BYOD - Bring Your Own Device Security

BYOD - Bring Your Own Device

By Paul Rummery, Securenet Consulting

...the threat landscape is vast. Attackers will exploit vulnerabilities from a number of sources across your infrastructure. Here are some useful tips on where to plug the gaps.



The truth is that something as simple as the use of an unmanaged USB stick or the installation of an infected Facebook widget could put an entire organisation’s data stores at risk. Many risks raise from devices not being properly patched and then accessing websites with malicious content. Organisations need to be able to not only develop policies; they also have to implement the necessary technology to support them and train all employees about why the rules are so important.

SecureNet Consulting offers a 4 step process; 
1) Document business policies
2) Identify risks 
3) Implement technologies to protect your assets, enforce the policies on devices before they connect to the network 
4) User Education.

Preparing for Cyber-threats

* Unauthorised Access
* Web Application Vulnerability
* OS and virtual machine Vulnerabilities
* Endpoint and network attacks Data Leakage




Identity and Access Policies

There is a need to monitor user data and resource access, even the activities of everyone who has privileged levels of access to the organisation's systems and data in order to discover internal threats. System, database, network and user administrators have privileged levels of access to systems and data. Outsourcers and other service providers may also have this level of access. There is the potential for availability and security risk due to unauthorised system changes. There are also risks associated with inappropriate data access by privileged users. A targeted attack might succeed in compromising a privileged account, which could then be used to directly gain access to critical or sensitive data.

Data Access Monitoring

Because the ultimate goal of many targeted attacks is the theft of data, it makes sense to apply security monitoring to data access. Data loss prevention (DLP) technology provides a means for organisations to identify sensitive data and monitor its access and movement. Integration of DLP alerts into the SIEM would provide data context to security monitoring.

Application Activity Monitoring

The application layer is a popular attack path for a number of reasons. Web application vulnerabilities can be discovered and exploited from the outside, and the vulnerabilities tend to exist for a long time (due to long remediation cycles). Application credentials are easy to steal from users that are victims of spear phishing attacks or from users that access corporate applications from unmanaged (and corrupted) privately owned devices.


SIEM - Security Information & Event Management

Manage risk and compliance across the enterprise even for hybrid cloud environments, helps businesses to reduce loss, improve decision-making about resource allocation...not to mention ensuring you are compliant before your audit is due. SIEM tools are powerful reporting systems, that pool data from individual hardware and software systems, contextualise the information to address compliance and management questions. Without such tools, these individual systems require a lot of human resource time in compiling and contextualising data into meaningful business and management information, whilst all the while vulnerabilities go unchecked and unprotected.

SecureNet provide assessment services to report vulnerabilities across your network infrastructure (cloud, web applications, network gateway, core systems, mobile users and end points). We can then advise and provide technical expertise to remediate known issues based on your existing technology and recommend any further solutions you may need, available in the market, designed to mitigate unknown threats, alert and action on suspicious behaviours.




We provide solutions to meet customers requirements, meet compliance and cover evolving threats - we assess your unique environment and present options so you only buy what you need. Clients include major banks, government, intelligence and law enforcement organisations – you don't get a client endorsement better than that.

These solutions systems are scalable, secure hardened Linux platforms which in themselves do not need patching like a number of Windows based options.