Partner Article

How is the public sector protecting mobile data?

It’s no secret that the public sector stands to potentially save thousands through the adoption of ‘digital by default’ and an increasingly paperless environment. However, as this trend continues to gain pace, the risks evolve with it, writes Stephen Midgley.

For example, in previous years managing data often meant literally keeping hold of it. If you let a stack of CDs fall into the wrong hands (or even just out of the right hands), you were in real trouble. By comparison, once that data is virtual and accessible from any device endorsed to access it, every single one of those endpoints becomes a potential security breach. And from laptops to desktops to smartphones, tablets and phablets, more and more are ending up in the wrong hands. In the past five years, security mishaps and data breaches have dominated the news headlines, with reported incidents of data breaches increasing by 1,609 per cent in local government. You do not need to look far for examples—earlier this year, Glasgow City Council was fined £150,000 for losing 76 unencrypted laptops. Such disasters are nothing new, but so far have generally been limited to legacy mobile devices. The influx of new form factors has changed this completely.

Absolute Software recently conducted its second annual report into the changing face of data security, analysing the circumstances of over 13,000 thefts. The results were startling. At the top level, the amount of data remotely wiped from stolen devices has risen by over 700 per cent, while quantity of devices recovered is up by 132 per cent. Nearly every meaningful statistic is still rising at a rate of knots.

So how do public institutions protect themselves against these growing threats? And how open is the public sector to embracing trends like Bring Your Own Device (BYOD) as a result of this increased risk? In considering this, it’s important to start by looking at the main areas of potential threats and analysing how they specifically affect this understandably conservative industry.

The first, most obvious concern is working remotely and working from home—in fact, within our research, the airport remains the leading location for device theft. It goes without saying that the further and more frequently you let a device travel outside the workplace, the greater the risk of it going amiss and requiring wiping or retrieval. But that’s not to say that you should impose limitations on how widely devices are allowed to be used. One of the biggest misconceptions about managing the influx of mobile devices in the workplace is that you can increase security simply by laying down strict guidelines. Employees will break the rules every time, either through naivety, ignorance or ingenuity. A file emailed to a personal account to work on while out of office here; a cloud storage account setup to access data on multiple devices there—the opportunities for digital data breaches are broader than ever. Either way, the result is the same: you’re not as secure as you thought you were.

So when it comes to working from home, and remote locations, it’s better to find ways to enable your employees to use their devices in the ways they are trying to. You can mandate and even push certain apps directly to devices for these kinds of tasks, safe in the knowledge that you’re in control of how they’re used. You can offer the benefits of being able to find someone’s personal phone if it does go missing and get it back to them. With the right software, these opportunities are well within reach and allow you to lead the charge of innovation instead of struggling to keep up with it.

However, equally as important as enabling your team to work how they choose is the priority of making it easy for them. Where you require user maintenance or time spent helping you setup the programme, keep it simple. If you rely on long complicated guides or high maintenance intrusive policies, you may be expecting too much of already busy staff. That, in turn, could lead to flaws in execution that leave you less secure than you had thought.

An area that’s just starting to receive more attention in regard to security is apps. In this area, it’s important to remember that it’s never “just an app”. Your team need to realise that installing an app or activating a new feature can open dangerous and vulnerable new pathways for these threats. And they may be hard to mitigate in software alone. Take common file sharing tools like Dropbox, which may allow the transfer of files beyond the channels that you’re consciously managing. In many ways, these utilities are the modern equivalent of the age old USB stick dilemma. Another important consideration is the wide variety of devices and operating systems that are increasingly hitting your organisation. From iOS to Android to Windows Phone and BlackBerry, there may be clear majority market leaders but it still only takes one device in the minority to undermine your entire mobile security strategy. Make sure you have a system that lets you manage the full range, today and into the future, without duplication of effort. It’s important to ensure you have a system that will throw up alerts and draw your attention to any potential area of danger well before they become a genuine threat. In the public sector especially, it’s better to spend time looking into a few false positives than miss the boat when something serious makes it onto the radar. If this report teaches us anything it is that preparing properly is really the best way to secure the increasing array of mobile endpoints emerging in the public sector. The sooner you start down this path, the sooner you can start operating with confidence and use the benefits of the mobile world to create an improved citizen experience.

This was posted in Bdaily's Members' News section by Stephen Midgley .

Explore these topics

Enjoy the read? Get Bdaily delivered.

Sign up to receive our popular morning National email for free.

* Occasional offers & updates from selected Bdaily partners

Our Partners