© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Emerging Risks in a Mobile Environment Shared Assessments Roundtable November 6, 2012 Art Kirchoffer Executive Director – Risk Management AT&T
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Distracted driving Employee injury 3 rd party claim Electromagnetic Fields (EMF) / Radiofrequency (RF) Numerous studies; no definitive opinion FCC re-examining standards Limited insurance availability Wildfire Aerial cable exceeding capacity of poles Limited insurance availability Natural catastrophe COWS, SOWS and COLTS 2 Traditional Risks
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Consumerization of IT & BYOD/A/C Near-field communication (NFC) Mobile payments (ISIS, MCX, Google Wallet) Connected homes, cars & cities mHealth M2M (The Internet of Everything) Cloud Big data 3 Industry Trends (and emerging exposures)
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Smartphones, notebooks, laptops, tablets, other Data and privacy risk Device theft / loss iOS v. Android Abundant availability of applications Malware increasingly targeting mobile devices Social networks Intellectual property Short life cycle + constant change 4 Device and Application Risks (BYOD)
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Legal and privacy issues more complex than security challenges Lack of case law and legal precedence PCI Security Standards & HIPAA Logistical challenges of e-Discovery and ability to search for, collect and preserve data Device ownership and the right to seize Data / content / ownership Employee privacy Liability for employee personal activities Copyright / IP risk FLSA and wage & hour lawsuits 5 Legal & HR Considerations (BYOD)
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Externalization of business Line between organization and supplier is blurred Many of the risks are the same, but with less control Robust contract and supplier GRC program are best tools Burden of oversight rests with the organiza tion Supplier information security requirements should address mobile Insurance is good backstop 6 Supplier Considerations
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Management and security around mobile lags Exposure evaluation requires enhanced skill set Technology constantly changing No clear rules Untested insurance solutions Traditional P&C policies exclude losses related to intangible data Specialty cyber and E&O coverages have emerged Should address data breach and privacy issues for cloud and mobile Can extend coverage to suppliers Coverage cases and large claims have not tested these policies 7 Risk Management Challenges
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Establish policy around the RM process Training and reinforcement Not all data / users are created equal Policy should include / address: Employee agreement Expectation of privacy; personal content; usage monitoring Security (sign-on, encryption, back-up) Device / OS options and limitation Application access & controls Device disable, wipe and confiscation Stipend or reimbursement Records and information management Policy not airtight, but a step in the right direction Consider MDM & MAM tools 8 Mobile Device Risk Management
© 2010 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. 9 Itcanwait.com