Corporate or personal device, MDM or application-level protection. Which model works when, and what to do when a device is lost.
A mobile device today is a full working tool: email, documents, the MFA app, often VPN access too. From a security perspective, though, it still sits outside the system in many organisations.
Corporate device, full management. The organisation owns and manages it. The strongest control, but the most expensive, and personal use must be settled.
Personal device, application-level protection. Managing not the device but corporate applications and the data within them. Personal data remains untouched. For most organisations this is the viable path.
Personal device, unmanaged. Web access only, downloads blocked, everything else denied. Where there is no capacity for the first two, this is the minimum.
In practice the second model works best, because it does not meet employee resistance while still addressing the real risk, which is corporate data.
Screen lock and encryption. On modern devices encryption is automatic where a screen lock exists. Without one, there is none.
Separating corporate data. A work profile or containerised applications prevent corporate documents landing in a personal cloud.
Remote wipe. Erasing corporate data from a lost device. On personal devices, selective wipe: the work profile only.
Minimum OS version. Do not permit access from unsupported systems. This is enforceable through conditional access.
Conditional access. Limited access from unmanaged or non-compliant devices: browser-based, without downloads.
This process must exist in writing, because during the first real case nobody will have time to invent it.
Do not force full management onto personal devices. It is legally problematic and employees route around it: they forward mail to a personal account, which is far worse.
Do not forget departures. When someone leaves, wiping corporate data from their personal device is as much part of the process as collecting the laptop.
Do not overlook tablets and smartwatches. If corporate email reaches those too, the same rules apply.
Our IT security services include designing the mobile access architecture.
Comprehensive IT security services including firewalls, WAF, IPS, SIEM, DLP and endpoint protection from…
Why mandatory 90-day rotation is wrong, what the right length rule is, and how to roll out a password…
Modern phishing is no longer given away by bad spelling. Which techniques work, what to teach staff, and…
Our specialists are happy to discuss what this means in your organisation's environment.