Lost devices is the leading cause of data breaches

By on
Lost devices is the leading cause of data breaches

Lost or stolen mobile devices were the leading cause of data breaches over the last decade for the financial sector.

A Bitglass report found 25.3 percent of data breaches that have occurred since 2006 were due to malicious actors getting their hands on a corporate mobile device. This is well above the 19.2 percent of breaches that were caused by hacking, the 14.1 percent due to unintended disclosures and the 13.1 percent of incidents caused by company insiders.

The report does not disclose how many devices are lost, nor how many of those might end up in the hands of a malicious actor, but the fact that many employees have access to key corporate information means any loss can be catastrophic.

Bitglass product manager Salim Hafid told SCMagazine.com: "This gets at what constitutes a breach - even if a device was lost due to an employee's carelessness, the organization must still disclose that event because there is some chance that the data may fall into the wrong hands. Given the volume of sensitive data accessed by employees on a daily basis, it's inevitable that some will find its way onto devices and that some devices will be lost or stolen."

Bitglass sees part of the solution to this problem as better utilising the cloud. The cloud offers improved infrastructure and application security with teams dedicated to staying several steps ahead of hackers, the report states, which allows sensitive corporate information to be offloaded from devices that can be misplaced or stolen.

Hafid also offered up some additional suggestions.

"The reality is BYOD and access from outside the corporate network are becoming more common, and it's the organization's responsibility to ensure adequate data security is in place. That means limiting access in risky contexts, encrypting data at download, and enforcing some device-centric controls like remote wipe and device passcode locks,” he said.

The report noted that those serving in the financial services sector are not only being singled out for attack, but have already suffered data breaches.

In 2014, 37 data breaches were disclosed in the financial services sector, jumping to 45 in 2014 and almost double to 87 in 2015. And in the first half of 2016 five of the largest 20 banks in the USA have endured a data breach.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Log in

Email:
Password:
  |  Forgot your password?