your smartphone after a set amount of inactivity. For lost or stolen smartphones, this is a critical security block.

* Encrypt the data on your smartphone and media card. Encryption mixes everything up so no-one but you can read anything without the correct password.

HSS: What does BlackBerry offer as standard to its clients that helps secure their data?

* Patkovic: Just by following the checklist above, your personal data will be locked down like a safe. But your BlackBerry smartphone protects your data in other ways too. Here are some examples:

BlackBerry smartphone authenticates the BlackBerry Operating System every time you start a device. This prevents an attacker from tampering with the operating system, by planting a back door for example. This provides for a secure and trusted environment for other applications you may allow on the devices.

Secure browsing to shopping and banking sites using SSL encryption.

Attachments are rendered into safe formats to help protect you from malicious code.

Applications received in e-mail cannot run on your BlackBerry smartphone.

By default your BlackBerry smartphone continually removes sensitive data from temporary memory.

Our BlackBerry Enterprise Server offers over 500 IT policies, catering to the security needs in businesses where data privacy and protection are business critical, but equally to those organisations where security is a nice-to-have rather than a requirement.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
You will not get your files back with VECT
Information Security
If the newbie to the ransomware scene, VECT, comes knocking at your organisation’s door, do not pay the ransom! The decryption keys simply do not exist. They were discarded at the moment of encryption by the malware itself.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.