Almost half (49%) of all businesses said COVID-19-related remote work worsened their mobile security efforts, and 40% list mobile devices as their No. 1 IT security threat, according to this year’s Verizon Mobile Security Index.

In its fourth-annual survey, Verizon found its lowest-ever percentage of companies that admitted to a mobile-related security compromise — only 23% of respondents compared to 39% last year. But, as the report authors say, “hold the Champagne. Nearly one in four companies suffering a mobile device attack is not cause for celebration.”

Meanwhile, the percentage of companies that said they sacrificed the security of mobile devices including IoT devices to “get the job done” and meet a deadline or productivity target increased from 43% in the 2020 report to 45% this year. Additionally, almost a quarter (24%) sacrificed the security of mobile devices to facilitate their response to restrictions put in place due to the pandemic. So it’s not very surprising that companies that sacrificed security in 2021 were 1.5 times as likely to experience a mobile-security related compromise.

“While businesses focused their efforts elsewhere, cybercriminals saw a wealth of new opportunities to strike,” said Sampath Sowmyanarayan, chief revenue officer at Verizon Business, in a prepared statement. “With the rise of the remote workforce and the spike in mobile device usage, the threat landscape changed, which for organizations means there is a greater need to hone in on mobile security to protect themselves and those they serve.”

Verizon Mobile Security Index 2021

For its 2021 Mobile Security Index, Verizon contracted an independent research firm that surveyed 876 professionals responsible for buying, managing, and securing mobile and IoT devices. This includes small companies and large enterprises from all industries across Australia, the U.S., and the U.K.

Despite the drop in known compromises, more than two-thirds of respondents said the risks associated with mobile devices increased over the past year, and half said that these risks are growing faster than others in their IT environments.

Additionally, it doesn’t look like the reliance on — and security risks associated with — mobile devices will slow down in the near future.

According to the report, 70% of companies that saw remote work increase because of the pandemic lockdowns expect it to fall again. However, 78% expect it to remain higher than before COVID-19. Overall, respondents say they expect the number of remote workers to settle at 48%.

Similarly, respondents said that nearly half (46%) of their IT workloads now run in the cloud, and 75% said their reliance on cloud-based apps is growing.

Companies Still Fail at Security Basics

But despite the expanded use of cloud services and mobile devices, most companies are still failing when it comes to security basics. Since Verizon started conducting this survey in 2018, it has tracked how many companies have four basic protections in place. These are: changing all default/vendor supplied passwords, always encrypting sensitive data when sending across public networks, restricting access to data on a need-to-know basis, and regularly testing security systems and processes.

Usually, in previous reports, around 12% of companies surveyed had all four basic security measures in place. This year, however, just 9% had all of them in place.

Looking ahead, as corporate data and applications live everywhere, across data centers, cloud, and mobile devices, and increasingly migrate between all three, Verizon advocates that businesses adopt zero-trust frameworks and secure access service edge (SASE) architectures to secure corporate resources. The report highlights three steps to zero trust network access — and supporting technologies for each step.

First, verify users. This ensures that users are who they say they are when they attempt to access corporate systems. Supporting technologies include multi-factor authentication such as biometrics and on-time passcodes.

Step two: validate all devices and confirm that the devices making requests are known, fully patched, and meet corporate security standards. Companies can use endpoint device management technologies and digital certificates to do this.

And finally, limit access to corporate resources even when a user is verified and the device is validated. This relates back to Verizon’s basic security measure around restricting access to data to a need-to-know or least-privilege basis. Supporting technologies to limit access include network segmentation and a software-defined perimeter.