Mobile threats should be on everyone's radar

September 2011 Infrastructure, Information Security

The security space is constantly evolving. As fast as technology is changing, cyber criminals with malicious intent are never far behind, adapting their methods to take advantage of new ways of attack.

Cyber crime has become a more profitable industry than the drug trade, and as a result the malicious software now developed is no longer about simply causing a nuisance, but has evolved into a sophisticated scheme aimed at stealing sensitive information in order to make a profit. Methods like spear phishing are aimed at obtaining this information through a highly targeted attack that uses personal details and information to make the attacks seam more genuine, and this method is gaining popularity. Other trends to look out for include the growing use of shortened URL links in spam e-mails to disguise the nature of the link and the use of languages other than English in malicious mails depending on region.

One trend however that stands out as something that is set to explode in growth is the move away from threats that only target the Windows operating system. In the past, because Windows owned such an overwhelming majority of the market, it made sense for cyber criminals to focus their activities in this space. However as Mac and other non-Windows operating systems have gained market share they have increasingly become the target of attacks over the years, as there is now profit to be made by aiming at these users. This move has also been fuelled by the massive growth of the smartphone and tablet PC market, and as these devices have become more mainstream they have become at greater risk as targets for malicious intent.

The use of smartphones, and now of tablet PCs, to access the Internet, has grown exponentially over the last few years, especially in emerging markets such as South Africa, where a large percentage of the population uses their phone as their means of accessing the Web. Mobility is by no means a new thing, but the sheer proliferation of its use in recent times as well as an increasing drive for constant connectivity has greatly increased the risk associated with using these devices.

One mistake users make is in assuming that these devices are safe to use for browsing. However the reality is that they are at risk for the same threats that attack PCs and computers, as spam e-mails are often pushed to the devices through in-built e-mail capability and malicious links could just as easily contain harmful software that could attack the phone. Specific viruses are now being written for phones, and there is now a range of viruses and Trojans aimed particularly at these mobile devices, sent through SMS, MMS and e-mail, with the intent once again of stealing information.

The other risk is that often these mobile devices are connected to a network in a home or office environment. Malicious tools that infect mobile devices may not affect the phone directly, but they can sit dormant until the user connects to a network and can then affect the network in the same way as computers accessing the network can. This makes it vital for organisations of all sizes as well as personal users to protect their smartphones and other mobile devices in the same way they would protect their PCs and networks.

Solutions are now available for mobile devices that offer protection against malicious threats as well as against unauthorised access to information. These solutions provide similar protection for mobile devices including anti-virus technology and firewalls, as well as additional functionality including SMS anti-spam protection. And with ever tightening compliance regulations for enterprise, mobile protection solutions can help to ensure that users with such devices do not compromise the internal and external security compliance requirements of businesses.

The rule of thumb is that information must always be protected, no matter the device on which this information sits. With the dramatic increase in mobility and the growing number of users who now have multiple devices this has become a more complicated process. Protecting all network accessing devices from malicious software is becoming a necessity, but software is not enough and a comprehensive backup strategy needs to be in place that covers all of the devices used to store and access information.

The reality is that the more portable a device, the more likely it is to get lost or stolen, and with people now using these highly portable devices to work from as well as their PCs, multiple versions of documents exist across multiple platforms which need to be backed up. These mobile devices need to be synced to PCs and the network to ensure the correct information is backed up.

Protecting information is a two-fold process that has become even more important with the growth of mobility and constant connectivity. A combination of the latest protection software with a comprehensive, all encompassing backup strategy is the best way to ensure organisations and individuals do not fall foul of the ever increasing number of threats in the cyber world.

For more information contact Fred Mitchell, Drive Control Corporation, +27 (0)11 201 8927, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cyber resilience – protect, defend, recover
Infrastructure
The challenge with AI is that threats are getting harder to detect. As a result, plans in 2024 are not just about detection and prevention, but about recovery.

Read more...
Powering business resilience and field operations
Infrastructure Products & Solutions
[Sponsored] The Anker 757 Portable Power Station emerges as a strategic asset for businesses looking to overcome power instability and the demand for operational efficiency in remote and field-based environments.

Read more...
Top bets for backup and business continuity
Infrastructure
Become your organisation’s data pioneer and spearhead data governance and protection of critical data. Challenge why best practices are not adopted or in place, while highlighting the inherent risks this poses.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Next-gen solar-powered switches
Infrastructure
Duxbury Networking has introduced its range of solar unmanaged switches, which are ideal for any environment requiring reliable Power-over-Ethernet (PoE) capabilities, such as IP phones, cameras, and access points.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...