Bring your mobile security up to scratch

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

It's an expensive business having your laptop stolen, as the Nationwide Building Society found out last month — and Worcestershire County Council may soon discover.

But the biggest cost doesn't necessarily come from having to replace the lost system. Rather, in Nationwide's case, the main outlay ended up being the £980,000 fine imposed by the Financial Services Authority, for what the regulator deemed were serious information-security lapses. Much time and money were also spent in informing customers of the potential risks they could be exposed to because of the theft, which took place at an employee's home in August 2006.

As a result, although Philip Williamson, Nationwide's chief executive, said "there has been no loss of money from our customers' accounts as a result of this incident", and that if there were they would be reimbursed anyway, the situation has nonetheless led the company to commission "a comprehensive review of information security procedures and controls".

Worcestershire County Council, meanwhile, was informed by its IT supplier Serco that an employee had a laptop stolen from them in a street robbery over the weekend. The laptop contained the personal details, including bank and national insurance information, of 16,239 staff and former personnel, laying them open to possible identity theft.

The council has alerted affected staff of the incident by letter and opened a hotline for them to call in order to obtain more information on how they can protect themselves from possible fraud.

But these two organisations are not the only one to have laptops disappear on them. According to a Freedom of Information enquiry undertaken by our sister publication silicon.com in August 2006, a swathe of government departments have suffered losses of their own.

The Ministry of Defence, the worst affected, reported 21 laptops stolen between July 2005 and July 2006. The Home Office saw 19 filched, the Department of Health, 18, the Department of Trade and Industry, 16, HM Prison Service, eight and the Identity and Passport Service, four.

But theft is not the only means by which laptops go walk-about. A 2005 survey of London taxi drivers undertaken by Taxi, the magazine for the Licensed Taxi Drivers Association, and sponsored by mobile security supplier Pointsec, found that over a six-month period passengers left an astonishing 4,973 laptops behind — although 96 percent were returned to their owners after the drivers went to the effort of tracking them down.

A further 5,838 PDAs were also abandoned in this way along with an astounding 63,135 mobile phones — an average of three per cab — although in the latter instance, drivers managed to return about 80 percent.

This would all seem to indicate that, in spite of offering convenience and flexibility to an increasingly dispersed workforce, mobile devices are nonetheless generating their own set of information-security risks.

One of the key concerns here relates to data leakage and the fact that unauthorised people could potentially get their hands on sensitive corporate information if laptops are lost or stolen.

Despite this, according to the Department of Trade and Industry's Information Security Breaches Survey 2006, undertaken every two years by PricewaterhouseCoopers, four-fifths of UK companies still rely on nothing more than passwords to protect their systems.

The problem with this, points out David Perry, a principal analyst at research company Freeform Dynamics, is that passwords are notoriously insecure. "People often use an unoriginal password or have it socially engineered out of them during a quick phone call. Quite a few are also in the habit of writing them down, but thieves always know where to look. For example, if they nicked the laptop bag too, it may well be in there," he says.

The situation is compounded, however, by the growing presence of wireless networks, used by staff when they are out and about and, to an increasing extent, when working from home.

Where the difficulty comes in here is that it is currently more or less impossible for users to know whether they are hooking up to a legitimate network or to a rogue hotspot — an issue that is particularly acute for users of Intel Centrino-based laptops, which look for a signal as soon as they are fired up.

This troublesome state of affairs is not helped by the fact that wireless security technology is still in its infancy, although products such as AirTight Networks intrusion prevention software are starting to emerge to tackle the issue.

Another potentially dangerous situation, says Ian Kilpatrick, managing director at distributor Wick Hill, is that of someone creating a so-called man-in-the-middle scenario.

"The user may believe that they've successfully connected to the wireless network, but someone else may have already got onto it and they could be connecting through them," he explains. "This means that person could log in using the employee's details and see any data that's flying back and forth, although the biggest single issue is that once they've got an identity, they've got it for ever."

As a result, Kilpatrick recommends that organisations ensure staff use SSL or IPsec virtual private networks when connecting to the internet from their machines, and also that laptops come with two-factor authentication products such as tokens or digital certificates to ensure that users are who they say they are when they try to log onto the corporate network.

Another vital tool is encryption software to protect any sensitive data that is held locally on the laptop. This, Kilpatrick says, can cost as little as £70 per machine these days if purchased in volume, "which compared to potential fines and reputational damage is trivial money".

A further worry, meanwhile, is the extent to which laptops can leave the corporate network open to infection by malware. According to a study by Symantec's Enterprise Security Group in 2005, the most common source of automated worm attacks was employee laptops, with 43 percent of organisations saying that incidents had been generated in this way. A further 34 percent indicated that infections were caused by the laptops of non-staff members.

Unfortunately, however, says Phil Huggins, chief technology officer at security consultancy Information Risk Management, the use of programs other than antivirus and anti-spam to protect client devices is erratic at best.

"The concept of endpoint security tends to be a very basic thing. It's pretty accepted now that you'll put antivirus software and maybe some anti-spam on all laptops, but deploying things like intrusion prevention, personal firewalls or encryption software, all of these are patchy," he says.

To make matters worse, while organisations may be vigilant in ensuring that their internal systems are patched and security software is kept up-to-date, all too often they are haphazard in lavishing the same care and attention on their laptop estate.

This is where remote management software can prove useful. Such systems can...

Talkback

There's a recent article at atlarge called <a href="http://www.atlarge.com/story/0,3800012715,39166465,00.htm">Bullet-proof laptops</a> that looks at laptop and mobile working security and precautions that might be of interest....

modafo 26 March, 2007 10:51
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

51 minutes ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

5 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

10 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

14 hours ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

18 hours ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

19 hours ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

21 hours ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

21 hours ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

23 hours ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

1 day ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

1 day ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

2 days ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

2 days ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

2 days ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

2 days ago by Mispam on Windows 8 start-up speed forces USB boot workaround