Showing posts with label Mobile Device Management. Show all posts
Showing posts with label Mobile Device Management. Show all posts

Monday, 23 September 2013

Mobile Security Best Practices

Mobile devices are quickly surpassing traditional computers for more and more of our needs.  As these functions evolve and expand, and we use our wireless tools to access more information, the security risks multiply.

Most companies let employees use their work devices to access personal information or let them use personal devices to access work information. With the rapid proliferation of mobile devices not slowing down, malware infections are on the rise, growing 163% in 2012. Just like the golden days of Netscape Navigator and those AOL discs in the mail, hackers are more than happy to take advantage of this vast new crop of unprotected devices.

But it’s not only hackers we need to guard against. We need to make sure other scenarios are covered, such as What happens when my phone is lost or stolen? Or, How do I prevent a data breach? And, How can I manage all this stuff?  So with all this in mind, let’s go down the list:


Mobile Device Management

I won’t get into which system is best; this is a growing sector with a wide spectrum of offerings.  What I will say is to find a solution from a reputable vendor, with the features you are looking for, that allows you to effectively manage the devices used at your company. Some features to look for are support for ALL the platforms your employees use, remote locking and wiping, solid app management, connectivity controls (VPN, proxy, mobile data, wifi, etc), easy enrollment, robust security with document protection & encryption options, and integration with your PC management tools.

Authentication

How many of us just slide a finger to the right to unlock our devices?  I’m betting more than half.  Whether you choose a secure pattern, a pin or password, your fingerprint, or your face, make sure you are the only person who can get past your lock screen.  This is the first line of defense when your phone ends up in someone else’s hands.

Remote Location & Wiping

This is most likely a part of your Mobile Device Management solution, but there are plenty of good stand-alone apps that do a great job with this too. When an employee device is lost or stolen, swift action is a must. Sure, using GPS to track down a thief is enticing, but the main focus of IT should be to keep company data secure by locking and/or wiping. This means employees need a fast, easy way to alert IT of the situation, whether it’s a phone number, email address, or secure web page. For some organizations, it might make more sense to put employees in charge of handling the wipe. Whatever the procedure, have a plan in place that everyone can follow in a moment of panic.

Bluetooth & NFC

Turn them off. Unless using a headset or sharing a photo with a friend, these tools are open doors into your devices. Both are hackable with the right tools, and can present real security risks.  Viruses have been found that spread from phone to phone via Bluetooth. So, keep them disabled when not in use, and if your device supports hidden mode, use that too. Some guidelines on using Bluetooth wisely can be found here.

Firewall Policies for Mobile Devices

When devices travel around the city, or the country, they are exposed to all kinds of risks not present in the office. When these same devices return to the office and connect to the company network, they could cause trouble if infected. Setting up separate firewall policies for smartphones and tablets will help mitigate this risk. Most likely, these devices don’t need access to the same data or systems that PCs do, and so they should be blocked. Closing off as many holes as possible is the name of the game, so whitelisting only what’s needed is always better than blacklisting known dangers.

We’ve only skimmed the surface here, but the criteria covered above should serve as a solid starting point to develop a secured mobile workforce. As devices grow in diversity and capability, new variables will enter the equation. As always, keep yourself informed and keep employees informed to keep your company secure.


Want more mobility and workforce productivity

Google Apps is a cloud-based productivity suite that helps you and your team connect and get work done from anywhere on any device.
  • 99.9% up time for reliable constant access
  • Secure data storage and connection
  • Effortless Collaboration
  • Flat-rate Pricing


Luke Reynolds is a new member of Newmind's IT managed services team. Previously he worked with schools, not-for-profits, and businesses to help them acquire and deploy Google Chromebooks on the enterprise level.

Luke Reynolds enjoys writing, music, film, and any form of radical human expression. He's also a rabid proponent of Kalamazoo's local roller derby team, the Killamazoo Derby Darlins.

Monday, 16 September 2013

Managing Mobile Devices - Platform Reviews

It’s a big world out there. Lots of places to go and people to see. Also, lots of places to lose your mobile device and a fair few people who may want to nab it from you. Fortunately, different developers are coming up with solutions that help you protect your device - or at the very least your data.

Droid Does

First to weigh in, Google has released it’s own device manager for Android devices, called Google Apps Device Policy. You can access this tool from any browser by visiting google.com/apps/mydevices. Installing is super easy: just pull up the app from the Play Store (Or scan the QR code that will display from the device manager on your browser). Once it installs, just ‘add device’ from a browser, sync the device, and you’re good to go.


Your domain’s administrator can require that users have a pin or password, set an idle-out screen lock, and wipe the device. Additionally, the device’s user can remotely change their pin, lock their screen, and cause the device to ring out (for those ‘lost in the couch’ scenarios). Also, if the device’s GPS is active, the user can track it.

This tool does require that the domain you sync to is a Google Apps for Business or Education user as well as a minimum system requirement of Android 2.2 or better, but the app’s integration is pretty seamless. However, being an Android-only solution does limit this tool’s usability in a BYOD environment

Up in the Air

Sand Studio’s AirDroid has recently iterated, and what used to be simply a cable-free way to access the data on your phone from a computer, has added many of the tools Google’s Apps Device Policy brings to the table while maintaining all the other goodies that the app has to offer.

AirDroid 2, as it’s labeled on the Apps Store, will do some of the basics that Apps Device Policy will: Remote wipe, remote screen lock, remote password change, GPS tracking, and ring-out a beacon for phone-finding. There is one additional feature that definitely piques interest, however: You can set the device to snap a photo whenever someone fails to enter a proper lock-code and send that photo to you! A very powerful tool.

Unfortunately, AirDroid 2 is not designed with fleet management in mind, and so there isn’t a tool for managing multiple devices from a single dashboard. Though there is always the make-a-big-clumsy-spreadsheet method of doing things.

Meraki-and-Roll

Meraki offers an absolutely free MDM solution that is rather comprehensive. The install is simple enough: Sign up at Meraki.com to access their Systems Manager, pull the app down from either the Apple or Play store, respectively, then plug in the code that the manager console gives you when you ‘add a device’ from your browser.

Once you’re in and have some devices attached you can configure the extensive options. The dashboard give you an overview of all the devices attached to your account. Pulling up each device gives detailed information including: charge status, storage capacity, serial number, IMEI, phone number, data for the network it’s attached to, plus more. Here, you can also clear your passcode, lock your device, erase the whole thing (or target certain data with a selective wipe), ring a beacon, and send a message to display a-la text message.

You can also review any apps installed on the device and, while you can’t remove them, you can restrict the install of new apps, as well as make a whole other list of restrictions including Face-time, screen capturing, Youtube (for iOS), and camera use (both).
You can also require that a user set a passcode, configure WIFI and VPN settings remotely, and push documents from the web by using the ‘backpack’ feature.

To make MDM life easier, the Meraki platform allows you to create different profiles for different user groups, so you don’t have to configure each device separately.

You can also receive email alerts for a host of events, including network enrollment, app installation, or removal of the Meraki app! Remote destop functionality exists, and while not device-agnostic, it does cater to both Apple and Android users.

Decisions, decisions...

Though all 3 of these options share a lot of basic functionality, there are enough differences to really make these MDMs varied and interesting. If your fleet is all Android or Chrome powered, for example, maybe Mobile Apps Policy is the way your org should go. For a true BYOD environment, however, there’s just no beating Meraki’s device-agnostic platform. Then again, the potentially-thief-stopping snap-shot power of AirDroid 2 is not something to be discounted.

I know there are plenty more MDMs on the market and would love to hear what you’re using. Just leave a quick comment below so that others can find it. I’ll pull from your comments and write up another review.


Don't know where to start?! Feeling intimidated?!

Newmind Group will help identify key areas of improvement and manage the project from start-to-finish eliminating your headaches!

Jarad Selner is a new member of Newmind Group's Chromebooks team, working with schools, non-profit groups and businesses to deploy and integrate Google Chrome devices within their organizations.

In his off-time, he can be found booking bands, teaching music lessons, and playing at a variety of venues in and around the great city of Kalamazoo, Mi.

Monday, 2 September 2013

BYOD vs Standardization - SaaS makes it easy

I started this BYOD series to show that the root of this conversation isn't about devices, specifically, but instead business goals. This post, the 3rd installment of the BYOD vs Standardization series, will touch on a few security misconceptions and strategies for becoming device agnostic. If you're not familiar with device standardization head back to the first post of this series, BYOD vs Standardization - Understanding Your Mobile Strategy Pt1. (Understanding the various device policy models can give insight into how to implement what this post will discuss, so check out part 2, BYOD to COPE: The Mobility Spectrum.

What is driving the mobile device discussion?

Without going into specifics of device policies and standardization, the reason for this discussion is productivity & mobility. Businesses want their employees to be productive and employees want to be mobile - use new technology that affords them new freedoms, like the ability to work where and when they can be most productive. A $2 cup of coffee is now a passport to internet connection, productivity, and better business - not to mention work-life balance.

Mobile Security Misconceptions

We've talked about business data security before. Stories about malware and hackers, like the Syrian Electronic Army hacking the NYTimes and Twitter websites, are everywhere and concentrate on the hackers. This sensationalism minimizes the root cause of the hack - HUMAN ERROR. The reason hackers in Syria were able to access these prominent websites was due to a lack of security protocols addressing human action in providing security credentials.

According to Financial Review, "The incursion was traced to India-based perpetrators who fooled staff at a US-based reseller of Melbourne IT ­services into handing over personal details and, as a result, the login and passwords which allowed someone to access and change key details for the websites."

Firewalls, anti-malware, double authentication, etc, would not have helped the NYTimes or Twitter avoid this intrusion, as the hackers had legitimate login credentials. One might want to move data to self-managed servers, implement extreme security measures that require access to particular network to gain access, etc. Is this really the answer?

Concentrating on network best practices and on policies that promote responsible actions by your employees are the better and so is allowing Software as a Service (SaaS) providers do what they do best.

SaaS vs Self-Managed

SaaS providers are specialists, not only in their software, but in storing the data they work with. The data passed through their systems are their "bread-and-butter" and securing it is in their best interest. So much so that many SaaS providers have their data stored in SSAE16 data centers (audited by 3rd parties), have implemented biometric safe-gaurds, 24/7 staffed security and foot patrols, environmental controls, advanced firewalls, backups & redundancies.

I know what you're thinking - "I can do that." True, but are you going to be as good at it while still being great at running your business?

Benefits of SaaS

Now that we've established it’s better to let a service provider be the expert of a solution, letting you be the expert of running your business, what are the benefits you can realize by going SaaS?
  • Low cost for multiple device support
    SaaS platforms are looking to gain a broad user base and therefore build their platforms to run on most, if not all, popular platforms, browsers, operating systems, etc.
  • No Cost Updates
    SaaS providers strive to stay relevant as new devices and platforms are released and will continue to update their platform so that your employees can access business data, with no update costs to your company.
  • Zero Tech Debt
    Your company doesn't have to worry about maintaining a server, upgrading it, being relegated to outdated software
  • True mobility
    The fact that (good) SaaS platforms are accessible by any device and any platform means that your employees have access anywhere, anytime - staying productive! Check out What's going on at Greenleaf Hospitality since they migrated over to Google Apps.

    Downsides to SaaS

    Let's keep this objective and be sure to touch on some downsides to SaaS:
    • Lack of update control
      While the exact roadmap of platform updates is out of your control, most SaaS providers have a community where their user base can influence or suggest new features and development. Let's face it, letting them deal with staffing a large developer team is saving you hundreds of thousands a year. Not to mention they'll roll out with updates faster.
    • Requires reliable web connection
      Putting your data in the "cloud", as it were, means that for your employees to be productive you'll need consistent reliable internet uptime and access. As most business is conducted online anyway, I'm pretty sure this one is covered. If your employees want to be mobile and work off-site, they probably already know how to find reliable connections.

      Where to Start!?

      Rolling out SaaS to every aspect of the company isn't realistic. Look to smaller sections or units of your business or department where data is database driven, requires network connections, and can be easily searched/filtered/queried. Look at some of these SaaS platforms to improve your operations:
      • Project/process management - Podio, Trello, Basecamp
      • Email - Gmail/Google Apps
      • Document Collaboration - Drive/Google Apps
      • Accounting - Freshbooks
      • Marketing/Sales - Mailchimp, Marketo, CRM software, Streak, etc.
      Many of these solutions have free versions or trial periods to help you evaluate usefulness, efficiency and implementation strategies.

      Capitalize on efficiencies of scale, by moving to a SaaS provider and give your employees the freedom of mobility and increase productivity.


      Don't know where to start?! Feeling intimidated?!

      Newmind Group will help identify key areas of improvement and manage the project from start-to-finish eliminating your headaches!

      Daniel Proczko has been working with organizations and individuals to build & grow the entrepreneur community of Kalamazoo, MI. From organizing TEDx events, hack-a-thons, and documentary screenings to engaging with business leaders, Dan strives to inspire individuals with new ideas and better thinking.

      Having always been interested in tech and understanding the value of innovation through IT, communicating the importance of strategic IT thinking is one of Dan's primary goals within Newmind Group.

      Monday, 12 August 2013

      BYOD to COPE: The Mobility Spectrum

      This is part 2 of our look at mobile policy strategy and the great mobility debate. Be sure to read the first post, "BYOD vs Standardization - Understanding Your Mobile Strategy," to explore device standardization.


      Environment & History

      Look around the office of 10 years ago, and you’d probably find basically the same place as today. Sure, we have better computers now, but those are basically the same boxes as before.  So, in terms of tech, what’s changed?  For that answer we need to look in our pockets.

      10 years ago, if you needed your work email on the go, you got a Blackberry.  Spreadsheets Presentations?  ThinkPad.  Fast forward to now, and you probably have a device in your pocket that an do all of that, and faster.  Wireless devices - whether phone, tablet, laptop, or any of the hybrids in between - have become indispensable at work.


      So how to balance the needs of a mobile business community with security concerns, financial overheads & employee morale?  If we imagine the different possible configurations on a graph, it might look something like this:

      What are my Mobile device policy Options?

      With BYOD (Bring Your Own Device), the risks of unmanaged devices accessing and housing company data are mitigated by IT implementing management controls.  When this happens on an employee’s device, it can negate the freedoms BYOD is championed for.    The amount of employee satisfaction drops sharply, due to feelings of being hijacked.  When implementing BYOD try not to mandate controls on the devices, but instead look to create data access controls. This will keep morale up and also productivity.

      Using the COPE (Corporate-Owned Personally-Enabled) model, the sweet spot for installing management software and controls is larger.  Since the device (and mobile plan) is paid for by the company, and since employees can customize it to their liking,  most workers are more apt to graciously allow a moderate level of company management without that nagging feeling of being boxed in or watched over.

      Further options

      You’re not relegated to BYOD or COPE.  There are a plethora of other options you can explore them and find the best fit for your culture.  Here are a few:

      • CYOD (Choose Your Own Device)
        A liberated form of standardization, employees select a device from an approved list
      • CLEO (Corporate Liable, Employee Owned)
        Reverse BYOD, where employee owns hardware and company pays for service
      • BYOC (Bring Your Own Cloud)
        Not a mobility policy itself, but can be used to augment an existing setup


      Criteria for Deciding

      All the above are really different configurations to the same end: accessing data ubiquitously. Company culture and data access needs will be major factors in deciding how to form a mobile policy.  Here are some points to consider when shaping yours.

      • What platforms can your IT staff support?
      • What level of data mobility does each employee group need (CRM, financial, legal, procedural, everything)?
      • What security requirements do you have for each type of data?
      • How valuable is data ubiquity to your workers?
      • How important is device freedom to your company culture?


      Beyond these, there are bound to be company-specific criteria you’ll need to consider as well.  The best answer may end up being a full commitment for a specific model, or you may find choosing different models for different employee groups makes the most sense.  The point is to select the plan that best conforms to you.

      Conclusion

      As we all move forward into this tech-rich future, there will be new devices that again change the standard business paradigm.  To get the most out of these nascent capabilities, remaining aware of the full spectrum of options and how others are implementing them will be key to a future-ready company.

      Part 3 of this series can be found here, "BYOD vs Standardization - SaaS makes it easy"




      Luke Reynolds is a new member of Newmind's IT managed services team. Previously he worked with schools, not-for-profits, and businesses to help them acquire and deploy Google Chromebooks on the enterprise level.

      Luke Reynolds enjoys writing, music, film, and any form of radical human expression. He's also a rabid proponent of Kalamazoo's local roller derby team, the Killamazoo Derby Darlins.

      Monday, 22 July 2013

      BYOD vs Standardization - Understanding Your Mobile Strategy Pt1

      Mobile devices, collaboration & mobility, seem to be a hot topic recently. In just about everyone’s pocket is a device that gives them instant access to the Internet. A Nielsen study recently found that “66% of Americans 24-35 now own a smartphone.” With so many users owning their own mobile devices and bringing them to the workplace, its not surprising that IT departments and employees are clashing over ownership, data access and privacy.

      Misconceptions

      Employees aren’t waiting for IT & management approval to bring their devices to work. According to a CTIA study, “60 percent of IT professionals believe 25 percent or less of their employees are accessing work related information on their smartphone or tablet, while 57% of users said they access work related information on their smartphone or tablet at least once a week.” This may be why “smaller companies, with fewer than 500 employees, are less likely to communicate to their employees about BYOD and security.” Misconceptions about the workforce drive IT departments to prioritize the importance of strict mobile device policies, defaulting to device standardization. Standardization circumvents the grey areas of privacy and personal property, but comes with its own pitfalls.


      Range of Device Standardization

      Where does your organization currently stand?
      Where do you want to be?
      High device standardization
      requires that everyone use the same type of PC (laptop vs desktop, Apple vs Microsoft vs Linux vs Unix), the same mobile phone (iPhone vs Android) even so far as to require the same model and software version (iPhone 4S or HTC ONE running Android v 4.1.2). This level of rigidity allows IT departments to specialize in a few devices and provide deeper levels of support, internally developing business operation platforms to obtain competitive advantage. High device standardization carries high device purchase costs and high technological debt, causing some enterprises to run outdated software.

      Low (or zero) device standardization, BYOD, is essentially the exact opposite. Employees are able to use any device they like, creating an atmosphere that may have over 15 different types of devices, from different manufacturers, running different versions of software. This makes it difficult for IT employees to cultivate a high degree of proficiency in every device. Although IT staff may not be experts in all device types in an organization, this atmosphere opens the door for employees to create user groups and organize genius bars. The most important aspect of low device standardization is the high accessibility of data, which leads to greater gains and efficiencies, that we’ll explore in a later article of this series.

      The Tipping Point is Mobility & Collaboration

      As you’ve probably deduced, the conversation isn’t BYOD vs Standardization, but instead understanding the culture & needs of your workforce. If a high degree of mobility & collaboration is needed, then your data will need higher accessibility via more devices.

      The goal is not to decide for your organization what level of mobility & accessibility is needed, but rather allow the organization and its members to dictate the level they require. Here are a few questions to help start to evaluate your organizational situation:

      • Does your organization have employees spread geographically? 
      • Is there a specific type of device the members of your organization already lean toward? 
      • Do the software platforms and data formats in use require a particular device or platform for access?

      Use the questions above, and form other questions, targeting value-driving processes within your organization to gather data about your company’s environment & attitudes toward personal devices & data access. Use those insights to create a BYOD & mobile device policy and IT data access strategy that will be easier and more positively viewed by your workforce.

      In the next installment of this series, “BYOD to COPE: The Mobility Spectrum

      Daniel Proczko has been working with organizations and individuals to build & grow the entrepreneur community of Kalamazoo, MI. From organizing TEDx events, hack-a-thons, and documentary screenings to engaging with business leaders, Dan strives to inspire individuals with new ideas and better thinking.

      Having always been interested in tech and understanding the value of innovation through IT, communicating the importance of strategic IT thinking is one of Dan's primary goals within Newmind Group.

      Thursday, 16 May 2013

      4 Simple Steps to an Effective BYOD & Mobile Policy

      There is building momentum toward creating a connected & mobile workforce. This trend requires business data access through personal mobile devices. News headlines of leaked business-critical data, financial statements, corporate espionage, hacked corporate accounts, corrupted data flash across your eyes. BYOD & mobile devices won’t end in catastrophe or cause friction within your organization, but will require some change management and a mobile policy and some Mobile Device Management (MDM).

      We took some time to chat with some IT directors and found some research showing that,
      • 60 percent of IT professionals believe 25 percent or less of their employees are accessing work related information on their smartphone or tablet.
      • 57 percent of users said they access work related information on their smartphone or tablet at least once a week.

      It became clear that a BYOD/mobile policy is becoming a necessity and should have the following elements:


      1. Set of expectations that align with your organization’s goals 
      2. Clear and plain language 
      3. Concise, so that everyone reads it 
      4. Tools to enforce (Mobile Device Management)

      Mobile Expectations

      You want the most out of all of your employees and the best way to do that is to let them know exactly what you expect. Many employees are not privy to the overarching strategy of an organization and feel that their efforts are lost in the shuffle, as are their desires and need for work-life balance. Explaining how mobile devices fit into the corporate culture and goals of the organization will provide guidelines for their use within day-to-day operations. Your employees will appreciate being allowed to stay connected to their families and personal lives.

      Clear and Plain Language

      “Thou shall not pass”, Gandalf can get away with such words, but a mobile policy that is going to be understood should be written with plain English and not legalese. When was the last time you actually read the user agreement license on a new piece of software? (Well, you’re the head of IT, so probably always, but the majority of employees won’t.) So keep the language simple and clear. Using normal conversational vernacular will suffice.

      Concise

      One of our favorite mottos is KISS “Keep It Simple Stupid”. A mobile policy over 2 pages is probably pushing it. Remember, this is a document that should be a guideline for usage, not document every possible scenario (which is impossible, because that time the rhino came into the company bathroom to use their cell phone for a personal call, was not foreseeable...and not true, but you get the picture). Also, 11pt font single spaced makes our eyes cross and causes vertigo (not really, but it is hard to read) and we want everyone to read the new policy. If the entire policy can fit on a single page, great. If not, don’t go over 2 pages. We all have work to do.

      What Not To Include

      Policies already sound like a proverbial “ball and chain” and when approaching it employees will cringe thinking that management is going to restrict usage again or impose some arcane security requirement, or ban use all-together. When approaching your mobile policy, do not include the security policy or write an entirely new one. You’ve already got one and to keep it easy all you have to do is make sure the policy fits within it.

      Mobile Device Management Tools

      Sometimes its not enough to just have a policy; you want to sleep more soundly. Finding the right tool can be hard. You want to improve productivity, but you do want to keep data safe while keeping up morale. When evaluating an MDM be sure that it covers all types of devices, Mac PC, Android iOS, etc, provides network analysis, scales with your business, supports BYOD (if you’re not supplying mobile devices), links ties in with business reporting, and supports content management.

      Newmind Group device management clients benefit from these features, but if you're not ready to make the jump to such a robust tool, try the lighter Meraki Mobile Device Management platform. It will monitor multiple device types, from iPads and Androids to Macs and PCs, and even monitor recent locations, and allow administrators to lock and erase devices, among other great features.
      Meraki Mobile Device Management device list and connectivity.

      Those are just 2 of the many tools available to help make your workforce mobile, collaborative, productive and secure.

      Now go forth and create your mobile & BYOD policies. Remember to keep them short & clear, with easy to digest expectations that fit within your current security policy and you’ll be one step closer to a more connected & efficient workforce.