Guarding the gateways: how unsecured apps put your business at risk—and what to do about it

  • Defence
  • Cyber
  • Cybersecurity

© Ercom-Illustrator

  • Type Insight
  • Published

In an era where nearly every employee brings their own device to work and business relies on a myriad of mobile applications, even a single unsecured app can be a cybercriminal’s golden ticket. Earlier this year, the removal of infected apps from major app stores underscored a troubling reality: application vulnerabilities are among the most common routes for attacks on company information. With almost a third of cyberattacks exploiting these weaknesses, understanding the risks—and how to mitigate them—is critical for any organisation determined to secure its digital frontiers.

Last February, Apple and Google removed around twenty mobile applications from their stores. These apps were infected with malware that stole users’ data. Applications are a very common entry point for cybercriminals: nearly one‑third of attacks exploit application vulnerabilities to access a company’s information system.

At the same time, 84% of organisations observe that their employees work from personal devices. What are the different cyber risks linked to unsecured applications? What best practices should be adopted to identify risky applications and ensure the security of your organisation’s data?

The dangers of unsecured applications

An application can expose your organisation in several ways. Some are poorly designed technically, others do not integrate sufficient security mechanisms… There are also malicious applications designed to spy, collect data or carry out cyberattacks. Here are the main risks of an unsecured application:

  • Data collection: Some applications collect a large amount of data such as contacts, geolocation, browsing history, etc. Sometimes this collection is mentioned in the app’s terms of use, sometimes it is carried out without the user’s knowledge. In both cases, it represents a threat to the confidentiality and security of your data, which may then be sold, exploited or disclosed.
  • Abusive permissions: Malicious applications often request access that is disproportionate to their function. For example, they may demand access to SMS, the microphone or the camera. If such permission is granted due to lack of vigilance, the application can then spy on the user and capture confidential information.
  • Unpatched vulnerabilities: These flaws are exploited by cybercriminals to exfiltrate data, execute remote code or obtain privileges to access more sensitive information. The most at‑risk applications are those that are no longer sufficiently updated by their developers.
  • Interception of communications: Many applications do not ensure data encryption. If the user connects to an unsecured network such as public Wi‑Fi, hackers can intercept, view and modify the information exchanged. This is a significant risk for employees on the move or working remotely.
  • Malware installation: Some applications may contain malware used by cybercriminals to access your data, record keystrokes, activate the camera remotely or even take control of the device. A single compromised device can become an entry point into your company’s network and serve as a vector for a ransomware attack, for example. To deceive users, some hackers do not hesitate to clone well‑known applications.
  • Shadow IT: Employees may install applications without informing the IT department and use tools that are not approved or devices that are not authorised (phone or PC). Beyond the significant security risks this practice entails, their use escapes your supervision and may not comply with your internal security policy or applicable regulations.

What best practices should be adopted to secure application usage?

Your organisation can implement several best practices to protect itself from the threat of unsecured applications:

  • Integrate security components directly into devices, such as full encryption of all communications, a VPN to secure browsing, or control of various ports (USB, Bluetooth, Wi‑Fi…).
  • Adopt a Mobile Device Management (MDM) solution: 
    This tool allows the IT team to remotely manage the entire mobile fleet from a single interface. It is possible, for example, to configure devices, perform application updates, block certain applications or delete data in case of theft or loss.
  • Implement a controlled BYOD (Bring Your Own Device) policy: 
    Rather than completely banning the use of personal devices—which will likely continue regardless—authorising BYOD with clear rules helps reduce risks. For example, define the types of authorised devices, list the applications and resources employees may access, and specify mandatory security measures (encryption, MFA authentication, VPN, etc.).
  • Maintain good digital hygiene: 
    It is important to systematically install application patches to fix vulnerabilities as soon as developers release them. Likewise, refusing unnecessary access to certain device functions or applications helps protect the confidentiality of your data.
  • Raise employee awareness: 
    There are good reflexes to adopt to identify a risky application. First, check its rating on the store and read user reviews. Then, ensure the application is published by a known and verified developer. Finally, pay close attention to the permissions requested: for example, a professional note‑taking or project‑management app has no reason to request access to your contacts, messages or real‑time location.

Conclusion

The security of applications and communication tools is a critical issue for protecting your organisation’s data. Our Cryptosmart Mobile solution enables the deployment of a robust ecosystem to secure smartphones and tablets intended for professional use. This is made possible through the integration of several security mechanisms such as full device encryption, a sovereign VPN, local protection with port control, as well as the management of authorised applications and their associated permissions.

Approved “Restricted Distribution”* by ANSSI, Cryptosmart Mobile meets the requirements of sensitive environments while remaining simple to deploy across a large fleet of devices.

*Renewal in progress