Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Enterprise Services

Getting Smart about Smartphone Security

One-hundred and thirteen smartphones are stolen or lost every minute in the U.S.

By Claire Meyer
smartphone slide 1

Rinaldi Rampen, Director of Security and Risk for LivingSocial, believes that security awareness and education is the best starting point for smartphone data security.

Photo courtesy of Rinaldi Rampen

smartphone slide 2

Justin Morehouse of GuidePoint Security says that a strong user’s policy forms the rules of engagement for smartphone use in an enterprise.

Photo courtesy of Justin Morehouse

smartphone slide 3
smartphone slide 1
smartphone slide 2
smartphone slide 3
May 9, 2013

One-hundred and thirteen smartphones are stolen or lost every minute in the U.S. How much data is that? How many patient files, Social Security numbers, business transactions, contact lists and accounts? How much litigation potentially faces an organization after the loss of one smartphone?

Now, before you run out of your office to confiscate everyone’s smartphone, securing mobile devices is not an insurmountable task. It requires some collaboration, education and some initiative, as well as the recognition that – at this point – keeping smartphones out of the workplace is near-impossible.

 “Most commonly, organizations’ largest risk is losing control of their data,” says Justin Morehouse, Founder and Principal of GuidePoint Security, an Information Security Solutions firm. “Once an organization’s data is on the mobile device, it is subject to intentional or unintentional theft or misuse.”

Other considerations pop up when addressing BYOD (Bring Your Own Device) policies, instead of company-issued devices.

“The starting points are different, but the risks are the same,” says Rinaldi Rampen, Director of Security and Risk for LivingSocial, which is a deal-of-the-day website with more than 70 million members worldwide and 2,200 employees in the U.S., including 1,000 at-home or mobile office workers who use their own mobile devices. “Company-issued devices are easier to start with; you can issue pre-configured devices with built-in controls – a required five-character PIN, for example. A company phone also comes with a sense of additional responsibility for the employee: ‘It’s not my phone, so I should be more careful.’ But after that, the risks are fairly even,” he says.

Morehouse says that the main difference between BYOD and company-issued devices lies in control and standardization: “BYOD requires organizations to support a vast array of devices and operating systems. Those organizations succeeding with BYOD have limited their support to certain versions of iOS and Android, thus reducing the administrative burden associated with supporting each and every new device and OS update.”

Supporting a wide-range of devices makes implementing best practices difficult. Rather, he suggests that companies should pair reduced device support with strong policies and procedures.

According to Rampen, the user policy acts as almost an employee “contract” or sign-off on the uses of the phone. “It’s a manual, people-oriented process. It’s never just a tech issue,” he says. “Tech solutions are there for verification and enforcement, but your main risks come with the users, so that’s where your policies should start.”

“Think of your mobile device usage policy as the rules of engagement, especially where an employee’s personal data is concerned,” Morehouse adds. “In case of an incident, the company must have the right to perform investigations on personal devices.”

Companies should also clearly define what is and what is not personal data, including email, contacts and documents, he says. “Especially in a case where the company has to erase corporate data from a phone, the user should be aware that any co-mingled personal data could be lost.”

The classification of data is another area where companies need to be very specific.  Morehouse recommends that companies refer back to their data classification program to determine what assets need protection and what compliance measures you are required to meet.

“Ask where your critical data sets are,” says Rampen. “Take Salesforce for example: Each end point or device should only have access to data from that person’s market. It’s easier to put controls in place from the system, not the device, so figure out an overarching system plan.”

One of the major keys in securing mobile devices compared to laptops or stationary computers lies in the mindset: “Identify your phone or tablet as the same thing as a laptop,” says Rampen. “They have access to the same things, so you should train end users to treat their phones like a company laptop.”

Similarly, transfer your organization’s laptop security best practices to smartphones: setting up passwords and PINs, and including ongoing education about infected applications and emails.

“Security awareness and education is always good – remind, teach and reteach your end users to be aware of how their personal actions can affect professional data on devices,” Rampen says.

A lost phone is one of the most concerning personal situations because users are so dependent on the information stored in their devices. It can take users hours or days to report a missing device, whether it was stolen or left in a cab, and there is no way easy way to guarantee that the data was not compromised, even if the device is located. Morehouse says, “Organizations should shrink the window of opportunity to take data from the device. Ideally, enterprises should implement a self-service portal where employees can locate their device, and then remotely suspend, lock or even wipe it. Your biggest ally and enemy when a device is lost is the battery. Without remote connectivity, the ability to issue a remote command to protect the device is useless. By enabling users to take action themselves, organizations can reduce the likelihood of device compromise.”

“The (smartphone security) space right now is very immature,” Morehouse says. “It’s an area that has not fully been addressed. All mobile device management solutions solve traditional IT problems, such as asset inventory, provisioning and access control, but few solutions address Information Security specific problems. However, we’re starting to see a more data-centric approach towards securing mobile devices with solutions driven primarily by Information Security requirements.”

 At LivingSocial, Rampen is running a convergence shop, cross-training within logical and physical security: “There are lots of cyber components in physical security now, and there is a lot of physical compliance to consider in cyber security. You have to understand the compliance and regulations for both sides in order to protect yourself and your data.” 


  Trouble Abroad

 

As the proliferation of smartphones collides with the expansion of global enterprises, a few issues were bound to occur, not the least of which being cyber espionage.

“It sounds like something out of a movie,” says Morehouse, “But it’s really happening.”

When persons of interest – typically executives of high-profile organizations – travel abroad, state or non-state actors may be interested in data that the executives carry with them on their phones. In a common scenario, a U.S. company is looking to acquire a Chinese company. U.S. executives travel to China to negotiate the terms of an acquisition, and one of their smartphones is compromised. A malicious actor could turn on the device’s microphone during a strategy meeting, thereby uncovering the company’s offers, plans and proposals, ultimately compromising the negotiation.

According to Morehouse, there are 12 high-risk areas for smartphone security while traveling abroad. Some you might expect: China, Iran, North Korea, Russia and the Ukraine; others you might not, such as France.

Here are his top recommendations for smartphone security abroad:

  • Don’t bring your phone: The simplest answer is often the most difficult to follow through on – smartphones are a valued business tool now, and it would be difficult to enforce their removal. But if the travel does not require an executive’s personal phone, avoid accumulating more risk by bringing it.
  • Employ mobile forensics: Any device used abroad should be checked for breaches when returning home.
  • Use burner phones: Traveling employees hand over their usual devices before leaving the country, using a pre-paid phone with limited information while abroad, which is then examined, wiped or disposed of upon returning home.
  • Employ geo-locational data access: Allow a device to access certain data depending on its GPS coordinates. For example, an executive on a business trip to Sydney or Tokyo could be granted full data access, but when he or she steps off the plane in Beijing, the system revokes the smartphone’s data encryption keys until it returns to a trusted territory.

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Claire Meyer is a former Managing Editor for Security magazine.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Leadership and Management
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Security Enterprise Services
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    New Security Technology
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Person working on laptop

Governance in the Age of Citizen Developers and AI

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Deltek

    How to Use Social Media for Better #Security

    See More
  • Safe Schools

    Building a Better Campaign for School Security

    See More
  • ISC West 2018 Product Review - Security Magazine

    2018 ISC West Product Preview: A Broader Security Technology Roadmap

    See More
×
Rinaldi Rampen, Director of Security and Risk for LivingSocial, believes that security awareness and education is the best starting point for smartphone data security. Photo courtesy of Rinaldi Rampen
Justin Morehouse of GuidePoint Security says that a strong user’s policy forms the rules of engagement for smartphone use in an enterprise. Photo courtesy of Justin Morehouse

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!