By Josue LedesmaOrganizations are very different now compared to the last five or 10 years. High-speed internet access and wireless devices has led to bring your own device (BYOD) acceptance becoming the norm. As a result, security organizations are faced with a unique issue they struggle to contain.In this article, we’ll go over what devices infosec departments should have an eye on and how to tackle the challenge of BYOD head-on. For an expert’s perspective, we spoke to Georgia Weidman, founder of Shevirah, a mobile and IoT testing company.Weidman mentions that any security considerations should also be extended to software and technology that’s in place on many of these devices. Not knowing whether an employee has unintentionally installed malicious software or apps on their phones or laptops is another example of poor visibility.She also mentions that additional factors can make it difficult to take inventory effectively. Device details like device type, connection type, software version, operating system, installed apps, whether the device went to another country, and more are all considerations that can affect how a device may bring risk to an organization.If these considerations feel overwhelming, that may be because you’re trying to tackle these problems on a case by case basis. When it comes to device management, Weidman encourages thinking long-term and from a big picture perspective.“We don’t think about [security concerns] well enough or long enough. It’s about the next big thing.”Rather than trying to face each device’s potential vulnerability head-on, it’s much more important to have the right security mindset to be well-equipped to handle potential problems as they arise.
The Problem With BYOD: Lack of Visibility
First, let’s identify the problem with BYOD. Because employees are connecting to an organization with owned laptops, mobile phones, and other wireless devices, security departments don’t have the kind of visibility they would with organization-owned devices.However, Weidman notes that even with org-owned devices, the visibility problem associated with BYOD can still ring true. This is because devices can be issued with full permission and admin capabilities. Weidman explains that this allows employees to potentially install software that could be malicious or engage in risky behavior that could then compromise an organization’s network.A recently exposed vulnerability of Sennheiser’s headset device highlights these potential risks. The headset required users to install a software that was discovered to be exploitable and could lead to Man-in-the-Middle (MITM) attacks. As headphones and headsets are a common office presence, it’s easy to see how this software vulnerability can impact an organization.This isn’t an isolated incident - any device that connects through Wi-Fi, Bluetooth, or requires additional software presents a potential problem for an organization who doesn’t have a way to track that device or prevent unfettered access.Devices Organizations Should Be Aware Of
Weidman highlights how issues with devices have always been a problem for security departments. She recalls how devices like printers were widely reported to have vulnerabilities, often without a patch or an update. Highlights of flaws among other popular devices are also a mainstay at major security events and conferences, turning attention to why visibility and device management is important.As technology improved, the kinds of devices that security organizations should be aware of include:- Mobile phones
- Tablets
- Employee-owned laptops
- Wireless accessories (keyboards, headsets)
- Bluetooth devices (such as smart watches, fitbits)
- Wireless speakers
- Voice-activated devices
- Webcams and conferencing devices
- IoT devices
