Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ColumnsCyber Tactics ColumnCybersecurity News

Managing Thumb Drive Security Risks

Network security practitioners are well aware of the challenges posed by removable data storage devices, including thumb drives.

By Steven Chabinsky
September 1, 2014

 

Thumb drive security
 

Network security practitioners are well aware of the challenges posed by removable data storage devices, including thumb drives. The blessings of their small size, low cost and ease of portability also are their curse, since they are more difficult for companies to track.  In addition to the risk of loss, removable media – like other peripheral devices – often are a conduit for transferring malware onto networks and for stealing data. 

Researchers recently discovered they could insert specialized malware into USB firmware that allowed the infected device to masquerade as a different type of USB device altogether. For example, a computer can be tricked into thinking that a thumb drive is actually a keyboard, and as a result accept the device’s output of typed hacking commands.

 

Missing You

In one case in the past year, a healthcare provider notified nearly 50,000 patients of a missing USB flash drive believed to contain patient names, dates of birth and prescribed medications. Companies can better prepare for these types of losses by establishing and enforcing a removable media policy, which defines when USB storage devices may and may not be used, to include consideration of data sensitivity, network criticality and standard use cases. Encryption should be used whenever sensitive data is stored on an external device, and employees should be required to report any lost, stolen or misplaced removable media and understand how to dispose of it.

 

Jumping the Air Gap 

Of course, not all data loss involving thumb drives is unintentional.  In 2008, a foreign intelligence agency gained access to SIPRNet, a U.S. military network used for sharing information at the Secret level by first deploying malware to infect unclassified, vulnerable computers connected to the Internet.  Once executed, the malware searched for thumb drives. Once a thumb drive was detected, the malware would jump onboard the removable media, wait for an unwitting user to bring the thumb drive to its next destination, gather some information about the locals, bundle it up and transmit it back home. In the event the malware found itself on an air-gapped system without an Internet connection, as was the case with SIPRNet, it planned its escape route by way of another thumb drive. Since the malware got onto the network by riding on a thumb drive, the odds were high that it could leave the closed network in the very same way, but this time carrying stolen property. Just as thumb drives can infect computers, computers can infect thumb drives. 

Another problem is that the very nature of removable media serves as a malicious insider’s best friend. As demonstrated by Edward Snowden, thumb drives that are banned as a matter of policy may still be used with devastating effect if sufficient technical controls aren’t in place. To protect your business, systems administrators should consider deploying products, configurations and sufficient personnel resources to block USB connections from particular types of devices, monitor USB connections, audit data transfers and disable autorun and autoplay features. Being able to prevent unauthorized use always is preferable but, when that’s not possible, companies also should consider endpoint monitoring solutions that quickly detect, contain and mitigate rogue activities.

 

Stop. Don’t Think. Connect. Infect.

InfoSec training should include specific cautions regarding the use and disposal of thumb drives. Employees should know what to do if they find a flash drive on the street. Without proper training, the odds are high that an employee will insert a found flash drive into your corporate network, either to find the rightful owner or out of curiosity. When the Department of Homeland Security purposefully dropped data disks and USB flash drives in the parking lots of federal agencies and government contractors, 60 percent of the found objects were inserted into an agency or contractor network. The number rose to a staggering 90 percent when the thumb drive sported a DHS logo. In an unrelated study, even IT professionals admitted to plugging in found thumb drives – more than 75 percent, in fact.

 

Thumbs Up or Thumbs Down?

Whether the convenience of using thumb drives outweighs the risk is a fact specific business question. One potential middle ground is to permit thumb drives only to pass between company owned computers, and always to require encryption.  If you have additional advice or lessons learned about removable media, please post your comments to SecurityMagazine.com. 

 

About the Columnist:  Steven Chabinsky is General Counsel and Chief Risk Officer for CrowdStrike, a cybersecurity technology firm that specializes in continuous threat monitoring, intelligence reporting, network security penetration testing, assessments and incident response. He previously served as Deputy Assistant Director of the FBI’s Cyber Division. He can be reached at steve.chabinsky@crowdstrike.com. You can follow him on Twitter @StevenChabinsky.   

KEYWORDS: data security data storage flash drive cybersecurity intellectual property protection thumb drive security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Chabinsky 2016 200px

Steven Chabinsky is global chair of the Data, Privacy, and Cyber Security practice at White & Case LLP, an international law firm. He previously served as a member of the President’s Commission on Enhancing National Cybersecurity, the General Counsel and Chief Risk Officer of CrowdStrike, and Deputy Assistant Director of the FBI Cyber Division. He can be reached at chabinsky@whitecase.com.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Why Your Business Environment Should Drive Cybersecurity

    See More
  • Cyber Tactics - july 2018

    Managing Supply Chain Risk

    See More
  • Traveling with Technology Security Magazine November 2017

    Traveling with Technology: An Information Security Guide

    See More

Related Products

See More Products
  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • High-Rise Security and Fire Life Safety, 3rd edition

  • 9780367259044.jpg

    Understanding Homeland Security: Foundations of Security Policy

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing