4 Rules of Thumb for Better Mobile Device Security

Security threats are everywhere, lurking in alley ways and around corners and even in your favorite coffee shop. Yet mobility is in demand, and people will use their smartphones and other mobile devices because it’s convenient, even if company policy suggests against it.

This is a big deal for IT and security professionals and CIOs, which is why it took a while for IT to recognize the need to address mobile device security rather than simply deny mobile device use. With data breaches, ransomware attacks, hacks and information leaks happening on an almost daily basis, businesses must find ways to protect their valuable applications and data from loss or misuse while at the same time enabling mobile device use.

The following 4 rules of thumb are not comprehensive but are four essential rules of thumb to help guide business owners in addressing mobility management and security within their organizations.

Rule 1: Make sure there are clear mobile device use policies and support them with ongoing administration and strict enforcement.

I can’t say enough about having good security and mobile device policies and keeping them modernized, relevant, and actually enforcing them. Too many businesses say they have a “security and use” policy in place, yet it is outdated and doesn’t reflect the actual tools or processes currently in use.  Even more frequently a business will develop a policy just to say it has one, but won’t actually train workers or enforce compliance.

Rule 2: Require and enforce strong passwords, manage access in real time, and force password changes with some frequency.

It is essential that all user access to applications or data be controlled at minimum by password-protected logins to the device and corporate resources coupled with periodic forced password changes. Users often prefer to not require passwords or other authentication for device access, but corporate policy should not only require them but also enforce their use.  Also, user access should be managed in real time, meaning that any aspect relating to access should be disabled or revoked immediately upon employee termination or reassignment. Too often these forgotten chores are relegated to after-the-fact IT administration, which allows users to access resources beyond their rightful boundaries.

Rule 3:  Do something to contain the applications and data on the device.

Whether the approach is with containers, cloud hosting, server-based computing or something else, it is really important to try to “contain” the applications and data accessed from the mobile device. Risk is created when users sync data directly to the device’s storage or install applications directly on the device to access corporate data. Password and other security measures prevent unauthorized access, but allowing applications, credentials or data to be stored directly on the mobile device allows those things to interact with other things on the device.  Containers, hosting and server-based computing models keep the applications and data within secured spaces, often not even storing essential items on the device but only accessing them via the device. This allows the business to provide users with the access and functionality they need to do their jobs, but also reduces the vulnerability of applications and information assets.

Rule 4: Keep device software up to date and download fewer apps.

Updating mobile device operating system versions and release levels is important to make sure the device has the most current security patches and threat protection.   Some mobile OSes even have capabilities which can help keep personal and work apps separated.  Limiting the number of apps users can download to their devices should also be considered. Users may randomly download and install applications to their devices with little regard for the quality or security of the app, and often accept terms of use without really reading them. Consumer apps from app stores may pose risks to data and the device, so IT should check regularly for problematic apps if the device is used to access the corporate network, applications or data.

Mobile and wireless are in demand

Just about every business has people who use their phones and tablets for some business use, and every one of those mobile devices and the apps running on them could open the door for a hacker, ransomware, data theft or compromise. While there are many benefits to be gained by enabling remote and mobile devices in the business workflow, unrestricted access only creates risk.

Keeping mobile devices secure for business use takes multiple approaches, as there is no single method or solution that works for every situation. Our 4 rules provide a basic foundation for business mobility management, offering a starting point for developing a more thorough and detailed plan.

Make sense?

J

Mobilizing QuickBooks Desktops

 Hosted QuickBooks for Remote and Mobile Access

There was a time not too long ago when the “thought leaders” in information technology said that the desktop is dead, and all software will be accessed via the web. (Note: I put “thought leaders” in quotes because industry thought leaders are often those with the greatest media influence.  After all, you can’t lead them if you can’t reach them, right?). The whole no software thing is a dramatic oversimplification of what is happening with computer software, but one thing is kind of coming true: nobody wants to be tied to their desktop.  It’s not that the desktop is dead… it’s just not all there is. For users of the desktop editions of Intuit QuickBooks software, the question really isn’t whether they intend to give up their familiar and trusted software to use a different, online solution. The question is how to use the QuickBooks desktop software they want in the cloud so they can use it on desktops that aren’t the primary desktop computer, or on mobile devices.

Computing technology has finally reached a level of accessibility that was previously only imagined in science fiction stories.  Communicating instantaneously with anyone anywhere around the world; accessing extensive (limitless?) libraries of information, art and music with a simple handheld device – these are the things that people do every day without a second thought.  Business users may even be able to access their business documents, email, contacts and appointments etc. from mobile devices, enabling a productive and functional mobile workforce.
desktop-appsYet the desktop remains as the primary workhorse for most business users. This is where the productivity applications live, where large spreadsheets and full-screen applications are run, and where keyboarders and production data entry users operate.  Tablets, touchscreens and mobile devices just don’t provide the same capabilities unless you tether them to full size monitors and keyboards.  Even then they may not because they might not run the same OS as the desktop.  The point is that the desktop hasn’t gone away and isn’t likely to any time soon.  Users may use more mobile apps and devices, but this isn’t diminishing use on the desktop as much as it augmenting it.  This is what fuels the interest in application hosting and virtual desktop computing models – the desire to mobilize desktop and network applications and working environments.

Hosting applications and data gives businesses the flexibility of working in desktop applications and accessing data just as if they were in the office, yet users may be located anywhere there is Internet connectivity. When the applications and the associated data are managed in the datacenter, businesses are able to centralize their information assets and manage them more effectively than if the data were distributed among multiple computers.  While most sync and share solutions require files to be downloaded to local computers in order to open and edit, a hosted application service with virtual desktops and file sharing provides a security model which keeps business data secure yet available for user access without compromising security by downloading information to the user device.

A hosted solution approach can make license utilization more efficient and compliance easier to maintain, too.  By enabling access to applications on a centralized platform and eliminating the installation and maintenance of software on individual computers, businesses reduce the reliance on local IT personnel to install and update applications and user accounts, and improve their ability to control application assignments and usage.

Hosting helps businesses take advantage of technology that would otherwise be unaffordable, and delivers the mobility and centralized management required to boost productivity and contain costs.  There is a high cost to managing a business network, and creating secure mobile access to that network can represent an exponential increase in IT spending (just to initially set up, not to mention ongoing costs for security management, monitoring and support). Rather than taking on the entire burden of service management and delivery directly, businesses electing to work with hosting providers find that they are able to focus more on business operation, strategy and growth – and spend less time worrying about the IT supporting them.  Costs are reduced, workers are empowered, and capabilities are increased while knowledge and process investments are preserved.  When it comes to mobilizing business applications like QuickBooks desktop editions, it all starts with a hosted approach.

Joanie Mann Bunny FeetMake Sense?

J

Is it Cloud or is it Desktop?

Is it Cloud or is it Desktop?

There are a few realities that users of purely SaaS-based solutions are finding, and among them is that most web-based applications don’t readily integrate with the desktop – and the desktop is still where a lot of the real work gets done.  Yes, users are increasingly mobile and are using smartphones and tablets to create and access information via mobile applications and services, yet the PC desktop – whether it’s an actual desktop computer, laptop or full-featured tablet – remains as the workhorse for business.  Even the most popular SaaS applications continue to rely upon the desktop and locally installed applications to get some of the work done (note that many Salesforce.com users still find Excel to be their most effective reporting tool).  In an effort to deliver mobility for those applications traditionally tied to the desktop, software developers have adopted two main approaches: redevelop the application for the web (which usually means bringing functionality down to a lowest-common-denominator approach), or applying a traditional terminal server or virtualized application approach and calling it “cloud”.

desktop-apps

Neither option is awesome for the software maker – the time and cost of development certainly isn’t low, and the realities of hosting conventional desktop or LAN-based applications in shared infrastructure are pretty ugly at best.  What these software makers need is a way to allow businesses to continue to use their software for the desktop and LAN, enabling the user with software license use rights to access that software product and associated data on any of their “desktops”, regardless of where that desktop might be (or what device it is running on).  The model is cloud, but then it’s a desktop model too.

Independent software vendors are more frequently turning to platform providers (PaaS) to help deliver whatever “cloud” approach the company elects, and these ISVs are also feeling the bite of outsourced service fees and growing costs of delivery.  It is not just the direct customer questioning the cost of deploying resources in the cloud – software providers are questioning these costs, too, especially as they attempt to deliver resource-intensive solutions from hosted infrastructure that bills them based on resource utilization.  MyQuickCloud is proving that ISVs and their customers no longer have to bear large infrastructure costs in order to deliver complete user mobility. MyQuickCloud supports IaaS providers and their partner networks, allowing infrastructure-as-a-service offerings to include a simple and fast way to immediately make that infrastructure useful for desktop and application delivery.

The information technology industry has seen a lot of disruption in recent years, with complexity and risk in systems rising as users demand more functional mobile capability and software developers struggle to protect and preserve their assets (users included).  MyQuickCloud jumps right into the middle of it, delivering solutions for business customers, software developers and cloud providers alike, and answering the question of whether it’s cloud or desktop.  The answer is “yes”.

jmbunnyfeetMake Sense?

J

Moving Your Systems to the Cloud

The IT industry is promoting Software as a Service and online applications as the new normal for computing, and unless you’ve been living under a rock for the past few years you have heard how it is supposed to make our computing lives ever so much better.  Hiding under that rock might also have spared you from reading about the various failures and outages which impact users, forcing them to make do without the online applications and data they have become so reliant upon.  It’s surprising, but not unimaginable, that businesses rely so heavily on applications and services that didn’t even exist a few short years ago.

The potential benefits of a SaaS model are many, but the risks are equally significant and should not be minimized.  This assessment should center on a review of the application software in use, considering whether or not it is meeting the needs of the business.  Where and how the software runs is much less of an issue than the functionality and process support it provides – most “legacy” applications can be run in a cloud server environment, making remote access and managed service part of the service model.

There is risk in changing business applications – risk of data loss, changed or broken data relationships, lost productivity, and more.  Many businesses would benefit by running their applications in a cloud model while continuing to utilize the software solutions their operation relies on.

Application hosting models where desktop applications are delivered on cloud servers is  often overlooked when businesses go looking for cloud software because they are shopping for software and not the platform.

With Software as a Service (SaaS), the software and the platform are combined and together represent the solution. With application hosting on a cloud server, the software is the same software a business would traditionally run on PCs and servers, but the they are installed and managed on the cloud server rather than the local computers.

The big benefit is the agility of the platform and the user mobility it allows.  The unspoken benefit is that you can still “take your ball and go home” if the service doesn’t work out.

Removing the barriers for adopting an online working model allows the business to experience the benefits attached to cloud computing without introducing unnecessary risk through unneeded changes in software and applications.

Make sense?

J

 

Surprise! Consumer apps get IT approval in small businesses: GIGAOM.com

Surprise! Consumer apps get IT approval in small businesses: GIGAOM.com

In a recent article on GigaOm, author Barb Darrow discusses the findings of a survey of small businesses in the US, UK, Canada, Australia and New Zealand, where it was found that the use of “consumer” information technology is being more widely accepted for use in small businesses, and that many of these selections are happening without the knowledge or participation of the IT department.

“Employees are driving business apps selection in many small and medium businesses, according to new research. A good percentage of productivity, social and collaborative apps now sanctioned by IT in SMBs were brought in by workers without IT knowledge.“

Reporting that small businesses are adopting “consumer” IT, and that it is OK with IT departments, isn’t a surprising finding.  Small businesses have begun leveraging mobility and cloud solutions to their benefit, being able to take advantage of powerful technologies that previously only enterprise IT departments could enjoy.

 “.. the line between personal and workplace technologies has become all but invisible. That poses real challenges to IT departments that have to deal with all sorts of technology coming in over the transom. But it also opens up opportunities for vendors that design easy-to-use consumer apps to enter the business realm as well.”

The cloud introduces new agility and capability for all businesses, not just small business. For IT departments in larger businesses, this is a big IT management issue. For smaller businesses, the IT manager is often the business owner or an occasionally contracted on-site technician.  When faced with IT needs in the business, many small business owners will at some level rely upon the solutions they also use in their personal lives – in many cases, there simply isn’t a budget for both.  The line between business and personal has always been “blurry” for the small business owner.

Make Sense?

J

Read more: Disruptive Trends = Emerging Opportunity: Adapting to a changing technology and business environment

What will my business be worth, when I need it to be worth a lot?

bodeguy

Business Enlightenment

Get on the path…

  • Read more about how accountants need business intelligence, too
  • Read more about how there’s no fear and loathing in accounting
  • Read more about the pressure on accountants to deliver more value and intelligence to their clients
  • Read more about Data Warriors: accounting in the cloud

Everybody Clicks: Keeping in touch with your business online

Everybody Clicks

Keeping in touch with your business online

In today’s technology focused market, it’s hard to find a way to stand out from the crowd. Making that effort to communicate with clients is more than just sending them a quarterly newsletter or email. It’s about evolving your business to meet their needs. Everyone wants everything online these days. It’s not just convenient anymore, it’s expected.

If your business doesn’t provide your clients with the level of online service they have come to expect, they probably won’t stay your clients for very long. If you want to make sure these new expectations are being met it means building and maintaining a presence on the web. That’s right; your website is the new face of your business. It’s often the first thing new clients see so it has to make a good impression. As the old saying goes, “you only get one first impression.” This adage is just as true for your website as it is for you. Old, outdated websites just aren’t good enough anymore. People want somewhere they can go to get the latest updates on the services your business provides, and they want it to be easy to find that information. Maintaining your website, keeping it up to date and full of useful information is important. It can also be time-consuming or expensive.

As a business professional, probably a bookkeeper or accountant, you probably spend as little time as possible managing your website and composing newsletters. Now, imagine that you just got back to the office after lunch and you want to do some work on the company website, maybe check on the traffic statistics while you’re at it. Normally you’d go and log in to three or four different places, one or two to do the work on the site and the other one or two to look at your statistics. This is a waste of time and energy, but not one you can avoid. Now let’s say you have some time left before you go home for the night and you realize you haven’t sent out this month’s newsletter. That’s another site to go log into. Site after site, a new interface or dashboard each time. Not to mention the hassle of entering your new contacts into your CRM or selecting the right recipients for the newsletter from your contacts lists. Everywhere you go there is another step to the process of staying in touch with your clients, to keeping the website updated and accurate. Login after login and dashboard after dashboard. What if there was something that could streamline everything? Keep your company’s blog in the same place as your site traffic statistics or web-based CRM solution? (Wouldn’t that be neat?) One login to get to everything. Keeping your clients informed, organized, and satisfied. Everything you want at the click of a mouse.

Your time is your money, so saving time is saving money. Having all of your online tools in one place would do just that. No wasted time, no need to repeatedly log in. Just getting everything taken care of, from one place. Not to mention your clients’ needs. Every business has a website nowadays; online payment options, blogs, forms to request information, the list goes on and the need for them is not confined to accounting and bookkeeping firms.

Let’s say you’re a small hobby shop, selling model trains and cars with all the odds and ends needed to build or maintain them. Do you rely solely on word of mouth or paper ads to bring you the business you need? Of course not. You get a website. The problem is you don’t know where to start. So, you hire someone to build it for you and to make changes when needed. That gets expensive. Ok, so you build it yourself using one of the many solutions available on the web today. Now you control everything, from the colors and graphics to the content but how do you track the traffic your site gets? Or what information your customers look at the most? Analytics of course! Unfortunately that means another thing to buy and another page to log into. The same goes for CRM solutions or email domains. Each aspect of your business is locked away in its own little corner. Frustrating, isn’t it?

Wouldn’t it be grand if you could change your homepage, send a newsletter, and track today’s site visits all from one place? Well, that’s where Nakea.net comes in. Nakea.net is a solution that is perfect for any business. It has web design, analytics, email marketing, contact management, and much more all in one place. That’s right.  One login and you have your world at your fingertips.  Just click to log in, and it’s all right there, with easy to use features and templates that allow you to gear your website, and your communications, to your clients and customers.

Make Sense?

Nakea.net, delivering the smartest social website your business can build, is a sponsor of Cloud Summit 2012.

Get Cloud Summit information here.

Summit Sponsors include: