What are the actual security risks of OS X for businesses?

Security lagging behind

Another issue is endpoint security and David Flower, EMEA managing director of Bit9 + Carbon Black, says in the enterprise this is lagging behind Windows.

"Despite the fact that Mac OS X is becoming increasingly popular for enterprises, there are still significantly fewer security solutions available to protect it. The built-in security mechanisms for Macs are as good as those for Windows, but to combat today's advanced threats, the ecosystem needs to be stronger," he says.

Flower adds that most security solutions in the Mac ecosystem are signature-based, which just isn't sufficient for dealing with advanced threats. "Signature-based defence works well against known, documented threats, but just can't handle today's Advanced Persistent Threats (APTs)," he says.

He says that it is crucial that companies bear in mind that hackers are deliberately targeting them. "They'll be looking for any vulnerabilities or weak links in the security chain. Despite being less familiar with Mac endpoints than they are with Windows, they may well target them because there just isn't as much security to bypass," says Flowers.

Yosemite

Keeping on the latest version of OS X is crucial

Is Yosemite safer?

Munro says that updating OS X to the latest version, Yosemite, is crucial to avoid some vulnerabilities. Also, knowing which version a Mac is running would be helpful too.

"If you have no idea what OS X version a Mac device is running, and how well updated it is, it could well be vulnerable to the Firewire/Thunderbolt encryption bypass attack, enabled by the Inception tool. Recent OS X and FileVault versions are okay, but older versions (Lion 10.7.2 or previous) are open to this abuse. So updating is crucial," he says.

Password problems hit Active Directory

Munro says that with Macs something as straight forward as a password refresh can cause real headaches.

"One corporate environment I was in recently had a Mac/Windows base that used Active Directory (AD) for managing users," he says. "They had a large amount of problems getting Macs to change passwords on password expiration. This meant that all of their Mac users ended up with static passwords, of which most of them were the default set by the helpdesk. This lead to half the users in AD with a password of 'Password1'. So, there will be issues with integration between different technologies – make sure this is worked out before it goes live."

Protecting your organisation's Macs from threats

What an organisation does to protect its Macs from secuirty risks depends on how many there are in the network, according to Munro.

"If there are only a smattering of devices then you should audit them by hand. Review OS versions, check patch freshness, review apps etc. and draw up a simple policy for maintenance and use," he says.

Munro adds that if there are more than a handful of Macs then an enterprise really should have the policies and software in place to diminish the risk.

"In our experience it is the organisations with huge numbers of Windows boxes and just a few Macs that suffer the biggest problems in this respect. If I wanted to target such an organisation the least supported/most neglected desktop OS would be my favoured vector," he observed.

TOPICS
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike