Welcome!

Cloud Security Authors: Craig Lowell, Pat Romanski, Shelly Palmer, Ed Featherston, Elizabeth White

Related Topics: Cloud Security, Mobile IoT, Microservices Expo, IoT User Interface, Agile Computing, Wearables

Cloud Security: Article

How to Re-imagine Your Business for a Mobile World

And keep your data safe while doing it

There is little argument at this point that the mass adoption of mobile technology and bring-your-own-device (BYOD) strategies by enterprises is a true business technology revolution. At the core, the catalysts driving this revolution are the vast array of mobile devices leveraging soaring bandwidth - 4G - and super-fast internals - quad-core processors - which have become commonplace.

With this high-bandwidth, ultra-capable combination, end users see the productivity and convenience possible by running the newest, most sophisticated business applications on their own personal mobile devices.

And it's not just end users who can benefit. A recent Symantec survey found that innovative companies - early technology adopters, especially of mobile technology - are seeing significantly higher revenue growth and higher profits than traditional organizations; in fact, by nearly 50 percent.

The question facing every enterprise is, "Are we re-imagining our business with mobility as a central component?" Here are some suggestions on how to accomplish this, while keeping sensitive business data secure.

Evaluate App and Data Needs
The previously mentioned Symantec survey found that 84 percent of those successful, innovative companies are proactively adapting their businesses based on business drivers rather than simply reacting to user demand. So, companies need to evaluate. Thus, the first step in re-imagining business in a mobile world is to determine the apps and data end users could utilize - beyond email - to get their jobs done more efficiently.

App Type
Apps for CRM, e-Health and ERP are just a few good examples of line-of-business apps companies in different industries can leverage to improve productivity through mobility. Add to this list cloud-based file storage apps that give users access to their data across computing platforms.

Data Access
Beyond app type, companies must take a closer look at target user groups to determine each segment's specific data access needs. Some users might need resident data on their devices, while others who are likely to have connectivity all the time can manage with cloud-based data. Understanding each group's specific needs will help determine the type of technology approaches possible.

App Procurement
Once app type and data access requirements are well understood, companies need to explore app procurement. For some, the only way to get exactly what is needed is to build a custom app or have one built for them. However, hundreds of thousands of apps are already available for the most popular mobile operating systems and, in many instances, the perfect app likely already exists.

Keep App and Data Security Top of Mind
The Symantec survey referenced earlier also found that the innovative companies who are leading the way in mobility adoption also experience about twice as many mobile security-related incidents, such as loss of corporate data. This leads to a second question enterprises must ask, "How do we keep our sensitive data safe in a mobile world?"

From a high level, there are really two approaches to keeping business data on mobile devices secure. The first is protecting data at the device level and the second is protecting it at the app level.

Device Level Data Protection
Data protection on mobile devices at the device level largely involves mobile device management (MDM) software. MDM provides business IT with control over complete devices and, as such, policies can ensure devices are password-protected and also provide the ability to remotely lock or wipe devices in the event of a loss or theft and even prevent the forwarding of emails.

However, MDM cannot address other data loss-related concerns such as copy and pasting of sensitive information or, more important, protecting corporate data in applications beyond the email client.

Thus, the device level approach creates an environment where it becomes far too easy for sensitive data to mingle with personal apps and leak out through, for example, a web-based email account, social networking application or personal cloud storage. This can all occur without IT ever knowing.

App Level Data Protection
The next logical area where enterprises can implement and enforce policies to keep data on mobile devices secure is at the app level. The previous iterations of this approach involved sandboxing technologies, where corporate data on mobile devices is held in an established digital container on devices, and data flow from the sandbox or container is controlled. This approach prevents the confluence of personal and corporate data, the ability to copy and paste data accessed from within the sandbox to other areas on the device, and unauthorized email forwards from within the sandbox.

This sandbox approach worked well when email was the only app businesses wanted to mobilize. However, as companies re-imagine their businesses with a focus on mobility, this approach falls short. Any corporate app that needs protection has to be built in or modified to fit into the sandbox. With the diversity of apps available, this approach is very limiting and even the early proponents of this technology are moving on to other strategies.

One of these strategies is mobile application management (MAM), which addresses the limitations of sandboxes while still meeting corporate security needs. MAM technology allows companies to wrap their corporate apps and the data tied to them in their own security and management layers. This gives enterprises complete control of their apps and data while leaving user-owned information untouched. In contrast to the legacy sandboxing approach, it does this without any additional overhead, either from affecting device usage or source code modifications.

With MAM, controls such as authentication, encryption, data loss prevention and expiration - apps and data can be manually expired or set to automatically remove themselves from devices based on perimeters established by administrators - can all be applied to corporate apps and other resources on otherwise unmanaged, user-owned devices. In this way, complete end-to-end visibility and control over where sensitive data is flowing - regardless of what mobile application or service is being used to traffic the data - can be achieved and, just as important, maintained.

In addition, MAM allows multiple corporate apps to securely communicate with each other and for data traffic segregation, so all traffic from corporate apps can be routed through the corporate network while the personal traffic is left unmonitored.

It is important to note, however, that MAM as a term is being used loosely within the industry. Different technology vendors use it to describe different things. Some refer to app distribution functionality as MAM and still others refer to simple app blocking as MAM.

From an enterprise perspective, however, MAM should be more than that. More than simply distributing the right apps and blocking the wrong ones, MAM is about protecting the corporate apps and data on mobile devices by taking management from a device level to an application level. It is the most effective tool for separating corporate data from personal data to make safe, effective BYOD policies possible.

Re-imagining business for a mobile world, while not without its growing pains, can be a fairly straightforward process. However, to re-imagine business for a mobile world confidently, MAM should be a part of every discussion.

More Stories By Swarna Podila

Swarna Podila serves as a senior manager with the Enterprise Mobility Group at Symantec, responsible for the messaging, positioning, go-to-market strategy and overall evangelism of mobile security and management products and services. In her role, she focuses on the enterprise routes to market, messaging the solutions for on-premise and cloud deployments. At Symantec, Podila has promoted the idea of user-centric and information-centric view and anytime, anywhere productivity.

Prior to Symantec, Podila served a product marketing consultant at Citrix. There she was responsible for the messaging and launching of the company’s networking products. Prior to Citrix, she worked at a software startup and was responsible for their transition from stealth mode to a mid-sized company. She was responsible for product messaging, identifying routes to market and sales enablement. With over 10 years experience in the IT industry, Podila has held a number of roles in product strategy, marketing and engineering. She has an undergraduate degree in Electronics and Communications Engineering and an MBA from Santa Clara University.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
Early adopters of IoT viewed it mainly as a different term for machine-to-machine connectivity or M2M. This is understandable since a prerequisite for any IoT solution is the ability to collect and aggregate device data, which is most often presented in a dashboard. The problem is that viewing data in a dashboard requires a human to interpret the results and take manual action, which doesn’t scale to the needs of IoT.
Internet of @ThingsExpo has announced today that Chris Matthieu has been named tech chair of Internet of @ThingsExpo 2016 Silicon Valley. The 6thInternet of @ThingsExpo will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
SYS-CON Events announced today the Enterprise IoT Bootcamp, being held November 1-2, 2016, in conjunction with 19th Cloud Expo | @ThingsExpo at the Santa Clara Convention Center in Santa Clara, CA. Combined with real-world scenarios and use cases, the Enterprise IoT Bootcamp is not just based on presentations but with hands-on demos and detailed walkthroughs. We will introduce you to a variety of real world use cases prototyped using Arduino, Raspberry Pi, BeagleBone, Spark, and Intel Edison. Y...
Much of IT terminology is often misused and misapplied. Modernization and transformation are two such terms. They are often used interchangeably even though they mean different things and have very different connotations. Indeed, it is somewhat safe to assume that in IT any transformative effort is likely to also have a modernizing effect, and thus, we can see these as levels of improvement efforts. However, many businesses are being led to believe if they don’t transform now they risk becoming ...
CenturyLink has announced that application server solutions from GENBAND are now available as part of CenturyLink’s Networx contracts. The General Services Administration (GSA)’s Networx program includes the largest telecommunications contract vehicles ever awarded by the federal government. CenturyLink recently secured an extension through spring 2020 of its offerings available to federal government agencies via GSA’s Networx Universal and Enterprise contracts. GENBAND’s EXPERiUS™ Application...
What does it look like when you have access to cloud infrastructure and platform under the same roof? Let’s talk about the different layers of Technology as a Service: who cares, what runs where, and how does it all fit together. In his session at 18th Cloud Expo, Phil Jackson, Lead Technology Evangelist at SoftLayer, an IBM company, spoke about the picture being painted by IBM Cloud and how the tools being crafted can help fill the gaps in your IT infrastructure.
SYS-CON Events announced today that LeaseWeb USA, a cloud Infrastructure-as-a-Service (IaaS) provider, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. LeaseWeb is one of the world's largest hosting brands. The company helps customers define, develop and deploy IT infrastructure tailored to their exact business needs, by combining various kinds cloud solutions.
The best-practices for building IoT applications with Go Code that attendees can use to build their own IoT applications. In his session at @ThingsExpo, Indraneel Mitra, Senior Solutions Architect & Technology Evangelist at Cognizant, provided valuable information and resources for both novice and experienced developers on how to get started with IoT and Golang in a day. He also provided information on how to use Intel Arduino Kit, Go Robotics API and AWS IoT stack to build an application tha...
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
It’s 2016: buildings are smart, connected and the IoT is fundamentally altering how control and operating systems work and speak to each other. Platforms across the enterprise are networked via inexpensive sensors to collect massive amounts of data for analytics, information management, and insights that can be used to continuously improve operations. In his session at @ThingsExpo, Brian Chemel, Co-Founder and CTO of Digital Lumens, will explore: The benefits sensor-networked systems bring to ...
"Tintri was started in 2008 with the express purpose of building a storage appliance that is ideal for virtualized environments. We support a lot of different hypervisor platforms from VMware to OpenStack to Hyper-V," explained Dan Florea, Director of Product Management at Tintri, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
Identity is in everything and customers are looking to their providers to ensure the security of their identities, transactions and data. With the increased reliance on cloud-based services, service providers must build security and trust into their offerings, adding value to customers and improving the user experience. Making identity, security and privacy easy for customers provides a unique advantage over the competition.
SYS-CON Events announced today that Venafi, the Immune System for the Internet™ and the leading provider of Next Generation Trust Protection, will exhibit at @DevOpsSummit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Venafi is the Immune System for the Internet™ that protects the foundation of all cybersecurity – cryptographic keys and digital certificates – so they can’t be misused by bad guys in attacks...
Is your aging software platform suffering from technical debt while the market changes and demands new solutions at a faster clip? It’s a bold move, but you might consider walking away from your core platform and starting fresh. ReadyTalk did exactly that. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, will discuss why and how ReadyTalk diverted from healthy revenue and over a decade of audio conferencing product development to start an innovati...
For basic one-to-one voice or video calling solutions, WebRTC has proven to be a very powerful technology. Although WebRTC’s core functionality is to provide secure, real-time p2p media streaming, leveraging native platform features and server-side components brings up new communication capabilities for web and native mobile applications, allowing for advanced multi-user use cases such as video broadcasting, conferencing, and media recording.
Large scale deployments present unique planning challenges, system commissioning hurdles between IT and OT and demand careful system hand-off orchestration. In his session at @ThingsExpo, Jeff Smith, Senior Director and a founding member of Incenergy, will discuss some of the key tactics to ensure delivery success based on his experience of the last two years deploying Industrial IoT systems across four continents.
There will be new vendors providing applications, middleware, and connected devices to support the thriving IoT ecosystem. This essentially means that electronic device manufacturers will also be in the software business. Many will be new to building embedded software or robust software. This creates an increased importance on software quality, particularly within the Industrial Internet of Things where business-critical applications are becoming dependent on products controlled by software. Qua...
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
SYS-CON Events has announced today that Roger Strukhoff has been named conference chair of Cloud Expo and @ThingsExpo 2016 Silicon Valley. The 19th Cloud Expo and 6th @ThingsExpo will take place on November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. "The Internet of Things brings trillions of dollars of opportunity to developers and enterprise IT, no matter how you measure it," stated Roger Strukhoff. "More importantly, it leverages the power of devices and the Interne...
The Internet of Things will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, demonstrated how to move beyond today's coding paradigm and shared the must-have mindsets for removing complexity from the develo...