June 30, 2010
Had a very interesting conversation this week about the evolving trust model for mobile security in the enterprise. I was talking to Terry R, who focuses on risk management and compliance, and he was telling me how his company’s perimeter security strategy needs to fundamentally change.
As he put it: “Our challenge is that our infrastructure, applications, and databases are designed for a perimeterized world. Our systems rely on a strong perimeter. We need to tear that perimeter down.”
The catalyst for the conversation was smartphones, which operate almost constantly outside the perimeter. Since the perimeter is no longer “reliable”, security becomes a matter of trust. Which device do I trust with which data for which user under which circumstance? The same questions, certainly, as existed before smartphone adoption. But the answers are now much more difficult to pin down. The trust model for mobile is a rapidly moving target. New operating systems appear every year. New devices appear every week. New consumer apps appear every minute. And end-users constantly set and change the debate.
How does a security team keep up? The more rigid ones will likely fall behind. The nimble ones will adopt a flexible mindset that can trade effectively between security and privacy, usability and control. Protecting enterprise data without compromising end-user experience will be the goal. A dynamic but rational model of trust that can operationalize the model below will be one of the important tools.

(Thanks, Terry, for the ideas behind this post)
June 3, 2010
No big surprise. After several months of media speculation, unlimited data is no more. In the battle of network-thirsty-smartphones vs. capacity-constrained-data-networks, the score is Smartphones 1 Networks 0.
Today’s AT&T announcement strikes me as more of a pre-emptive than reactive move, though. If currently 35% of subscribers already use more than 200MB of data per month, that number is only going to skyrocket over the next 24 months as smartphones outsell feature phones in the US and become the most common access point to the internet.
Clearly i’m now going to pay by volume of usage. But an unanswered question is what happens to service quality as the network load continues to hockey stick? Do I end up paying by volume and desired quality?
As the consumer dynamic evolves, two implications emerge for the enterprise as well:
- Real-time visibility into voice, SMS, and data usage becomes essential to prevent serious bill shock from overages
- Service quality monitoring becomes the best pro-active mechanism to protect the user experience, especially if network quality starts to erode
However, one of the major challenges companies will face is that you can’t control something you can’t see. Most users have no idea how many KB a web page download is or how much traffic answering those 50 emails generates. Without awareness, behaviors don’t change.
So in the age of variable pricing, visibility becomes paramount at both the individual and the corporate level. Hold up a mirror and show me what I’m doing so I can make sure it ain’t crazy.
May 28, 2010
With so many more economical choices for purchasing smartphones, more global workers now choose to bring their own device to work. That’s a double edge sword. Productivity increases but use of corporate data on employee owned devices translates into increased risk. What if the employee leaves and goes to a competitor? What if the phone is broken or lost? What happens when that employee phone connects employees’ friends, social networks, their media (illicit or virus laden), and games disguising network attacks. Telecomm is not prepared and IT is overloaded to deal with threats.
With nearly 50% of future phone purchasing moving towards smartphones, employers need a scalable solution to both manage and secure valuable corporate assets. AT&T executives also detailed this week that 40% of iPhones are now going into the enterprise. IT and Telecom are converging in their need for intelligent mobile device management that secures these assets while providing both a user and business view into costly bills. MIT Technology Review writes about Service providers harnessing mobile usage patterns this month as well.
By the end of 2011, a recent study from Nielsen states Smartphone deployments will be so rapid that there will be “more smartphones in the U.S. market than feature phones.” Smartphones show higher application usage than feature phones even at the basic built-in application level. During Nielsen’s Mobile Insights survey respondents noted in the last 30 days that users are taking full advantage of device application capabilities. Apple iPhone OS (32%) and RIM OS (37%) control more than two-thirds of today’s market while Windows Mobile, Android and Symbian account for the remainder. All OS and device suppliers are increasingly aware of the need for diverse business applications – apps that need to be securely managed at scale. The smartphone Tsunami is cresting and businesses are now realizing these mobile applications represent a significant increase in corporate data usage on devices never before managed. The next step for IT is proactive user, application and device management.
Mobile Data: A Gold Mine for Telcos
May 12, 2010
The FCC is following the lead of the EU and getting serious about data charges. There is a good article in GigaOm about this: http://gigaom.com/2010/05/11/fcc-seek-rules-to-avoid-24000-mobile-bills
The goal is to limit mobile data “bill shock” for consumers. I think of it as going for a 300-mile road-trip, pulling into the gas station, and realizing that gas is now $100 per gallon. If I’d known, I would have taken the train.
The basic issue is that consumers have no idea how much data is used when they browse a website, or stream a video, or download an email attachment.
We have two market forces crashing into each other:
- User appetite for mobile data grows and grows as smartphones become better and better at browsing and apps
- Operators get more and more concerned about the network infrastructure investments necessary to maintain service quality and keep up with this crazy hockey stick of usage
The “easy” solution is to charge, charge, charge, which constantly shocks the user and inhibits the expansion of the mobile internet. But to paraphrase the FCC: “You can’t control what you can’t see.” Real-time visibility into usage is the first step to both rational use and rational pricing.
But what about businesses? Don’t they face the same issues? Don’t they also need the same real-time visibility?
The answer is “yes”, their needs are similar. Each company’s IT or telecom group will need to put its own strategy together on how to rationally manage mobile usage and expense as-it-happens.
After all, the bill shock of my 300-mile road trip is a drop in the bucket compared to the cost of getting it wrong at the corporate level.
April 11, 2010
Was just commenting on a post over at http://theemf.org/ about the constantly increasing complexity of mobile in the enterprise, especially given the recent introductions of iPad and iPhone OS 4.0. This is both the beauty and challenge of our industry. From the user’s perspective, the bar for mobile capabilities keeps getting raised and the experience keeps getting better and/or different.
The challenge is that enterprises aren’t used to moving at this kind of consumer-speed. It reminds me of that old car commercial (I think it was Lincoln from the 70’s) where a jeweler is sitting in the back seat trying to cut a diamond manually while the car speeds along at 70 mph.
The “jeweler” is the IT department and we (i.e. the folks building tools and platforms to help) are the car suspension. And it’s going to take a heck of a suspension to avoid the potholes!
2010 is shaping up to be the most fascinating and unpredictable year we’ve ever had in enterprise mobility.
April 4, 2010
We’ve been doing app development at work for iPad, so I was really excited yesterday to check it out on launch day. But the most interesting thing happened when I brought the iPad home. My two oldest kids, 12 and 5 years old, gravitated to it like moths to a flame. The “wow, this is cool” fascination that lit up their eyes really stuck with me.
On one hand, both have access to a home computer, a laptop, and an iPod Touch, so it’s not that they haven’t experienced a touch interface or lots of apps before. But the special sauce here was simply (and most powerfully) the form factor – small enough to be easily portable and large enough to do the things they care about – games, youtube, surfing, and messaging. Suddenly computing was available in every room and on every surface (couch, bed, floor, desk) of our house.
I watched my two little prognosticators of the future and realized that, in their minds, our home computer was now officially obsolete.
March 3, 2010
Enterprise Mobile announced a hosted management service today for smartphones in the enterprise (built on MobileIron). http://bit.ly/ag8Y7u
There are a couple of interesting forces at work here. Gartner published research last December predicting “by 2012, 20% of businesses will own no IT assets.” The hypothesis is that the confluence of cloud computing, business process outsourcing, and the movement of smartphone/laptop ownership to end-users will result in a radically different IT model for a fifth of the business population. That’s actually staggering in its implications – IT teams get smaller, cap ex shrinks, custom development becomes obsolete, and end-user support models are truly virtual. It feels like smartphones are going to be at the front end of this shift.
Last year, IT departments spent a lot of time improving efficiency so they could continue to provide quality services in spite of shrinking budgets. The rapid adoption of smartphones during that time was great for end-users but in some ways the worse possible thing for IT, which now had to deal with a whole new raft of security, cost, and usability issues without any additional resources to throw at it.
That’s why I think the Enterprise Mobile announcement is really interesting. There is huge variability across enterprises in both capabilities and mindset for managing smartphones. Some want it on-premise, some want to outsource it. Some want just email, some want apps. But they all want choice because the smartphone market is moving far too fast to be predictable.
December 14, 2009
IT can’t do it alone. Smartphones are coming in from all directions, many times driven by end-users. And I haven’t seen many IT departments in 2009 flush with new resources to handle this influx as well as they would wish. Employees need to share the responsibility with IT to manage security, cost, and mobile apps. Think of it as self-governance guided by IT policy.
The basic notion of Cooperative Mobility is that most users want to do the right thing but don’t have the data or the tools to always make the right decision. Cost control is a good example. Everyone has their horror story of the $5,000 international roaming bill. Usually it’s not voice – it’s data, because the user just didn’t know how much data traffic email and browsing actually generates. In almost all instances, real-time visibility would have dramatically cut usage.
But which behaviors can be realistically changed and which require tighter control from IT? And what is the cost trade-off? If the premise of Cooperative Mobility is correct, striking that balance will reduce IT costs, scale IT effectiveness and actually increase user satisfaction by pushing more visibility and control to the perimeter.
November 19, 2009
MobileIron won Best in Show at Under the Radar today! Here’s a link to the presentation we gave: http://www.undertheradarblog.com/ I am really proud of the hard work the team has done to get us here.
It was an honor to be invited to Under the Radar. There were some awesome mobile startups there and I learned a lot from watching what others were doing.
I thought these guys http://www.m-via.com/ were solving a fascinating challenge of money transfer from US to developing countries over the phone. And these guys http://hopephones.org/ were collecting old phones and using them to provide better medical care in developing countries - that’s impact.
Plus I met Greg Grunberg, who plays the mind-reading cop on Heroes and is both a really nice guy and a mobile entrepreneur (http://getyowza.com/). A cool day.
October 16, 2009
Network World runs the Insider Threat column bi-weekly and gave us the opportunity to contribute to today’s column. You can find the column on the Network World site at http://bit.ly/3gPlQp .
Existing models for smartphone management take a very one-way approach to security. IT ends up being the police force and it’s a role that is not scalable, especially since users are reticient to give up control of their phone to begin with. Employee-owned phones just make the problem worse.
The central theme of the column is that responsibility needs to be shared in order for behavior and data to be secured. This model of Cooperative Security requires both a change in mindset and policy, plus access to tools that support both.