Story image

25% of firms fail to implement multi-factor authentication for BYOD

16 Feb 2018

As employees demand more flexibility in the workplace with the likes of Bring-your-own-device (BYOD), security policies may not be scratch, according to a survey of more than 200 IT and security professionals at the Gartner Symposium conference.

Data protection firm Bitglass conducted the survey as part of its BYOD and Identity research report. It found that 25% of organisations lack some form of multi-factor authentication when securing BYOD.

“Enterprises often misjudge the effectiveness of traditional security solutions, many of which are readily bypassed,” says Bitglass CEO Rich Campagna.

The company says that several high profile data breaches in recent months were caused by compromised passwords that were used to control access, as well as single-factor authentication. Because of challenges like these, organisations have turned to identity management.

“The BYOD boom exposes organisations to risks that can only be mitigated with next-gen, data-centric solutions that secure access,” Campagna continues.

The survey also gained insights about IT professionals’ views on facial recognition technology for secure mobile authentication – Apple Face ID in particular.

60% of respondents had reservations about Apple’s Face ID technology. Those reservations include accuracy of face detection (40%), prevention of unauthorised access (30%) and speed of facial detection (24%).

While passwords, PINS and fingerprint recognition are standard and familiar to enterprises, Bitglass says that facial recognition technologies remain unproven.

Respondents were finally polled about their top security concerns. External sharing was the leading concern (45%), followed by malware protection (40%) and unmanaged device access (40%).

Bitglass says these statistics indicate that organisations are doubling down on protecting data beyond the corporate network.

In another study, Bitglass also shared that 44% of scanned organisations had some form of malware in at least one of their cloud applications.

Microsoft OneDrive was most vulnerable with a 55% infection rate, while Google Drive, Dropbox and Box were not too far behind. 

“Most cloud providers do not provide any malware protection and those that do struggle to detect zero-day threats. Only an AI-based solution that evolves to detect new malware and ransomware can keep cloud data secure,” commented Bitglass VP of product management Mike Schuricht at the time.

“Malware will always be a threat to the enterprise and cloud applications are an increasingly attractive distribution mechanism.”

Earlier this month Bitglass appointed its first Asia Pacific vice president of sales, David Shephard. The company plans to capitalise on demand for cloud and mobile security in the region.

ESET researchers break down latest arsenal of the infamous Sednit group
At the end of August 2018, the Sednit group launched a spear-phishing email campaign, in which it distributed shortened URLs that delivered first-stage Zebrocy components.
Container survey shows adoption accelerating while security concerns remain top of mind
The report features insights from over 500 IT professionals.
Google 'will do better' after G Suite passwords exposed since 2005
Fourteen years is a long time for sensitive information like usernames and passwords to be sitting ducks, unencrypted and at risk of theft and corruption.
Fake apps on Google Play scamming users out of cryptocurrency
Fake cryptocurrency apps on Google Play have been discovered to be phishing and scamming users out of cryptocurrency, according to a new report from ESET.
Hackbusters! Reviewing 90 days of cybersecurity incident response cases
While there are occasionally very advanced new threats, these are massively outnumbered by common-or-garden email fraud, ransomware attacks and well-worn old exploits.
SEGA turns to Palo Alto Networks for cybersecurity protection
When one of the world’s largest video game pioneers wanted to strengthen its IT defences against cyber threats, it started with firewalls and real-time threat intelligence from Palo Alto Networks.
Forrester names Trend Micro Leader in email security
TrendMicro earned the highest score for technology leadership, deployment options and cloud integration.
LogRhythm releases cloud-based SIEM solution
LogRhythm Cloud provides the same feature set and user experience as its on-prem experience.