Categories: Security

One In Ten Companies ‘Have Compromised Devices’

One in ten enterprises have at least one compromised mobile device on their networks, according to a new study, which found that the number of companies with suspect systems grew by 42 percent during the fourth quarter of last year.

The Q4 2015 Mobile Security and Risk Review, based on customer data from corporate mobile management firm MobileIron, also found that attackers are growing more sophisticated in making compromised hardware harder to spot.

Compromised devices

The findings highlight the increasingly complex problem of managing corporate devices, which have proven an effective way to penetrate a company’s network.

“A single compromised device can introduce malware into the corporate network or enable the theft of sensitive corporate data that resides behind the firewall,” said MobileIron Security Labs director Michael Raggo.

“Whether a company loses millions of records or just one record it’s still a breach. For all companies, but particularly ones in highly regulated industries, this is a huge problem.”

MobileIron said its study considers jailbroken or rooted devices – which are easier for attackers to take control of – as compromised. The firm said it had uncovered numerous variants of anti-detection tools that hide the fact that a devices is compromised, creating a “false sense of security”.

Non-compliance

The study also found that more than half of enterprises have at least one non-compliant device, including devices with PIN protection disabled, lost devices or devices that lack up-to-date policies.

“Non-compliant devices create a broader attack surface for malware, exploits, and data theft,” MobileIron stated.

Twenty-two percent of enterprises had users who had disabled PIN access, Mobile Iron said.

Other findings included that less than 10 percent of companies enforce device patching, creating security risks, while more than 95 percent of comanies had no protection against mobile malware.

Security researchers have said attackers are increasingly taking advantage of the relative lack of security protections on mobile devices to take over the units and use them to gain access to corporate networks.

Mobile malware

Earlier this month researchers discovered Android malware that spreads via malicious advertisements found on websites, including pornographic sites, and seeks to take complete control of a targeted device. The “HummingBad” malware was found on the devices of two employees at a major financial services institution, according to IT security firm Check Point.

Researchers have also highlighted that because mobile devices aren’t patched as regularly as full-blown computers, they are relatively easy to attack using known vulnerabilities.

Are you a security pro? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Meta Declines On Heavy AI Spending Plans, Despite Strong Q1

Share price hit after Meta admits heavy AI spending plans, after posting strong first quarter…

14 hours ago

Google Delays Removal Of Third-Party Cookies, Again

For third time Google delays phase-out of third-party Chrome cookies after pushback from industry and…

15 hours ago

Tesla Posts Biggest Revenue Drop Since 2012

Elon Musk firm touts cheaper EV models, as profits slump over 50 percent in the…

16 hours ago

Apple iPhone Q1 Sales In China Fall 19 Percent, Says Counterpoint

Bad news for Tim Cook, as Counterpoint records 19 percent fall in iPhone sales in…

20 hours ago

President Biden Signs TikTok Ban Or Divest Bill Into Law

TikTok pledges to challenge 'unconstitutional' US ban in the courts, after President Joe Biden signs…

21 hours ago