Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint //

Privacy

9/26/2017
10:30 AM
Niko Keller
Niko Keller
Commentary
50%
50%

Why Your Business Must Care about Privacy

It might not have something to hide, but it definitely has something to protect.

The current conversation often pits privacy against security, both in consumer and enterprise settings. This is especially true in the debate over whether mobile encryption is essential for the average user. However, not wanting to have personal information shared, acted on, or used by anyone without permission should be seen as a universal right.

Why? Because today, being proactive about privacy is no longer about trying to hide from authorities. Privacy plays into a much bigger picture; it goes hand-in-hand with security and protecting you, as well as everyone in your personal and professional life, from potentially being exposed by increasing cyberthreats.

Privacy & Security Standards on Mobile? There Aren't Any
Although consumers have a much better understanding of today's online threats, awareness of how vulnerable and exposed mobile devices are to cyber attacks, breaches, and unwanted spying is still extremely low. This is primarily driven by the misconception that the services and applications available on mobile devices today are secure and private. However, as has been shown by several major data leaks this year (such as with Docs.com), this is not the case.

The unfortunate truth is that organizations can choose to invest in as little or as much security as they want. They also have complete control over privacy options. For example, as part of Pokémon Go's user policy, users give an increased amount of privileges and some legal rights if they don't "opt out" of the legal waiver in writing. The opt-out process is valid only if exercised within 30 days following the date a user first accepts the app's terms and conditions. Users who installed the app gave Nintendo the right to access all of their contact addresses and even send emails on their behalf.

Moreover, many companies and app developers today deprioritize security over other functionality. That's because in today's fast-moving technology ecosystem, the ROI for security isn't perceived to be there. Security also takes time, ongoing investment, and resources.

Why Privacy Needs to Matter to Businesses
Because of the relaxed security and privacy standards across mobile applications and services, the mobile ecosystem has slowly become a stomping ground for cybercriminals.

Today, there are many different ways cybercriminals can launch an attack to breach sensitive information and gain access to credentials, be it attacking through a vulnerable cloud service, WiFi network, malicious apps, SMS phishing, email attack, or social media network. The problem continues to grow worse. In 2016, 8.5 million mobile malware attacks were discovered, which was a threefold increase over 2015.

Although research suggests that consumers have a better understanding of the threats on mobile devices today, the landscape is rapidly evolving. Cybercriminals increasingly are opting to target human vulnerabilities over technical exploits because of the huge success rate. With the bring-your-own-device trend, this makes mobile security and privacy critical for a business’s safety today. Although an organization may not necessarily have the information it needs to hide, it does have things it needs to protect, including data and employees. If steps aren't taken to address the social and technical threats that employees face today, the risk of corporate information being exposed via an employee's phone is near certain.

In addition, organizations must understand that a 360-degree approach is needed to address mobile security. Businesses not only need to adopt advanced technologies but also make education a critical piece of their strategy. Given mobile phones are foremost a consumer problem, employees need education about how their personal mobile phone behaviors could lead to a major company breach. 

Related Content:

 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Niko Keller, is the co-founder and CTO of Opaque Communications and is responsible for implementing and otherwise directing the company's technology innovation and product road map. With more than 20+ years of global experience in business intelligence, security strategy, and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
saraluck9090
50%
50%
saraluck9090,
User Rank: Apprentice
6/1/2018 | 1:18:56 AM
Business need much care about privacy.
When you're sitting in front of your computer at home, it's easy to feel safe while surfing the Internet. Focusing on privacy protection is vital in protecting your personal data both online and off. So, keep your personal information private. In many cases, consumers are happy to share information like photos, opinions and locations they are more protective.Safeguarding customer privacy is more than a protective measure; so its adminitration responsibility to takecare of private policy of online business. https://www.reecoupons.com/categories/online-services
Synergy360
50%
50%
Synergy360,
User Rank: Apprentice
9/29/2017 | 12:04:55 AM
Business Security
Well Said! There is nothing to hide but there must be something to protect. Businesses must protect their crucial data from unauthorized access. For IT and Business Consulting, refer Synergy 360 Consulting. Here is the site: https://synergy360.com.au
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...