All Posts By

Doug

What is Mobile Device Management?

By | Uncategorized

Mobile Device Management, or MDM for short, is a software product or service designed to simplify and enhance the management of mobile devices. In this post we’ll dig deeper into the devices, the management capabilities, and benefits of MDM and things you should consider when evaluating options.

Then we hear the term “mobile” it’s natural we think of our iPhone or Samsung. However, in the context of MDM, a mobile device is a general term for any type of handheld computer. In addition to smartphones, this designation includes: laptops, tablets, 2-in-1s, wearables, and notebook computers. These devices are collectively referred to as endpoints with names like MacBook, iPad, iPhone, Samsung Galaxy, Galaxy Tab, ThinkPad, Chromebook, Surface, Miix, iWatch, Galaxy Watch, and others. Some MDM solutions are designed for industry specific devices such as point of sale (POS), printers, and barcode scanners. Under MDM, these devices are managed by software installed on the device itself which is referred to as the client component. This software receives and executes commands which are sent by the server component acting as a centralized dashboard or portal.

MDM solutions allow company IT Administrator’s the ability to configure, control, secure and enforce policies on mobile devices without hassle and complexity. Considering security is a hot topic these days, let’s focus on a few of the security benefits of MDM. Do you or anyone you know read company emails from a mobile device? How about viewing company files from a mobile device? If you answered yes to either question, how do you know your company data is secure? What could happen if the device fell into the wrong hands? What if the device didn’t require a pin? Some of the security aspects of MDM include password enforcement, remote lock and remote wipe. Password enforcement gives you piece of mind to know the device has some security measures in place and if lost the device can be locked and even wiped clean remotely. These are just a few of the many features and benefits of MDM, others include: device setup, compliance, policy acceptance, tracking, application catalogue, mitigate roaming, policy enforcement, corporate wipe, and inventory.

There are many MDM solutions available and surprise, they don’t all include the same features. Here are a few important things to consider when evaluating MDM solutions: That it supports your devices both the operating systems and versions. The features most important to you and your business are part of the solution. Pricing; is it per device or per user and is there additional cost for support, maintenance and updates? Do they offer a trial period.

Next up: What is XaaS?

Click here for our previous post, “What is a pen test?”

What is a pen test?

By | Blog

A pen test, short for penetration testing, is a simulated cyber-attack on a company’s network performed to identify any potential vulnerabilities and exploit them. It is performed manually by a highly skilled security professional using various tools, techniques and processes to simulate the extent of what could happen under a real attack.

To explain it differently, think about checking if your house front door is locked. If it isn’t, you enter and rummage around seeing what you can take and the extent of damage you can cause. In finding the front door unlocked you have identified a vulnerability and by entering to find personal assets and sensitive information you have exploited it. This is in essence what a pen test performs except obviously the front door is the access to your company’s network and at risk is your data and customer information.

Why have a pen test performed?

Most company networks are designed, built, and maintained by employees that have little to no professional experience in security. Having a pen test performed provides you with a report highlighting points of weakness, the extent of damage that could be caused and a roadmap for security remediation. This resulting report can give you the opportunity to address any issues before they have been exploited by a criminal and peace of mind knowing your “front door” is secure.

Beyond peace of mind, if your business is required to comply with standards, for example HIPAA for healthcare or PCI-DSS for credit card processing, you may have a requirement for a risk analysis to be conducted periodically. A great way to perform this risk analysis is through a combination of a vulnerability scan and pen testing.

Things to consider

  • Pen testing is best conducted by a third-party vendor rather than your internal staff to provide an objective review of the network environment and avoid any conflicts of interest.
  • Pen testing is costly compared to a vulnerability scan for a few reasons. One main factor is a vulnerability scan is automated while a pen test is performed manually by an experienced security professional.
  • To keep cost down, don’t spending a lot of money on low-risk assets that may take several days to exploit.
  • Unlike a vulnerability scan, it is recommended that a pen test be performed once or twice a year.

Next up: What is Mobile Device Management (MDM)

Click here for our previous post, “What is a vulnerability scan”

Here are some items you should discuss when talking about performing a pen test. No need to read further unless you are seriously considering taking

  • What computer assets are in scope for the test?
  • Does it include all computers, just a certain application or service, certain OS platforms, or mobile devices and cloud services?
  • Does the scope include just a certain type of computer asset, such as web servers, SQL servers, all computers at a host OS level, and are network devices included?
  • Can the pen testing include automated vulnerability scanning?
  • Is social engineering allowed, and if so, what methods?
  • What dates will pen testing be allowed on?
  • Are there any days or hours when penetration testing should not be tried (to avoid any unintentional outages or service interruptions)?
  • Should testers try their best to avoid causing service interruptions or is causing any sort of problem a real attacker can do, including service interruptions, a crucial part of the test?
  • Will the penetration testing be blackbox (meaning the pen tester has little to no internal details of the involved systems or applications) or whitebox (meaning they have internal knowledge of the attacked systems, possibly up and involving relevant source code)?
  • Will computer security defenders be told about the pen test or will part of the test be to see if the defenders notice?
  • Should the professional attackers try to break-in without being detected by the defenders or should they use normal methods that real intruders might use to see if it sets off existing detection and prevention defenses?

DOES YOUR COMPANY HAVE A BACKUP PLAN?

By | News
Does your company have a backup plan to keep operations from falling apart in an emergency?
A business emergency is one of those things you never want to think about – until you have to. Weather emergencies. Natural disasters. The loss of a revenue stream.
A healthy fear is a strong motivator for many business owners to take action and protect both their businesses and their team.https://elbo.in/NEze

IoT DISRUPTION HAS BEGUN. WHEN WILL YOUR COMPANY BE AFFECTED?

By | News
IoT disruption has begun and retail is just the start. When will your company be affected?
We consumers live in a connected world, so the companies we deal with have good reason to live in that world with us.
#IoT connectivity will soon become the standard across the finance, healthcare, and automotive industries. Here’s how your business will be affected. https://elbo.in/s5US

PROTECT YOURSELF FROM A CYBERATTACK THIS HOLIDAY SEASON

By | News
Most people worry about online shopping scams, but few take active steps to protect themselves.
Online shopping dominated this past Black Friday, and Cyber Monday became the single biggest sales day in U.S. history, pulling in $7.9 billion.
No question about it: we are addicted to shopping while sitting on the couch. Here’s what you can do to protect yourself from a cyber attack this holiday season. https://elbo.in/sQ98