In recent years, Cyber Security Issues for Business Travelers
have become a very hot topic in the cyber security industries.
Malicious actors are cleverly attempting to extract sensitive
company information and personally identifiable information with
the combination of illegitimate Wi-Fi access points, phishing, and
watering hole attacks. All traveling employees and c-suite
executives are at risk of compromise. Cyber security team have
devised a plan of action for all company personnel, in mitigating
and minimizing the risk of compromise when on the road. By
incorporating personnel training on cyber awareness, regular
security updates of devices, and use of software tools in securing
the mobile devices.
All personnel on travel should take cyber security
awareness training on travel related cyber threats, such as
spearphishing, whaling, DarkHotel and Video Jacking. A monthly
newsletter of cyber security threat that highlights the present
trends and threats would enhance end user awareness as well as
serve as refresher on proper risk management while on travel.
Signing up to Cybersecurity & Infrastructure Security Agency’s
alerts and tips email, grants access to short articles such as
“Cybersecurity while traveling”, a brief yet informative bullet
points on how to stay protected on public networks. Through
training and monthly awareness, all traveling personnel should
recognize the risks of public access points such as “free Wi-Fi” at
airports and hotels, as well as common threats such as email
phishing, spearphishing, and whaling. Users should be aware that
business related communications and personal communications
should be segregated to company supplied devices and personal
devices (Hoelscher, 2021). Most importantly, users should be
aware to not leave any of their devices unattended at any time in
unsecure areas (CISA, 2019). With the end user’s trained and
aware of cyber security best practices while on travel, the
organization would be better protected from information leakage
and compromise, as well as protect the PII of end users.
While users should follow best practices while on
travel, the organization’s IT team can also practice and prepare
the end user devices to mitigate such threats from adversaries. IT
team should regularly apply security patches and software
updates to all company owned devices, not limited to desktops
and laptops, but also tablets and smartphones. All devices should
have encrypted drives, that can only be read by credentialed
users and device. The IT team should provide users with
password management software that enables copy and paste
passwords to deter key logging attempts on public access points.
Disabling insecure methods of communications such as https and
SSLv2/3 will be critical in keeping man in the middle attacks from
taking place (Murphy, 2014). The IT team can also use other
monitoring tools to further assist in protecting the confidentiality,
integrity, while keeping the availability for the end users.
Some of the tools IT team can deploy to ensure
confidentiality, integrity, and while maintaining availability for the
end users are VPN, company provided mobile hotspot, MDM
solutions and multifactor authentication methods. While VPN may
not offer perfect protection from attacker, it does offer more
secure communication between the end user to the company
resources, and cloud services. Many man in the middle attacks
can be avoided by encrypting the message being sent from the
end device. Multifactor authentication such as using USB/RSA key
for login, or CAC login can severely limit attacker’s ability to login
to the device or business-related accounts (Murphy, 2014). MDM
solutions provide the last-ditch effort in tracking a stolen device,
and the ability to secure wipe the data on set device. Many
MDM solutions have the flexibility to enroll different mobile
device types, such as laptops, tablets, and smartphones. It is
important that IT team prepares the devices to be secure while
not limiting the ability of end users to perform their duty on the
road.
With the devices prepared for secure authentication and
communication, as well as contingency planned by the IT team,
the end users’ risks will be greatly mitigated while maintaining
great availability to access the necessary resources while
traveling. End users should not solely rely on the security
measures taken by IT team and should be trained and prepared
for the potential threat vectors while on travel. These measures
should significantly reduce the attack surface and maintain
confidentiality, integrity and availability of the organization and its
resources.
References
CISA. (2019, December).
Cybersecurity while traveling
.
Cybersecurity & Infrastructure Security Agency.
https://www.cisa.gov/sites/default/files/publications/Cybersecurity-
While-Traveling-Tip-Sheet-122019-508.pdf
Hoelscher, P. (2021, November 28). 30+ cybersecurity tips for
travelers. Infosec Resources.
https://resources.infosecinstitute.com/topic/30-cybersecurity-tips-
for-travelers/#gref
Murphy, B. (2014, November 4).
13 Mobile Device Security Tips
for Foreign Business Travelers to China | RedZone
. RedZone
Technologies. https://www.redzonetech.net/blog/13-mobile-
device-security-tips-foreign-business-travelers-china/
Schlesinger, J., & Day, A. (2016, September 21).
Travelers beware!
That free charging station could hack your phone
. CNBC.
https://www.cnbc.com/2016/09/21/travelers-beware-that-free-
charging-station-could-hack-your-phone.html