The report notes that 90 percent of government employee respondents use at least one mobile device – laptop, smartphone, and/or tablet – for work purposes. Many government respondents are taking basic steps to secure agency data. Eighty-six percent lock their computer when away from their desk; additionally, 86 percent have a safe and alternative workplace compatible for work, and 78 percent always store files in a secure location.
Despite these secure actions, government employees are not showing the same caution for mobile devices. They are practicing potentially dangerous behaviors, including the use of public Wi-Fi (31 percent), a lack of multifactor authentication or data encryption (52 percent), and failure to use passwords on mobile devices for work (25 percent).
Even when employees do use a password, nearly one in three admits to using an “easy” password and six percent of those admit to having it written down.
When the appropriate security policies and procedures are in place and enforced, a mobile workforce can be a tremendous asset to a government agency. However, 57 percent of respondents who took the assessment from an agency/enterprise-wide perspective are failing to secure agency data, with gaps in mobile policies and security systems.
Despite the Federal Digital Government Strategy, more than one in four government employees have not received mobile security training from their agencies. Additionally, just 50 percent of respondents noted that their agencies have formal, employee-focused mobile device programs. Half of the agencies that took the assessment are missing fundamental mobile security steps, like utilizing a remote wipe function, or adding multifactor authentication or data encryption on mobile devices.
“In the near future, the number of mobile devices will exceed the world’s population, and by 2017, we expect more than 10 billion connected mobile devices,” said Larry Payne, Cisco vice president, U.S. Federal. “With the proliferation of devices, security continues to be a major concern. The 2014 Mobilometer Tracker study shows that six percent of government employees who use a mobile device for work say they have lost or misplaced their phone. In the average Federal agency, that’s more than 3,500 chances for a security breach. Organizations need to take the necessary steps to protect their data and minimize the risk of data loss.”
Despite shortfalls, government respondents scored considerably safer on the Secure Mobilometer than their private-sector counterparts. What can the private-sector learn?
- Know your workforce: 97 percent of government respondents who telework say they have a formal telework agreement in place versus just 56 percent of private-sector respondents
- Know your devices: 53 percent of government agencies require employees to register mobile devices with the IT department versus just 21 percent of private-sector organizations
- Require training: 53 percent of government agencies require all employees to take regular security training related to mobile devices versus just 13 percent of private-sector organizations
- Minimize risks: in a world where IT leaders must support users’ private devices, security becomes paramount, and 15 percent of government respondents have downloaded a non-work-related app onto the mobile device they use for work versus 60 percent of private-sector respondents.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.