By Scott Aurnou
Literally speaking, ‘endpoint security’ refers to protecting the various electronic devices that can connect to a computer network. Each device that can access a network creates a separate endpoint that has to be secured. This can include anything from cameras to printers or anything else connected to the network though, for most people, endpoint security means protecting laptops, smartphones and tablet computers against various electronic threats, as well as physical ones (like being stolen). In practice, this means trying to put in place an equal minimum level of protection for every device capable of accessing the network. To enforce this, a network may be configured to only allow access to devices that have certain specific security measures in place before connecting to the network and potentially accessing proprietary information and/or sensitive data. If an infected laptop, smartphone, tablet or portable storage – like a USB thumb drive – does connect to the network, it could upload malicious software (aka malware) or expose sensitive data from the network once it’s downloaded to the improperly secured phone, etc.
While this may sound like a relatively straightforward process, it’s often one of the weakest spots in any computer network. This is because of an increasingly common workplace concept referred to as Bring Your Own Device (aka BYOD). Employees, guests, consultants, students, doctors, co-counsel, family members, etc. frequently use their own laptops, phones and tablets and generally expect to be given access without the ‘hassle’ of having them checked first or downloading security software before exposing the network to whatever unfriendly software is lurking on their devices. An infected device can easily spread malware like a computer worm that, by design, will self-replicate, spread throughout a system and create openings additional malware like rootkits and Trojans (all things you would definitely rather not have on your network).
Read more ›