Cybersecurity: data under surveillance

The threat of sensitive data being hacked hangs over every business. Business travellers are prime targets, facing a crucial challenge: combining mobility, connectivity and security.
shutterstock/Wright Studio
shutterstock/Wright Studio

Last May, a computer attack caused panic in more than 150 countries. The aptly named "Wanna Crya "ransomware", took the data of infected computers hostage and demanded payment in exchange for their return. Unprecedented in its scale, this piracy is not isolatedThe US elections had already given rise to a number of intrusions a few weeks earlier.

The media exposure of these attacks will at least have had the merit of shining a spotlight on one of the world's most notorious terrorist groups. a sensitive subject, long underestimated Cybercrime is not science fiction. "Even today, the leaders of many companies do not fully appreciate the digital challenges they face, while other managers can be misled and overestimate certain risks."believes Hervé Schauer, Chairman of HSC. "But in recent months, things have changednuance Diane Rambaldinifounder of Crossing Skills and President of the French chapter of theInformation Security System Association (ISSA). Managers of both large companies and SMEs are beginning to be aware of the danger.". Some figures bear this out: almost a third of travel buyers (31 %) have observed an increased interest from business travellers in the security of their data over the previous three months, according to a study published by American Express GBT and ACTE (Association of Corporate Travel Executives).

Now that the idea has gained ground, it needs to be put into practice. However, companies are slow to take concrete measures and allocate adequate financial resources. "Cybersecurity is expensiveit's a fact"agrees Diane Rambaldini. "The main players in the sector have put together offerings aimed at large Cac 40 companies. The logic behind the structuring of their offerings, their scope and their customer relationships is focused on major accounts. Nothing was really planned for SMEs, because there wasn't really a market.she points out as she prepares to launch a solution aimed precisely at these small structures.

Information at risk

In this context, business travellers are perhaps the most exposed. reconciling mobility and connectivity at all costsThe risk of chasing WiFi networks increases. "The threat is real: the traveller will connect to the airport's public WiFi with sensitive documents or be too chatty in the hotel bar.says Diane Rambaldini. The risk needs to be considered from both a purely cyber-security angle, and also from a business intelligence point of view.." Too often, mobile professionals underestimate the risks. Perhaps because they have too much faith in human nature or - more likely - because they think that the information they hold is of no interest to hackers. Whatever the nature of this data, they forget that a hacker can use it to infiltrate and corrupt the company's system as a whole.

shutterstock/michaeljung
shutterstock/michaeljung

The eternal quest for connectivity and the mixing of private and professional uses are causing problems. According to ACTE and American Express GBT, 64 % of business travellers are authorised to connect to public WiFi networks using their business devices, and 58 % to use their personal equipment for business purposes while on the move. "It's understandable that travellers don't want to travel with two phones, but you can't go against innovation or habit, both of which are always stronger.warns Diane Rambaldini. There are solutions that can be put in place to secure these uses. In any case, good practice applies in both the professional and private spheres.".
The subject is all the more sensitive because computers and telephones are no longer the only potential targets. The development ofInternet of Things (IoT) is extending its range of connected devices. Watches, toothbrushes, trainers Everyday objects are becoming intelligent, and at the same time vulnerable. According to a study by Gartner, 25 % of cyber attacks against businesses will involve connected objects by 2020.

Technology providers are therefore focusing on the security of their offerings, as in the case of Blackberry which is investing heavily in this area to win back the corporate market. Data protection is becoming an integral part of product specifications. Fingerprint readers are becoming increasingly common on phones and laptops. Toshiba's new Tecra X40, for example, incorporates biometric authentication technologies and infrared cameras for facial recognition. Encryption keys are also starting to appear on consumer sites, while smartphones integrate 'safe' applications...

123RF/nasirkhan

What tools, what guarantees?

Yet it's hard to distinguish between the essential and the gadget, and above all to identify the most reliable solution that guarantees a level of security appropriate to travellers' needs. The certification developed byFrench National Agency for Information Systems Security (ANSSI) can serve as a benchmark for cyber-secure and informed shopping. For the time being, experts unanimously agree that virtual private networks must be used. These VPN (Virtual Private Network)which specialist Symantec describes as "a private network built within a public IT infrastructure, such as the Internet"These are now the norm in large companies. "A VPN connects to the company's point of entry and concentrates all exchanges within this encrypted tunnel.explains Hervé Schauer. This means that no one can eavesdrop on your conversation, even when you are on a hotel or airport network. This is the basis."

More often than not, data security is less about the hardware used and more about the best practices to adopt. "Avoid public wi-fideactivate the automatic search for networks: these are pretty simple reflexes."says Diane Rambaldini at Crossing Skills. Sometimes, certain technological precautions can even prove counter-productive: "Using an encrypted key is the best way to attract attention"warns Hervé Schauer. "Some customs have so many investigative possibilities that they can demand the encryption keys; this is even common today. It is better to avoid travelling with a computer, to pick one up on the spot, or to opt for a "naked" PCwithout any data". Diane Rambaldini agrees: "Some airport security services are forbidding travellers to turn off their electronic devices. This is a harbinger of things to come. Depending on the destination, I would recommend not taking a computer at all, or taking empty equipment.".

Far from the collective imagination that associates hacking with an army of geeks hiding in basements, cybersecurity can take on a completely official face. "There are so many pirates organised by governments!"warns Hervé Schauer. He adds: "They do not inform software publishers of the flaws they discover so that they can use them in turn." The practices of certain countries are not the only factor of uncertainty. In its risk map for 2017, Control Risks warns: "The data protection regulations of the United States and theEUwhich is more isolationist, are diametrically opposed, while the China and the Russia pass new cyber-security laws. The consequence will be a nationalist retreat, forcing companies to store data locally, at a higher cost, as they will be unable to meet international data transfer obligations.".

An affair of states

In concrete terms, choosing cutting-edge equipment and suppliers is not enough to protect against a possible intrusion, if the information stored can leak. At Concura specialist in technologies linked to business travel, emphasises the way in which this precious data is hosted: "The data is held on storage equipment owned and maintained by Concur, and hosted in data centres managed by third parties that provide adequate security guarantees."underlines Tristan FaujourHead of Risk and Safety for the EMEA region. She adds: "Some services can be provided from Europe, where the main processing centre is in the Paris region and the back-up centre in Amsterdam. The choice of location is made during contract negotiations.".

The regulatory framework is therefore crucial, as Hervé Schauer (HSC) confirms: "Legislation makes a big difference. We are all aware that a fire extinguisher is very effective in the event of a fire, but if maintenance is carried out properly it is only because a law requires it. Fear of the police plays a major role. Even if rules have been put in place in a few specific sectors for very sensitive data, this is not yet the case in digital security.".