
Since 25 May and the entry into force of the General Data Protection Regulation (RGPD)Europe has put some order into the way information is processed, establishing a sort of code of conduct to regulate the ever-increasing volume of traffic. Does this mean that the data of business travellers is now safe from any intrusion? The answer is obviously no, for several reasons. Because the authors of this regulation were unable, or unwilling, to codify in detail all the aspects relating to cyber security.
"A closer look at the RGPD reveals that there is only one and a half pages devoted to security. And even that is diluted in a very broad approach.underlines Diane Rambaldinifounder of Crossing Skills, a consultancy specialising in information systems security. The regulation doesn't really explain how to protect data, it doesn't define the secrets of awareness, it doesn't say much in the end... The RGPD sets out the main lines of thinking, entrusts companies with the question of the protection of data and the protection of privacy. privacy and data protection. It encourages them to carry out risk analyses, to sit down and think about potential incidents. But just because the RGPD has arrived doesn't mean that the CISO [The RGPD does not call into question this mission. On the contrary, it highlights it." What's more, it will take time - and penalties - for the text to be gradually refined in line with case law. And for the less zealous companies to really take the necessary measures.
So the threat to business travellers has not really diminished. What's more, those involved in cybercrime have no plans to comply with the RGPD... By their very nature, mobile employees are more exposed than their sedentary colleagues, and in more ways than one. "Business travellers are both producers, consumers and sharers of data. What's more, they will be connecting in disparate environments such as hotel or airport WiFi."reminds Nicolas ArpagianDirector of Strategy and Public Affairs at Orange Cyberdefense.
Those responsible forInternational SOS confirm: "Whether in transit or at their destination, business travellers - and by extension their company networks - are potentially more vulnerable to cyber-attacks and physical security threats. These threats are becoming increasingly sophisticated and daring in their methods of gaining access to their networks. confidential information business travellers."
cybercrime is expected to cost businesses between $2.1 billion in 2019 and $6 billion by 2021
According to International SOS, we can even expect a spectacular increase in intrusions over the coming years: "The theft of corporate data and information continues to rise, and cybercrime is expected to cost businesses between $2.1 billion in 2019 and $2.2 billion in 2010. 6 billion by 2021." Diane Rambaldini even mentions "a crazy race"and explains thatthe digital world is becoming increasingly important. connected devices are exploding. At the same time, cybercrime is becoming increasingly professional and is growing exponentially."
The increase in the threat can be explained in particular by the proliferation and democratisation of hacking tools. You don't need to be a seasoned computer buccaneer: a quick search on the Internet, for example, will turn up a "key logger at low cost. Once connected to a shared computer - in a hotel business centre, for example - this small device will record each user's keystrokes. Targeting a clientele of businessmen and women, the information collected is likely to be of a sensitive nature. If they are not transmitting strategic information from a professional point of view, they will probably be using it to book their flight, apply for a visa or check their bank account. So much valuable data for all kinds of fraudulent exploitation.
Poisoned gifts
Another common situation for professionals on the move: the business gifts. When signing a contract with a foreign partner, how can you be suspicious of a connected lamp, a memory card reader or a 2.0 clock? How can you refuse a potential partner a simple data transfer via their USB key? "Charging a device via a USB port is even a potential threat"says Nicolas Arpagian at Orange Cyberdefense. Last June, for example, at the summit organised in Singapore between Donald Trump and Kim Jong-un, journalists were given a media kit containing various practical items, as is customary. These included a small USB fan has attracted the attention of cyber-crime specialists. Given the forces involved, some observers saw it as a crude attempt at hacking. If examples of this kind were limited to meetings between the US and North Korean presidents, they would be very rare indeed. Unfortunately, this is not the case.
And what about Public WiFiTheir use is all the more irresistible because they are now everywhere, and most often free of charge. Many of their users no doubt complain about the registration protocols required to access these networks. But these are the bare minimum required to ensure a semblance of security while surfing. Whether it's the WiFi actually offered by an airport or convention centre, or a pirate network whose name makes it sound very official, business travellers have every interest in taking the necessary precautions. Caution, however, may not be enough in the case of a institutionalised intrusion Under the guise of national security, airport checks can lead to an extensive digital search. "In a number of countries customs services may try to retrieve the contents of the terminal"confirms Raphael BassetVice-President of Business Development at Ercoma French company specialising in digital security.
The increased risk and the media coverage it has received have served to raise awareness: business travellers have now clearly identified the threat they face. According to a study published in mid-August by the agency Carlson Wagonlit Travel (CWT)Less than one in five French business travellers (19 %) say they are sure they are not putting their company's data at risk while on business trips. Worldwide, the average is 35 %. For Raphael Basset, "there is a real awarenessBut this does not always translate into action. Companies have not necessarily adopted a real solutions dedicated to cyber security."
Preserving trust
Slowly but surely, specialists in the field are seeing the arrival of new adepts: "Three or four years ago, our customers were mainly government institutions. Then vital operators or essential service providers joined us. And now we're starting to get requests from large companies, consultancies and lawyers, because it's crucial for them to maintain their customers' trust.."
The anxiety-inducing environment also has the positive effect of making the cybersecurity market more buoyant than ever. This is attracting new players and stimulating innovation. One technology provider after another is launching into this field. Hub Onethe IT subsidiary of Aéroports de Paris, announced on 22 June the acquisition of Sysdreama French cybersecurity specialist. A few days earlier, Parnasse launched with Orange Cyberdefense A NEW OFFER to protect its members' devices and communications. This solution includesCrypto-Pass application developed by Ercom. This end-to-end mobile communications encryption solution secures the voicethe videothe mailbox instant and the audio conference.
Keep it simple
To reach a wider audience, Ercom has also teamed up with Samsung. "If we have launched into terminals Samsungis for their mass appealexplains Raphael Basset at Ercom. If the equipment offered to the user does not resemble the tools they are used to, it cannot work. The solution has to be as transparent possible."That's the challenge facing cybersecurity players, who have to develop reliable tools that don't affect the security of their customers. sacrosanct user experience. "We can build technological fortressesbut if no one uses them, we'll miss the targetsays Nicolas Arpagian. We need to build something that is technically powerful, but easy to use."
Nicolas Arpagian is quick to cite the example of Fleur Pellerin who, in spite of herself, provided an eloquent demonstration of the problem. In front of a television crew invited to visit her office, the former Culture Minister showed off her secure telephone, while admitting in the process, "I don't even know how to unhook it from its base". It is easy to imagine that this equipment, which is probably very reliable from a technical point of view, was not used very often.
Security must become a component of digital from the outset, not an option
For some experts, the challenge lies above all in the dialogue between the various players involved. "That's one of the problems at the moment: the digital and security industries are still finding it very hard to talk to each other.says Diane Rambaldini of Crossing Skills. They don't have the same aspirations, they don't see things in the same way. constraintI hope that we won't have to wait for dramas to arise around connected objects before dialogue opens up between these two worlds. I hope that we won't have to wait for tragedies to occur around connected objects before dialogue opens up between these two worlds.." Nevertheless, the consultant is optimistic: "this dialogue is going to have to open up, particularly as the RGPD provides for the security by designsecurity right from the design stage. We are already seeing the emergence of a new market, a digital offering that incorporates data security right from the design stage. Security needs to become a component of digital from the outset, not an option.."


















