Henk Waanders: “Manage your phones like every other device in your company”

Henk Waanders: "Manage your phones like every other device in your company" cover

Every company locks down its laptops and servers without a second thought, uses badge control for who walks through the door, and two-factor authentication stands guard over the network. Yet the one device that carries just as much sensitive company data, and that travels everywhere its user goes, is often left almost entirely unmanaged.

Henk Waanders, Presales Solution Architect at Sentyron says: "I compare it to a workstation; that's fully managed. But phones usually aren't, even though they carry the same business-critical information and do the same business-critical work. That's strange when you think about it."

The risk organizations consistently underestimate

Henk has spent years talking to customers about mobile security, and the pattern he sees is remarkably consistent: most of the threats organizations face today arrive through mobile devices, precisely because those devices don't get the same oversight as a laptop. Henk explains: "You need to manage what's on the device, what apps are and aren't allowed, and how data moves in and out. In practice that means routing traffic through a VPN instead of the open internet, the same way you'd treat a laptop."

Ask Henk why organizations haven't caught up yet, and the explanation turns out to be only partly technical. A large part of it, he says, comes down to how people relate to the device sitting in their pocket: "Partly it's a lack of awareness. And partly it's the feeling that this is my phone."

That instinct isn't hard to understand. Employees who receive a company phone tend to treat it the way they once treated a personal laptop, as something that belongs to them and that they can use however they like. But a phone that carries corporate email, corporate credentials, and access to the corporate network is, in every sense that matters, a company asset, and Henk believes that shift in thinking still has to take hold in most organizations. It has to be a two-way street, because a policy that leaves no room for private use tends to backfire.

Henk says: "That's not how it works. It's a company asset that carries company information, and that mindset shift still has to happen. There has to be a balance, of course. People need to be able to do some things privately too, otherwise they'll just start working around the restrictions on a second device."

Convenience versus security: where the line actually sits

That tension between what's convenient and what's actually secure comes up in nearly every client conversation Henk has, and the right balance looks different every time. "People working at a high classification level are very aware of the restrictions, they simply know certain things aren't possible. Lower down, where you're dealing with confidential rather than classified information, the awareness is often lower."

And no matter how many technical measures an organization stacks on top of each other, there's an uncomfortable truth Henk keeps coming back to: "In the end, people click links, reuse passwords, and pick up calls they shouldn't. You can put all the technical measures in place you want, but people remain the weakest link. That doesn't mean the solution is to lock everything down until the phone becomes unusable, though. If anything, the opposite is true: for most employees, you need a standard phone, something they already know how to use. What you build is a shell around it that makes it secure without getting in the way.”

One thing every CISO should check today

If Henk could ask every CISO reading this to do just one thing, it wouldn't be a technical audit or a policy review. It would be a single question: "How secure do you actually think you are?"

Most organizations, in his experience, already sense there's a gap somewhere. Very few have actually measured how wide that gap is. And as the conversation draws to a close, the point he keeps returning to is the same one he opened with.

Henk: "Bring your own device is dead, as far as I'm concerned. It might have worked once, but organizations shouldn't want it anymore. Companies that wait until after a breach are the ones that end up paying for it, in money, in trust, and in reputation."

​On Thursday 15 October, from 10:00 to 10:45, Sentyron hosts the webinar What if your phone is the leak? Mobile security for organisations holding state secrets and critical IP. Eward Driehuis of ThreatFabric opens with what attackers are actually doing on mobile devices today, after which Jurjen Braakhekke, Product Manager Secure Mobile at Sentyron, shows what a secure shell around a familiar phone looks like in practice. The session is hosted by Willemijn Rodenburg. Register here: https://sentyron.com/webinar-what-if-your-phone-is-the-leak-mobile-security-for-organisations-holding-state-secrets-and-critical-ip/