November 7, 2016 By Larry Loeb 2 min read

A Smartphone Upgrade Can Be Risky

As the holiday season draws closer, commercial incentives to make a smartphone upgrade grow larger. But business employees may have enterprise data stored on their phones or tablets.

According to a Blancco Technology Group survey, 68 percent of mobile users will purchase a new device during the upcoming season of festivities. Respondents said they were primarily influenced by financial incentives for switching to a new carrier or device manufacturer.

Who Is Responsible?

While 54 percent of respondents believed the original device owner was responsible for erasing data before trading in a device, 21 percent placed that onus on the reseller. Nearly half indicated that data erasure was someone else’s responsibility.

Respondents ranked financial details, Social Security numbers, credit card details, corporate emails and client lists among the most critical types of personal and company data that could be compromised when upgrading or otherwise reselling a device. Still, 72 percent of the survey participants said they had connected to insecure Wi-Fi, and 76 percent used their smartphones to access company networks.

Tweaking BYOD Policies

These findings should influence the way enterprises implement and enforce bring-your-own-device (BYOD) policies. It seems that any mobile device that is routinely used contains corporate data. Organizations must ensure that this data does not fall into the wrong hands, but they aren’t prepared to do so. In fact, 42 percent of those surveyed work for companies that lack visibility into what corporate data is on their smartphones.

Users can’t possibly be sure their older devices will be safe from data thieves, especially considering 32 percent would readily trade in their old phones to their mobile carriers or network operators. Even more concerning, 23 percent would sell their devices to online shopping sites or to retailers that cannot assure data erasure.

Enterprises must have methods in place to deal with this holiday upgrade binge. Companies should inspect any smartphone or device before it is sold to ensure that no company information can be exfiltrated.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today