Mobile Security: User Experience is the Key to Success

If mobile security measures aren’t easy to use, users won’t use them, say leading CIOs.

“When it’s not usable, users make stupid decisions.” With that statement, Janne Uusilehto, head of Nokia product security, pretty much summed up the most critical part of mobile security implementations: if users don’t use it, mobile security doesn’t work.

Uusilheto’s remarks were part of a great panel at the RSA Conference in San Francisco this week, where big-company security executives talked about the state of the state of mobile security. Though there was plenty of in-the-weeds discussions about topics like web apps versus sandboxed apps, and the ability to secure devices at a hardware level, the single point of agreement between the panelists revolved around the user experience — and how CIOs and others might make security measures easy enough to ensure they get used.

“As much as we try to give them [users] the safe thing to do, if there’s a cool new app out there, I know my data’s in that app,” said Dave Martin, vice president and chief security officer for EMC, when asked what keeps him awake at night. The rapid pace of innovation on the device and consumer app front, Martin said, means that folks trying to secure those products and services “are never going to be able to catch up.”

Maybe the most informative takeaway I had was that even though the security officers at big companies have plenty of power, they all seemed more concerned about preserving the user experience than shutting down functionality in the name of security. There were some exceptions, of course, like the government representative who joked that his agency’s BYOD policy consisted of a lockbox at the front door of headquarters, where employees could “bring their devices” and leave them there.

For the enterprise security officers though, the functionality of the new class of mobile devices and apps are already seen as being extremely important to their companies’ business, and they said their objective is to make security measures as easy as possible to use. Right now, that means a lot of trial and error and sound judgements, the kinds of things that smart CIOs use to enhance their corporate standing.

When it comes to mobile security, “we’re learning and iterating,” said Malcolm Harkins, vice president and chief information security officer at chipmaker Intel. “We’re seeing how people use [mobile devices] and understanding the user models and shaping the paths to manage risks,” said Harkins, who expects his company to reach a 70 percent BYOD figure sometime soon. Some of the security measures, he said, start with having to “put a stake in the ground and see what the reactions are.”

Sounds reasonable, and a measured approach. Keeping the user experience front and center is probably the best way to ensure that less stupid things happen.

About Author

Leave a Reply

Your email address will not be published. Required fields are marked *

Single Column Posts

Single Column Posts Subtitle

Why Every Online Business Needs a Terms of Service Agreement

Running an online business comes with a unique set of legal challenges. Whether you operate an e-commerce store, a SaaS...

Enterprise Mobile Security: Protecting Your Business in a Mobile-First World

Mobile devices have become the primary endpoint for enterprise work. Employees check email, access cloud applications, approve workflows, and handle...

How Enterprise Organizations Use Keynote Speakers to Drive Leadership and Culture Change

Enterprise organizations today face a paradox: they have more data, more tools, and more connectivity than ever before — yet...

How Professional Product Photography Drives Mobile Commerce Sales

Mobile commerce is booming. With more than 60% of online shopping now happening on smartphones, enterprise brands and SMBs alike...

How LVN Programs in Los Angeles Prepare Students for In-Demand Healthcare Careers

Growing Demand for Licensed Vocational Nurses in California California's healthcare workforce continues to face a significant shortage of qualified nurses...