BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

It’s an Insecure Mobile World Without Least Privilege

Posted August 23, 2011    Peter McCalister

It’s hardly a stretch in this day and age to say that every one of your employees has a mobile device, whether it is company issued or personal, but either way these devices can be the culprit of accidental insider threats more easily than ever before.

A recently released mobile threat report estimates that between half a million and one million users were affected by mobile malware in the first half of 2011, and for anyone that uses their device to access corporate email accounts or VPNs, an infected device could open up an entirely new world of concern around corporate data loss.

Malicious damage from a Trojan on a mobile device is capable of deleting files from the device and allowing personal and confidential information to be collected, without the user even being aware that it’s happening. If employees have sensitive data on their phones from email archives or in the form of corporate documents that have been downloaded directly to the device, the higher the risk that information can be leaked, should the device become infected. This is where having the right privilege management policies in place – ensuring that only the people who absolutely need access to information regarding certain elements of the business – is a critical first step to protecting your organization from this specific type of insider threat.

Part of developing best security practices around mobile phones takes place on the device itself, such as ensuring the software is always up to date and being cautious about downloading applications and clicking on links, but it’s also critical that organizations are implementing the best possible privilege identity management policies to mitigate the risk of an accidental insider threat breach from a mobile device.

Leave a Reply

Additional articles

darren-mar-elia

BeyondTrust Webcast: Darren Mar-Elia’s 4 Active Directory Change Scenarios to Track

Posted August 20, 2014    Chris Burd

In our latest webcast, we joined Darren Mar-Elia, CTO at SDM Software, to discuss best practices for Active Directory (AD) change management. Here are some key takeaways from the presentation, followed by a link to a full-length video of the presentation. Mar-Elia kicks things off with a critical insight: that the best AD change management…

Tags:
, , , , , , ,
normal-blog-img

New IT Security Best Practices for Maintaining “Business as Usual” Despite Evolving Threats

Posted August 13, 2014    Morey Haber

It’s time to get back to business. Here in the U.S., summer vacations are wrapping up and businesses are looking forward to closing out 2014. Over the past year, we’ve seen several incidents that warrant changes in the ways consumers make purchases and businesses conduct transactions. Consider last week’s theft of a whopping 1.2 billion…

Tags:
, , ,

Retina Vulnerability Audits – August 2014 Patch Tuesday

Posted August 12, 2014    BeyondTrust Research Team

The following is a list of Retina vulnerability audits for this August 2014 Patch Tuesday: MS14-043 - Vulnerability in Windows Media Center Could Allow Remote Code Execution (2978742) 34924 – Microsoft WMC Remote Code Execution (2978742) MS14-044 - Vulnerabilities in SQL Server Could Allow Elevation of Privilege (2984340) 34915 – Microsoft SQL Server Multiple Vulnerabilities (2984340) – 2008 34916 –…