Fortinet advises CISOs to mitigate risks from BYOD and BYOA by implementing a ‘layered’ cybersecurity approach with increased visibility
Fortinet, a Global leader in broad, integrated and automated cybersecurity solutions, today warned that the significant rise of bring-your-own-device (BYOD) and bring-your-own-application (BYOA) usage among today’s mobile workforce across Asia Pacific (APAC) are exposing corporate networks to more complex cybersecurity issues through shadow IT, data leakage and the cloud.
Employees now expect to have their mobile devices with them at all times, and to be able to access the information they need to perform their job from their devices at any location. To meet these needs, firms are increasingly allowing staff to connect to the corporate network from their personal devices, with little control over application use.
According to IDC Asia Pacific’s Enterprise Mobility Survey 2017, BYOD has become the primary choice in organizations, with 31 percent preferring this approach compared to 19 percent in 2015. Meanwhile, a recent Global Market Insights report projected the global BYOD market size to be valued at US$366.95 billion by 2022, with APAC forecast to be the fastest growing region at 20.8 percent CAGR.
“Enterprises large and small are going mobile,” said Rajesh Maurya, Regional Vice President, India & SAARC, Fortinet. “While embracing BYOD and BYOA will certainly bring cost reduction, increased employee productivity and efficiency as well as employee retention, there are significant risks in allowing unprotected devices and applications to access corporate networks and digital resources.”
A recent industry survey has revealed that about 65 percent of organizations are now allowing personal devices to connect to corporate networks, with 95 percent of CIOs stating concern over emails being stored on personal devices, and 94 percent being worried about enterprise information stored in mobile applications.
To benefit from BYOD and BYOA without compromising network security or losing visibility into classified data use, Sri Lankan organizations must address three major cyber security concerns:
- Shadow IT – Strict policies on the applications and services employees are allowed to use on their devices can result in staff circumventing this security protocol to acquire solutions that will help them do their job more efficiently. This can present a major security risk, as IT teams struggle to secure data on applications they do not know about, or ensure that these applications are updated with the latest patches. If data on employees’ devices is breached, it is unlikely that IT teams will know about it and be able to implement proper incident response protocols.
- Data Leakage – Data leakage refers to the unauthorized movement of corporate data from the secured datacenter to an unauthorized device or location. This often occurs when employees transfer files between corporate and personal devices, or when they have access to privileged data not essential to their roles. As cloud and SaaS application use become more common and the number of connected endpoints increase, IT teams often lose visibility into data use and movement. To minimize data leakage, CISOs should consider implementing access controls and network segmentation that gives clear visibility into how data is used and moved both across the network perimeter as well as laterally across the network.
- Application Security – On average, organizations have 216 applications running within their organization, not taking into account personal applications stored on employee-owned devices. As these endpoints and applications converge and connect to the network, in-depth application security is necessary. This is especially true in cloud-based applications, where it can be difficult for IT teams to enforce the standard security policies of their organizations.
“To ensure data security in the age of the mobile workforce, CISOs have to take a layered approach to security that provides visibility into data movement across the network,” added Rajesh Maurya “Specifically, this security protocol should incorporate application security, endpoint security, network segmentation and cloud security, in addition to standard network perimeter defenses such as firewalls.”