Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Leadership and Management

Why Superphone Hacks Are Your Business

March 1, 2011

Many of you in the traditional roles of corporate, investigations and physical security may not think your organization has an active role in your organization’s telephony security polices and programs. Well, at least not on the risk management side of the equation. Post-hack or theft, the investigation and clean-up, of course, falls to your organization. But the recent rise in smart, or the newly coined, “superphone” hacks, breaches and resultant losses do require your attention and participation at the front end of risk management. In many cases, the flaw is not the technology being used, but the people using and misusing the technology. According to a Verizon Data Breach Investigations Report, which cites misused permissions as a core issue, 96 percent of these cyber-breaches are avoidable by implementing simple or intermediate controls.

   This is not only an IT or technology security issue, per se. Rather, key risk issues are right in the sweet spot of corporate security, including culture, training and policies by employees to ensure that risk is reduced. The rise of corporate networks, electronic supply chains, remote workforces, global expansion and travel have all added to the complexity of risk management and securing the business, and mobile devices only add to the layer of brand risk. And then there’s the arrival of superphones to further raise the security bar.

 What are superphones? As a basis for discussion, there are the traditional cell or mobile phones, the original un-tethered phone for the purpose of making a call while mobile. Security was not an issue for the first mobile phones, unless you lost one or had the electronic serial number stolen and applied to another phone. The only “exposure” was a huge phone bill and a lengthy argument with your service provider. Losses were limited.

The superphone category also includes the Apple iPad and post-iPad tablets, and according to talk at the recent CES Show, Apple should have a profitable year, with a projected 20 million iPads in 2011 expected to be sold. The year 2011 has been dubbed, “year of the tablet,” and rightly so.

So what to do? A “Sysadmin” blog written by Trevor Pott and distributed in a recent OSAC briefing outlines the general issues and potential problems, and provides a good starting point for definitions within your organization, so that everyone from IT to sales is singing the same tune.

The blog, titled “Superphones: A Nightmare Waiting to Happen,” correctly points out that with new connectivity and functionality, the risk to new attacks for superphones has increased. Specifically, Pott defines superphones as those that include access to an integrated app store and multimedia playback capabilities.

 And his key point for you: “Superphones, on the other hand, are deadly. They are not only fully-featured computers in their own right, they are easy – and desirable – enough to use that everyday users are getting in on it. They are everywhere and worst of all, their popularity is seeing their vulnerabilities discovered, exploited and malware specifically designed to target them.”

It may be no coincidence that on the day after the blog was posted, McAfee, the anti-virus company best known for computer virus software, announced research that “smartphones are the cyber criminal’s new frontier.” According to the research, malicious attacks on smartphones increased 46 percent in 2010 (and you are thinking…only 46 percent?)

At the top of the attacked list are the market share leaders, including Google’s Android and Apple’s iPhone. And it is also no coincidence that McAfee acquired smartphone security company Trust Digital to enter this new growth market.

What are examples of the most common malicious attacks? One takes control of the Google Android application and quietly sends premium rate text messages to a number the hackers established. Their profits are instant and huge. Similar to the cell phone risk, the expense is yours. Of larger risk is spying to gain access to passwords to corporate networks as well as personal banking accounts. And the ability to download free apps to a corporate device that have not been vetted for malware is a significant risk. The February announcement of hacks on Western U.S. Energy companies by Chinese organizations included “tricking employees to reveal passwords.” There is nothing techno-savvy about that. That is all about people, policies and procedures.

Many of the publicized security breaches are the result of exploiting poor security technology and design. But many are also the result of not making users understand how to securely use their new superphone to protect the business and their own information. While the IT issues of superphones are not the traditional role of security, having a conversation with your IT folks leading the superphone charge may be worthwhile. Your expertise and voice in policies and tracking privilege usage beforean investigation has to be launched is central to the goal of protecting the business and building your brands.

KEYWORDS: hacking security risk management superphones

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • cyber-insurance-fp1170xv45.jpg

    Why cyber insurance protection is mission-critical for your business

    See More
  • threat-intel-freepik1170x658.jpg

    The case for continuous threat simulation: Why annual audits will fail your business

    See More
  • Why You are in the Customer Service Business

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing