Unpatched Bugs Rampant on Mobile Devices in Financial Services Firms

  /     /     /  
Publicated : 22/11/2024   Category : security


Unpatched Bugs Rampant on Mobile Devices in Financial Services Firms


More than a quarter of mobile devices used by financial services employees carry known vulnerabilities, according to a recent report.



Many financial services employees are toting around unpatched mobile devices, putting their companies and customers at risk of a data breach, a recent report found.
More than 25% of mobile devices used by financial services employees had unpatched vulnerabilities, according to Symantecs Q2 2017 Mobile Threat Intelligence Report: Mobility and Finance.
The data, gleaned from Symantecs endpoint mobile security software and other sources, also found that 15% of employees mobile devices at financial services institutions had been exposed to a malicious network, while three in every thousand devices were infected with malware.
If I read this report and I was Procter & Gamble, I would be asking my bank, what you are doing to protect my data when your executives are connecting to suspicious WiFi networks, or how many of your employees have phones with malware? says Varun Kohli, a senior director at Symantec. I would be asking these questions because my data is at risk.
And although corporate customers may find there is little they can do to protect themselves from the actions - or lack of actions - that their financial services company is taking, Kohli says that may change in the future.
I hear enterprises are asking their software vendors to take certain steps to protect their information, but I have not heard this of the banks, Kohli says. But companies need to also ask this of their business partners, too.
Patching Problem
Although Apple and Google may regularly patch vulnerabilities, employees at financial institutions may be unaware of the patch notifications. In part, Apple is able to push its patches out relatively easily since it controls both the hardware and software, whereas the task is more challenging for Android.
When Google issues a patch, it has to be delivered to the device manufacturer, which then performs its own version of the update if it decides to issue a patch for the flaw at all, Kohli says. 
Other findings in the report include a general lack of good mobile security hygiene. For example, more than 13% of mobile devices used by financial services employees lack the latest major OS version, while 99% do not have the latest minor update issued by Google or Apple, the 
report
found.
Some 4.6% of iOS users in this sector have yet to install the latest mobile operating system, compared to 47.8% for Android, according to the report.
Despite those results, the financial services industry as well as the healthcare sector tend to institute more frequent updates than all industries overall, Kohli says. He notes both industries suffer the most attacks because of their valuable information and data and, as a result, more is spent to secure those industries and the devices they use.
They are early adopters of security; but even then, we are seeing problems, Kohli says. I was very surprised at the results. I would have expected the number in the financial services industry to be lower.
Related Content:
Apple iOS Malware Growth Outpaces that of Android
Enterprise Android Vs iOS: Which is More Secure?
Key New Security Features in Android Oreo
10 Steps for Writing a Secure Mobile App
 
Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity
agenda here
.

Last News

▸ Some DLP Products Vulnerable to Security Holes ◂
Discovered: 23/12/2024
Category: security

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Unpatched Bugs Rampant on Mobile Devices in Financial Services Firms