Showing posts with label Mobile Security. Show all posts
Showing posts with label Mobile Security. Show all posts

Monday, May 18, 2015

BYOD is dead, long live device independence and proliferation

The advent of smartphones started a small experiment for senior management; it has now become mainstream. Explosion of smartphones in the enterprise driven by economical choices and increasing convenience has seen Progressive IT departments adopting a controlled and open attitude towards providing access to information on the go. Solutions have evolved with app-ification of many processes and business opportunities and Cloud based offerings. BYOD is no longer a 4 letter word, it’s reality for enterprises and CIOs.

Reluctant IT organizations are being pushed and forced into acceptance to define a framework on how to weave BYOD into the company fabric. Reality of yesterday which revolved around unmanaged devices, multiple platforms and form factors, and security of corporate data appear to be excuses now. While the starting point for most enterprises has been MDM or Mobile Device Management, additional solutions are equipping enterprises to create a secure and managed ecosystem for employees and partners.

The next few years will see a shift towards BYOD for most enterprises who are deploying mobility solutions of any kind. This is largely driven by the need to push information to stakeholders though newer use cases are emerging with sales force, distribution and approvals. There is also a pull exerted by various parts of the enterprise who are beginning to realize the time value of information. The challenge is not security anymore, it is managing the upsurge in expectations driven by the fact that someone has already done it somewhere in the world.

Is there a balance between complete freedom to totally restricted world ? There is no formula by size or industry type or even geography that provides a generic universally acceptable answer. Each enterprise will have to find its own equilibrium depending on need and benefit; my belief is that information enabled employees are likely to take better decisions or create newer opportunities in comparison to staff that live with enforced restrictive policies. Wearables open up new opportunities for the savvy technophiles.

The world is getting bipolar with mobility divided into 2 camps – Android and iOS. Stealthily a third alternative is emerging which offers comfort of the known and familiar to IT folks: Windows ! IT knows how to manage this platform while others intrusively came in from the consumer employee. I believe that this trend will be the saviour for IT giving them a platform that they know how to manage. Interestingly new innovation with dual boot devices with Windows and Android are just around the corner.

Some people may ask, what about the Blackberry as a device or platform ? Should we stop thinking about it ? There still are remnants of this in some enterprises. Should they stay in focus ? Predictions have a bad way of turning around and biting you; so if they do offer something critical that others don’t (which I am not sure of unless it is specific to your business), move them off. It is easier to manage one less technology than keeping it lingering around. In the near term I don’t see any merit in continuing with them.

The future belongs to an empowered enterprise where every person has information on demand available on his/her fingertips on a device of his/her choice. Ubiquitous and seamless access activated by secure channels that are MITM (Man In The Middle) and MOTB (Man On The Browser) attack proof; apps are obviating the need to create adaptive websites and compromises in user experience. Enterprises should explore a way to use Apps to provide secure transactional capabilities to employees while running off a public or private cloud.

New devices will continue to challenge IT; drive with policy which is adaptable and allows for induction of new environments. Put them to work in a lab before they start knocking on the door asking for permission to connect. Invest in tools and technology that allow you to manage the devices by exception and policy; that is easier to execute than creating an exception every time something new turns up. You will have limited time and capacity, use it wisely. Finally take a stand if it comes to a crunch; after all when things break only your neck is on the block !

Tuesday, March 26, 2013

The mobility conundrum


Take any event, survey or discussion with a vendor, or pick any IT magazine or newsletter, all of them have something on mobility and integrally linked to that is BYOD. Mobility has prominently featured in the top priorities in every survey. It has become as discussed or more a subject as BITA (Business IT Alignment) was a decade back. There are views and opinions on everything going mobile from business process to commerce from company to consumer and everything in between.

With number of innovative as well as hair brained ideas vying for attention, there is little to choose from for a CIO. Every one of these comes with a theory and hypothesis to change the world or transform the way business is done and information consumed. These range from recognizing your customers to agile delivery of information to senior management or pushing alerts to the sales or distribution teams. The need for instant approvals to various requests is no more a proposition cutting ice.

When I met a consultant from one of the big and respected IT and Management companies, the dialogue soon veered towards what is happening in this space. Everyone is talking about mobility and related challenges of managing the device, security of information and the big issue of non-company owned devices that connect to the corporate network. He went on to postulate that the future holds a lot of pain for the CIO who has to manage the diversity with new devices mushrooming every day.

So I challenged him to illustrate what he has seen of the deployments across companies that he has surveyed or CIOs met. What kind of applications are becoming mainstream ? Beyond sales force automation, reporting and maybe order entry by field staff, are there other use cases that have gained acceptance ? He mentioned insurance agents and banking relationship managers using mobility to sell their services; but these are corporate deployed and largely laptops with limited customer information if at all.

Then, where is the need for mobility ? Are CXOs demanding information on sales or other KPIs real time or by the hour ? Are knowledge workers expecting to carry their work from the desktop/laptop to their tablet or phone ? Is the shop floor crying for a mobile device or a transactional worker like Finance or HR executive expecting work enabled on a mobile device ? What information and process needs the velocity that mobility enables ? And if none need it, then why is mobility a big deal ?

Most mobile devices, managed or unmanaged, are connected to the corporate network for email access and to some extent on collaboration (read messenger or chat). Most organizations stopped supplying phones a while back and very few have procured tablets beyond the sales or field staff. The information the phones carry is corporate email and almost all users have password protected their individual or corporate device. Loss of phone gets the finder mostly an inoperable device which could get unlocked only by luck, rarely by brute force.

Information contained on tablets could have some value to the finder if again access can be gained bypassing the security. MDM or Mobile Device Management solutions are an insurance cover over and above protection that we all enable on our personal devices. A disabled email id or active directory will anyway prevent email and other information sync immediately. Security vendors whipping up paranoia would like you to believe otherwise by painting a grimy picture of revenue and reputation loss.

I am not propagating that enterprises stop looking at mobility or mobile security; what I believe is that review each case on the business value that can be quantified. Do not base your decisions purely on the spread sheets that vendors want you to use for TCO/ROI. Stop following the mobile information security hype and deploy pragmatic solutions; you are not following your competitors to pick up their lost device, likewise your competitors are not following your people around. Take care !

Monday, April 09, 2012

The Hyperconnected Executive


We live in a world of information overload, information thrust at us across all mediums; print, hoardings, building facades, transport buses, taxis, email, SMS, chat, social media, and now multiple mobile devices that wake up and stay with us until we go back to sleep. In bed, while traveling, at work, at home, with friends, in a meeting, relaxing by the beach, even while in the washroom, we are now connected, consuming, creating and contributing information to the ever growing heap.

Information overload was a term I heard long time ago when dial-up internet connectivity was just beginning to get into our homes. Suddenly the world of information opened up; over the years the quantum of information just continued to grow exponentially while technology folks created new terms to encompass the new paradigm. KB to MB took longer than MB to GB did and GB to TB to PB happened in a jiffy. Suddenly it appeared to be more than we wanted. Nostalgically, we did enjoy occasional moments of privacy with sparse cellular coverage, unaffordable handsets and obscenely high tariffs.

So when along with a few CIOs I met a learned senior consultant talking about the disruptive nature of technology innovations, it provoked an interesting debate. He outlined his theory on hyper connected information overload that every executive faces today. He postulated a world of hyper mobility where devices connected or disconnected from people receive information on the go. People consume this information and take decisions that influence business and personal outcomes. Everyone agreed and sought to look at the future. The wise man smiled and refrained from making any predictions.

The phenomenon today is driven by multiple location-aware mobile devices all connected to an ecosystem of corporate data and applications and personal/business social media interlaced with multiple apps. Thus corporate decisions are no longer only dependent on transactional or analysed data within the enterprise. This trend is increasing exponentially with buzz around Big Data which encompasses all the data. It however does not factor in the speed at which information is disseminated to the consumer of information. Are we burning the wires, read wireless, faster than we can process it ?

I do carry 3 devices (almost) everywhere with me; my laptop, my tablet and my smartphone. Across these almost all the information I need on the go is synchronized over the air. They are interchangeable and yet serve different purposes. From one line responses on the phone to approvals, dashboards and longer responses on the tablet, the laptop is still the device for writing posts like this and doing a lot of figure work with formulas or creating presentations. I know many would jump up and say all this is doable on the tablet; I personally find it easier on the laptop.

With divergence being the new convergence, it is certain that we will continue to waddle between screens; a recent study talked about multi-taskers using two or three screens connected to the same desktop computer for enhanced productivity. Really productive ? Velocity of information will continue to increase and our day will continue to shrink. We are doing more everyday thanks to technology. Our world is more productive, our companies more profitable; as individuals we see ourselves evolving faster, achieving goals quicker than we did even a decade ago. Will we ever stop ? I don’t know.

What will be the next disruption in this space ? A connected device to keep us busy while we sleep ?

Monday, May 09, 2011

BYOD Security Paranoia or Necessity

Not too long ago, IT departments faced the challenge of integrating a new consumer device into the corporate infrastructure; this was the iPad which took the fancy of every CXO and techno-affiliate with its cool factor. It did not matter that the tablet was another appendage to do everything that the earlier devices did well enough while ensuring that the information assets of the company stayed protected from nefarious elements. Said the tablet toting executive “I want it; security is for you to go figure”.

The starting point though was the iPhone, which was contained to some extent; the tablet was something different, a wave that swept away all opposition. Developers mushroomed all over creating applications to do everything that mattered and some that did not; IT had no clue what kind of vulnerabilities these created or introduced on the device. Faith in mankind was one of the strategies promoted by many to allow the devices to connect.

In another part of the world, employees went up in arms against the corporate issue compute devices, laptops, desktops, citing their home computers superiority over the standardized and locked devices. Thus the trend started that is now gaining momentum of BYOD, or Bring Your Own Device. It frees up financial resources, support too if the employee fends for herself, no hassles of managing refresh. But what about information on the device ? Confidentiality or sensitivity of information especially when the employee leaves ?

Now extend the same to the mobile, which is lot more like a consumable and gets changed on an average every year, in some cases earlier too. With the space evolving and a multi-polar world of IOS, Android, Symbian, Blackberry and Windows, that too with many versions, the challenges are unique and getting out of hand. In a world where every corporate employee expects all kinds of information on their fingertips (read mobile device), the security framework looks worse than a coarse sieve.

Mobile device security is an evolving subject; vulnerabilities on the mobile are being discovered every day and they are attaining critical proportions with multiple applications vying for attention. In a 24X7 world, the definition of acceptable risk has changed. CIOs are expected to create visibility of the potential compromises and keep the critical information assets secure at all times. The change in the security stance thus creates new challenges and opportunities requiring higher agility to respond. Abstraction of applications and information layers from the device is one of the strategies that helps and many frameworks are emerging in this space. Keep abreast of these developments and experiment before business forces change.

In another couple of years the expectation is that the dependence on the big computer (including laptops) will reduce dramatically; the CXO will carry a few devices (personal, corporate, function specific devices) and all will require management and access to corporate information assets. Start preparing now !

Monday, April 25, 2011

The micro-app nemesis

If you have looked for an app on Apple’s App Store, I am sure you have faced a Google search kind of frustration with hundreds of applications purporting to do the same stuff, one better than the other, or many times just a me too. So some of us end up downloading more than one to try and then decide which one is better; many a times we don’t end up discarding the others. Check around with friends who would have downloaded say an “Alarm Clock” and it is quite likely you will find that their app is different. You may be tempted to download that one too, just to try !

I met a CIO who was showing his angst on the fact that there were more than a dozen applications within his enterprise for travel approvals. While some were a result of “forgotten” acquisition synergies, the others were created by Shadow IT for departments to address short term need. These sustained themselves even after the corporate version was deployed. And now to top it all, almost all of them had mobile versions for different mobile devices thereby multiplying the number of micro-apps that were floating around.

The resulting collection of travel approval micro-apps exceeded a number that crossed the tipping point for the CIO. There was an uneasy silence on the table as she described the chaos and now the support expectations when some of them failed to work with the clamp down or rationalization of applications. Sympathetic nods followed as new governance processes were discussed and general agreement that the actions taken were fair.

Most of the micro-apps on the App Store are written by enthusiasts and programmers wanting to showcase their prowess. They test waters with free apps, and then add features and a tiny charge. Some start-up companies too indulged in similar bunch of apps on the store getting a few hits and lots of misses. How did this suddenly become an industry with 10 billion downloads in such a short span ? Because you can !

The simplicity and ability to create such apps is I guess one of the reasons that contributed to this explosion. Consumerization of the handheld device has given rise to the opportunity that had to be capitalized upon. The slowdown/recession encouraged the blurring of the lines between work and life, while everyone wallowed in the need to stay connected 24X7. The pressure is now on the CIO to stay ahead of the game and deploy even more processes that can be accessed on the mobile. Even if you have already formulated a mobility strategy, review it frequently to stay on top of the situation.

But what about the increasing number of micro-apps that are being downloaded, sanctioned or otherwise ? No one knows what kind of vulnerabilities they create; what will they lead to in the future ? Are they the future support nightmare ? Only time will tell; until then tread cautiously, create the micro-apps required, test the ones you may want to endorse from the store, and pray !

Tuesday, August 24, 2010

Mobile computing and security paranoia

The last few weeks have seen many news and analysis items on the enterprise mobile market leader, a player that made ‘email on the go’ a way of life, in addition to creating sore thumbs and marital discord for many corporate executives. After all these years, now there are growing concerns around national security in many countries around the world, not just corporate data compromise.

A few countries have taken a tough stance banning the service or seeking the key to monitor all traffic. The European Union decided to totally shift away to a popular consumer phone for their state offices with 20K+ users. The phone’s largest users as well as the associated services are worried about whether they will be required to shift away within a short span to another option. They are scared about imagining life without the familiar buzz every few minutes (of another email) and business applications.

Today we cannot think of work life without access to email, corporate applications, sales data and many more on the mobile. These devices have made 24X7 slaves out of their owners. Expectations of instant response to a message (irrespective of the hour) are becoming the norm. This increased productivity is now factored into the workload. Apart from enabling the sales force with planning, reporting and sales data, mobile devices have provided even the typical desk bound executive an ability to stay connected at home. Thus enterprises have seen improvements that were not possible earlier. Suddenly, all this appears to be under threat.

Should the CIO be worried about this looming uncertainty? While a total shutdown is not imminent, restriction in services is a reality. This may extend in the future and cripple the basic functioning of these devices.

To me, the answer is a resounding yes. Country laws and regulations are paramount for every entity operating within the geographical boundaries. There is no circumventing these; so if applications depend on a type of service, they may have to be rewritten or discarded. Alternatives should be explored and options made available, should a switch be required to reduce the adverse impact. This should be discussed with the management and the level of impact (if any), be communicated clearly and explicitly.

With an ever increasing number of mobile devices deployed by the corporate or just connected to the enterprise (employee owned), it’s important to periodically assess and review mobility solutions and options. Work with the service providers to create an insurance policy. No one wants to die, but insurance always makes sense.