ABOUT THE AUTHOR


Matt Brunk
Matt Brunk is the President of Telecomworx, an interconnect company based in Monrovia, MD serving small-medium enterprises. He has worked...
Read Full Bio >>
SHARE



Matt Brunk | February 20, 2012 |

 
   

Route 1 Challenges: BYOD

Route 1 Challenges: BYOD Bringing your own device is popular. Bringing your own secure device needs to gain traction as well.

Bringing your own device is popular. Bringing your own secure device needs to gain traction as well.

The enterprise is certain to be headed for a handful of surprises as employees and suppliers bring their own devices and connect them to the network. BYOD doesn't necessarily assure that these users also "Bring Your Own Secure" devices.

I had a talk with Route 1 CEO, Tony Busseri about their communications and services platform, MobiNET. MobiNET provides identity assurance and individualized access to networks and data. The solution is patented and built on FIPS 140-2 cryptographic modules.

The short version of how MobiNET works is simply that whatever device connects to the network becomes essentially a dumb terminal. Identities of users are authenticated and the solution is not device driven. IT and network managers steer what is accessible, and where in the network users are permitted. (See Solutions Overview here)

Tony noted that you must keep data within the fortress as well as knowing who the user is and authenticate them to strengthen the ability to stop data from leaving (see diagram below). Currently, many enterprises find themselves in a crunch, as they're pressured to let any device connect using any means; an exponential number of risks are either ignored, mitigated with self-insurance (banking), acted on with varying degrees of security at a wide range of costs, often betting the technology against an estimate of acceptable risk.

In my past post: Lost & Found: Another Security Nightmare,I wondered: The numbers of lost handheld devices compromises how many networks? But lost devices won't lead to changes in decisions until the attitude of protecting your data changes within the enterprise. I've long said that it's not what's coming into the enterprise that's as damaging as what is leaving it. This example rings true back to earlier times of private hardened networks being compromised by data leaving. Many of these compromises were either procedural flaws or failures to provide a degree of physical separation. With the BYOD rush, scores of new risks potentially enter and then obtain data from the interior of the fortress.

Since most of them are mobile, BYOD devices are potential moving targets. Oddly, when Apple employees allegedly lost their iPhones, a media storm either promoted the event of a new cool iPhone while ignoring the potential data compromise, or Apple feared some compromise of what, discovery of new hardware? Sadly, the new iPhones retain what the old offered and that is a 4-digit PIN to unlock the phone. But security and being open to communicate and obtain any data when and where you want it isn't a major selling point to the consumers. Arguably Apple and Google and scores of other firms aren't necessarily making security a key concern for users.

I asked Tony what key industries he thinks are vulnerable, and he said banking and law, because both of them are open to identity theft. Now as hardened vs. un-hardened browsers are concerned and whether or not all my data is safe, am I concerned? The reality is I want the convenience of having all my accounts linked at my bank so that it's easy for me. This is the cold hard reality of many users, and it's the challenges for network managers that try to appease them. The other reality is I am taking a risk, and the convenience is worth it until there's a compromise. Then, you will hear another tune and story as to why you don't do this. Will the bank be able to protect my data and is their platform secure? How secure? The word bank isn't always indicative of safe because bank robbers and hackers seem to target these assets. With a plethora of mobile devices, it's certain to be more than temptation that may lead to new and more effective attacks on mobile



COMMENTS




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Did you know you can style comments using HTML tags and upload your avatar photo? To upload your avatar photo, first complete your Disqus profile. Once your profile is complete, you may add your avatar photo. (Hide this hint)
Enterprise Connect Tour 2012
In response to the booming demand for SIP Trunks—and for information about SIP Trunks—Enterprise Connect is launching a four-city “road show” on this vital topic.
May 22: San Francisco
June 6: Chicago
June 27: New York
Enterprise Connect 2012 Roundup
Read blog posts and watch videos captured live at the industry's leading event, and catch up on all the post-show analysis too.
Enterprise Connect Webinar
In this webinar, you will learn how to make sense of the array of Hosted PBX offerings and home in on the key elements to look for in an enterprise-grade hosted solution. .
Enterprise Connect Orlando 2013
Enterprise Connect Orlando 2013 takes place March 18-21, 2013 at the Gaylord Palms Hotel. We'll be opening registration shortly. Stay tuned!
Upcoming Events
May 23, 2012
The explosion of new hosted and cloud communications offerings can be confounding. With the potential for cost savings and productivity enhancements, adopting the right Hosted PBX solution can make a ...
May 9, 2012
SIP Trunking and unified communications strategies are important components of enterprise telecommunication strategies. Enterprise Session Border Controllers (E-SBCs) play a critical role in maximizin...
April 25, 2012
Unified Communications (UC) is becoming mainstream in the enterprise, enabling real-time, collaborative communications via a host of new media and applications. But this transition will bring challeng...

Sign up to the No Jitter email newsletters

  • Catch up with the blogs, features and columns from No Jitter, the online community for the IP communications industry. Each Thursday, we'll send you a synopsis of the high-impact articles, podcasts and other material posted to No Jitter that week, with links for quick access.

  • A quick hit of original analysis by the experts who bring you Enterprise Connect, the leading event in Enterprise Communications & Collaboration. Each Wednesday, this enewsletter delivers to your email box a thought-provoking, objective take on the latest news and trends in the industry.

Your email address is required for membership. For details about the user information, please read the UBM Privacy Statement

As an added benefit, would you like to receive relevant 3rd party offers about new products/services and discounted offers via email? Yes

* = Required Field