Latest Blog Posts

Focus on 2012: 5 key areas in Enterprise IT

(19 December 2011)

From in-house to consultancy: moving to the ‘dark side’

(01 December 2011)

Brace for the feared double dip: IT planning can maximise mergers and acquisitions

(27 October 2011)

The tricky business of justifying IT expenditure

(19 October 2011)

IT consultants should drop the ITIL clichés to win clients over

(19 October 2011)

Steps to a successful Service Transition – new white paper by Plan-Net

(26 September 2011)

‘Cloud Consultancy’ – Experience On Demand

(26 September 2011)

ITIL 2011: Continual Service Improvement or just the result of V3 being rushed?

(03 August 2011)

The GLOCAL IT Service Desk

(26 June 2011)

Oh no… Not another Service Management initiative!

(20 June 2011)

5 reasons to employ an IT consultant

(22 May 2011)

Financial firms’ IP is safe with VDI

(11 May 2011)

IT Support: grow-your-own or buy organic?

(11 May 2011)

Where is that ‘cultural change’ which makes ITSM Best Practice effective?

(19 April 2011)

Executive exceptions: Best Practice killers or just business as usual?

(10 April 2011)

Desktop Virtualisation: Still not a perfect View

(23 March 2011)

What is the impact of the Cloud on the existing IT environment?

(10 March 2011)

Private vs. public sector IT security: more dedicated staff, yet less awareness

(03 March 2011)

Surviving IT spending cuts in the public sector

(15 February 2011)

10 things we learnt in 2010 that can help make 2011 better

(23 December 2010)

IT workforce continuity

(17 December 2010)

Minimising IT downtime for finance professionals

(30 November 2010)

ITIL V3 – should you bother?

(24 November 2010)

Taking the third option

(25 October 2010)

The peculiarities of Metro Bank’s IT outsourcing model

(19 October 2010)

Saving ITIL – how to protect the reputation of Best Practice frameworks

(11 October 2010)

5 tips for moving Disaster Recovery to the Cloud

(04 October 2010)

Does the future of business mobile computing lie in hybrid tablet devices?

(27 September 2010)

How many police officers does it take to email 10,000 criminal records to a journalist by accident?

(15 September 2010)

The perils of commoditising IT Support

(01 September 2010)

Life after ITIL – creating a culture of Continual Service Improvement

(02 August 2010)

10 reasons to migrate to Exchange 2010

(27 July 2010)

Are you Off-Sure about your IT Service Desk?

(14 July 2010)

Mind the skill gap

(11 July 2010)

Microsoft should fear not – is Apple even in the same league?

(24 June 2010)

Is your IT Service Desk future proof?

(22 June 2010)

The quest for a portable office - are all mobile devices safe for work?

(21 June 2010)

Will Tablets rule the future?

(16 June 2010)

Getting back to work - but with a service provider.

(15 June 2010)

Cloud computing: how to minimise lock-in risks

(09 June 2010)

Public sector, private data - is outsourcing the Service Desk too risky?

(02 June 2010)

Doing more with less: an opportunity to learn

(06 May 2010)

Sharing the IT Service Desk: sharing cost, sharing quality

(03 May 2010)

So, Microsoft outsources IT support – What’s all the fuss about?

(27 April 2010)

Survey reveals 1/3 of UK organisations put off Windows 7 roll-out, but are they wise to wait?

(13 April 2010)

Is information safe enough at NHS trusts?

(31 March 2010)

Best Practice and Virtualisation: essential tools in Business Resilience and Continuity planning

(25 March 2010)

What to look for when bringing offshore work back home

(22 March 2010)

5 thoughts on the IT Service Desk that need re-thinking

(10 March 2010)

Microsoft System Center Service Manager 2010: a credible challenger in the Service Management software market?

(17 February 2010)

Do you really want to lose (inter)face?

(15 February 2010)

A new lease of IT life

(11 February 2010)

From ITIL v2 to v3 – where to start?

(08 February 2010)

Can you afford not to invest in Best Practice?

(02 February 2010)

Experiential Learning explained through Confucius

(02 February 2010)

Quick win, quick fall if you fail to plan ahead

(11 January 2010)

Cloud computing – Help your IT out of the Tetris effect

(08 January 2010)

One of you may be fired

(17 December 2009)

Hot or not. ..Says who?

(15 December 2009)

2012: avoiding the IT Apocalypse

(03 December 2009)

Punishment alone does not work

(03 August 2009)

HSBC Data Loss

(26 July 2009)

ITIL for ITILs sake

(02 June 2009)

VDI and Windows 7

(06 May 2009)

The art of deception

(05 May 2009)

VDI - the revolution begins...

(04 May 2009)

Wake up and tackle the real VDI issues!

(24 March 2009)

ITIL Version 3

(18 February 2009)

Virtualisation - making the headlines

(18 February 2009)

Batten down the Hatches!

(18 February 2009)

Overcome the Freeze

(10 January 2007)

The quest for a portable office - are all mobile devices safe for work?

Posted in Infrastructure on 21 June 2010 by

"Free as a bird, is the next best thing to be," sang the Beatles. This is what modern workers want more and more: they want to be able to work while commuting, on a business trip and at home, even in the middle of the night or at weekends.

Naturally, the need for greater out-of-hours and out-of-office accessibility to work resources has grown with the development of new, smaller and lighter devices that are constantly coming out and gaining ground in the market.

With the choice getting wider by the day, professionals, who are getting more and more tech-savvy, want to be able to have their say when it comes to choosing their mobile devices. They want to be free to use what they like and are used to, for example their own mini Netbook or smart phone, rather than being forced to use machines approved by the IT department, often heavier and less discreet.

Some organisations have considered setting a budget for hardware expenses and allowing each individual to choose their own machine. Although arguably democratic, this move can turn out to be a disaster for two main reasons: firstly, the organisation would need to provide widely skilled, up-to-date support to cover all of the machines; secondly, and most importantly, the trendiest and newest gadgets often present the most risks concerning security.

While iPads and iPhones may appear more attractive than laptops, Blackberry and other handheld mobiles, it is not by chance that they are not popular in the workplace: they are not suited for remote VDI access and lack security lockdown features. Many smartphones were not originally designed for business or corporate use, therefore do not support data encryption. In addition to this, because of their novelty they may be more vulnerable to viruses and hacking. Let's keep in mind that trendy devices are more eye-catching and at a higher risk of being stolen. If the device is not effectively password-protected and its data encrypted, then the thief will have full access to the crown jewels.

Another risk linked to mobile devices is that the smallest, lightest ones have less storage capacity, therefore users end up transferring and storing data through the use of external devices such as memory sticks, and sometimes other unconventional tools which allow data storage, such as digital cameras memory cards or mp3 players, perhaps to conceal sensitive information. While small devices like memory sticks are easy to lose, the unconventional ones do not provide adequate levels of data protection.

Even with the new Data Protection regulations which came out this year, forcing private companies to declare breaches to the Information Commissioner who is free to make them public, and facing breachers with fines up to £500,000, it still seems that many organisations do not fully understand the need to enhance their security measures. A survey conducted by ICD Research in association with CBR found that organisations are planning to spend 42% more on mobility this year, whilst 36% will spend the same budget as the previous year. However, surprisingly, 61% are planning to spend the same amount of money on security as the year before, and only 28% are going to increase spending in that area. From this data, it appears that although organisations recognise the need for mobile devices and to embrace mobility, they do not completely realise the importance of security, which becomes even more crucial when work is taken outside the office doors.

To be effective, security must work in layers, and protect access equally from the outside and from the inside. Apart from passwords and physical barriers to impede external access, it is important to update antivirus software regularly, especially on the more modern devices, which are typically more vulnerable to bugs and attack by hackers.

It is important as well to allow data to self-protect, in case the previous measures fail to be effective or in the not uncommon case of human error. Only recently, the news came that a police officer emailed some 100,000 criminal records to a journalist by mistake, due to the auto-complete function in his email account. Although human error cannot be automatically prevented, there is a way to save the organisation from a breach of data security, and that is to encrypt all documents, even when they are just sent between co-workers. Data is exposed to risks whilst in transit, attached to emails, when the transmission channel is owned by an external provider.

To insure an enhanced level of security, training should be provided to all members of the organisation, as most breaches happen at end point. A security culture must be introduced with mobility to reduce the attendant risks and, most importantly, a loss of reputation for the whole organisation, and not only the employee responsible for the breach. It is only embracing such measures that mobility, efficiency and security can finally meet.

Ayodele Soleye, Senior Consultant

Find this article online on Director: http://www.director.co.uk/ONLINE/2010/06_10_ipad_security.html

Post your Comments

(required)

(required, never displayed)