March 20, 2015 By Kevin Olivieri 3 min read

If you notice uncharacteristically low activity and noise levels throughout the office this week, don’t worry. You haven’t mistakenly come into work on a weekend or a surprise holiday — it’s time for March Madness!

The NCAA men’s basketball tournament, one of the most watched and bet-on sporting events of the year, is about to tip off, and enterprise productivity is about to get rejected, with an estimated $1.9 billion lost this year. Due to a partnership between CBS Sports, Turner Sports and the NCAA providing unprecedented levels of access — including the availability of all 67 games online — even more employees than ever (nearly 100 million) are expected to be distracted by March Madness this year.

While the distractions and the significant bandwidth strains associated with following March Madness can damage organizations, there is another more dangerous issue lurking in the crowd that organizations with bring-your-own-device (BYOD) policies and enterprise IT should be particularly wary about: mobile security threats.

Mobile Devices and Malicious Activity During March Madness

A post-event study with IT managers around last year’s March Madness revealed that employees’ personal mobile devices were key players in following the tournament at work. Although there are official ways to securely follow the action, the likelihood that all employees will always use these is low.

Many employees who seek out free, alternative sources to watch the tournament may unknowingly turn to malicious websites and apps on their smartphones and tablets. Malware, phishing and other malicious attacks thrive during popular online events such as the World Cup and March Madness, and a slipup by one employee whose mobile device is connected to corporate data could wreak havoc on an entire organization.

Dangers of a Hard-Line Approach

One way organizations may look to combat the potential issues at hand is by completely banning and blocking anything related to March Madness in the office. While it seems straightforward, this hard-line approach is actually not recommended. Experts point out that it could have a dramatic effect on a company’s bottom line, with disengaged employees lowering the quality and quantity of work output and potentially increasing turnover.

Protecting the Enterprise From Malware Madness

With banishing March Madness from your organization off the table, there are two ways to avoid seeing your enterprise upset by mobile security threats: mobile threat management and user education.

If your organization supports BYOD, it is incredibly important to have an enterprise mobility management solution in place with mobile threat management (MTM) capabilities. MTM can stop mobile threats in your enterprise by detecting, blocking and managing mobile malware and addressing and remediating the concerns before they affect your organization. Having the ability to proactively manage mobile threats in real time is vital to help reduce the risk of sensitive corporate and personal data leaks from malicious March Madness-related cyberattacks.

User education is another effective defense that is absolutely vital at this juncture. IT can use this time to educate employees on the personal and corporate dangers of malware and phishing attacks targeting users seeking March Madness content on mobile devices and how to avoid them. Ignoring unfamiliar links, avoiding unofficial streams and downloading only official apps for the NCAA tournament will go a long way toward curtailing the myriad mobile security risks that could arise.

IT can also take this opportunity to remind employees of the organization’s established BYOD policy for personal mobile device use in the office and what they should do to stay compliant and continue to have secure access to the corporate resources they need to get their jobs done.

A strong combination of MTM and user education can be the difference between watching the upsets take place on the court and experiencing them in the enterprise.

Image Source: Flickr

More from Risk Management

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

How TikTok is reframing cybersecurity efforts

4 min read - You might think of TikTok as the place to go to find out new recipes and laugh at silly videos. And as a cybersecurity professional, TikTok’s potential data security issues are also likely to come to mind. However, in recent years, TikTok has worked to promote cybersecurity through its channels and programs. To highlight its efforts, TikTok celebrated Cybersecurity Month by promoting its cybersecurity focus and sharing cybersecurity TikTok creators.Global Bug Bounty program with HackerOneDuring Cybersecurity Month, the social media…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today