IT Security professionals suffer from password fatigue IT Security professionals suffer from password fatigue - RSS feed from Security Park
(25/06/2009)

According to a survey released by CREDANT Technologies, IT Security professionals admit that they are suffering from password fatigue when it comes to using their mobile devices, which leaves their data exposed to personal and corporate identity theft if these devices were to fall into the wrong hands.

Thirty five percent revealed they just don’t get around to using a password on their business phones and smartphones, even though they know they should as they contain sensitive and confidential information! Surprisingly, IT professionals are only marginally better at using passwords than the general population, as a survey conducted earlier in the year by CREDANT found that 40% of all users don’t bother with passwords on their mobile phones.

The sorts of information that IT professionals are storing on their smartphones and mobiles, many of which are totally unprotected with a password, include:
80% Business names and addresses
66% Personal names and addresses
23% Business emails
16% Personal emails
12% Bank account details
12% Business diary with details of all their appointments and meetings
7% Personal diary
5% Credit card information
4% photos
1% Passwords and Pin numbers

Andrew Kahl, Sr. VP of Operations & Co-Founder from CREDANT Technologies explains “It is alarming to note that the very people who are responsible for IT security are not much better at protecting the information on their business phones than most of their co-workers, who don’t necessarily know any better. If a mobile or smartphone goes missing and isn’t protected with a password, and contains business names and addresses and other corporate data such as business emails, then the company is immediately in breach of the data protection act by failing to meet some of its principals on electronic data.”

“Of even greater concern is the damage that can be done to a company, and the individual who is responsible for the phone, if it falls into the wrong hands, which could expose them to personal or corporate identity theft. It is therefore imperative that all mobile phone users who hold sensitive data, either personal or corporate, should always password protect it at a minimum - and encrypt it if the data is really sensitive,” added Kahl.

According to the IT professionals surveyed, the worst culprits at addressing mobile security within their companies are typically the sales teams, followed by the board of directors and senior management. HR comes out as the best at keeping their mobiles aligned to the corporate mobile security policy.

The survey also found that a third of IT professionals use their own personal mobile phone for work purposes even though the company specifically bans them for business use with almost a fifth spending more than an hour or more per day on their own personal phone for business purposes.

Related topics:  Authentication and identity management   Data management and data security   Mobile and Wireless Security   Security management and policies 


print versionPrint version | email this to a friendEmail to a friend | related articlesRelated articles


Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.


Other Security news and resources


Security News Suppliers Directory Jobs forum Classifieds Knowledge base White papers Research library Security books Special reports Security interviews Security companies Security events Security links Security market

Product channels

Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products

IT Security white papers and research library

Access Control  Authentication  Data Management  Data Security  Digital Signatures  Email Security  Identity Management  Internet Security  Intrusion Prevention  Network Security  Remote access security  Security Management  Security Policies  Security Software  Security Threats  Virus Detection Software  Virus Protection  VPN  Vulnerability Assessment  Wireless Security 

Security books, guides, standards and toolkits

RFID and Smart Cards books, guides and reference documents  Biometric books, guides and reference documents  CCTV books, guides and reference documents  Intruder alarms and intrusion detection systems books, guides and reference documents  Monitoring and surveillance books, guides and reference documents  IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits  Fire, Health & Safety books, guides and reference documents





Ensure that you conduct an effective information security risk assessment that is in line with ISO 27001 by purchasing vsRisk™ Risk Assessment Tool

Need a
Security reference book?
Find it on Amazon
Security books

Article search

Directory search


add your company
Google

ISO 18028 (Network Security Management)
Home | About | Contact | Submit article | Advertise | Newsletter | RSS | Search