
In our last episode, we discussed how data encryption helps deter malicious actors from accessing and using your sensitive data. With the help of our cyber expert cast, we learned how encryption mitigates the risk from bad actors and prevents compromises when the other lines of your cybersecurity defense fall short.
Today, as we take a greater look at the importance of mobile device management, you may ask yourself what does your laptop, smartphone, refrigerator, Fitbit, and Alexa all have in common? With the rise of BYOD in the workplace, these connected endpoints are freshly unique attack vectors ready for malicious actors to exploit. Here in episode 12, learn how to monitor and protect your workforce’s devices with help from our cyber expert cast from Cisco, JumpCloud, and TBI. We’re thankful to our partners for joining the “Who’s In Your Cloud?” series as they help us educate our clients and prospects on the road to #secure, reliable, trusted technology!
As a reminder, we began releasing a new episode every Tuesday, starting 10/20/21, and will continue to do so through late spring of 2022, with brief time off for holidays with family and friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational and enjoyable experience. So how do you tune in?
To easily follow the journey ahead, we’ve diversified your access options to all (23) of our coming episodes. You can follow along here on our blog or by any of the following methods:
- Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
- LinkedIn: follow here
- YouTube: follow here
- Facebook: follow here
- Podcast: follow here
Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!
Read Transcript
Welcome back to “Who’s In Your Cloud?” 21 Steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose. And we are back again for Episode 12: Mobile Device Management. So what does your laptop, smartphone, refrigerator, Fitbit and Alexa all have in common? Wrong, they are connected endpoints vulnerable to compromise by malicious actors. Given the fact that you’re probably watching this from your smartphone, this is one topic of our TOPcyber21 best security practices you’re not going to want to miss. But really though, you’re not going to want to miss any of these episodes, because what would you do without your weekly dose of me? Before we get into it, make sure to like and subscribe to our YouTube channel down below. It really helps us out. And while you’re here, check out our entire “Who’s In Your Cloud?” series in our playlist above. We post every Tuesday, except when we don’t, to LinkedIn, Facebook, YouTube and Spotify and get episodes delivered straight to your inbox by signing up at TechOnPurpose.net/blog. In 2020, there was a mass exodus from the business office to the couch office. Here we are in 2022 and businesses are still struggling to minimize risk and adapt their cybersecurity practices to this changing workforce landscape. Managing all endpoints can be a daunting task, especially with so many new devices in different locations and business owners not realizing just how wide this net really is. Without further ado, let’s have our cast of cyber experts tell us more. First, we have the one and only Jim Bowers, Security Architect from TBI as our VIP guest today. Jim you’ve been back so often, if I didn’t know any better I would think that you’re auditioning for my job. So sit down Know your place. You might need a little more hair and more makeup for my job. All right, from our JumpCloud partner, we have Principal Strategist, Chase Doelling. Welcome back, Chase.
Chase Doelling
Thanks. Happy to be here.
Lauren Lev
And from Cisco we have Yisbel Calzada , Systems Engineer. Good to have you again, Yisbel.
Yisbel Calzada
Thanks for having me back, Lauren.
Lauren Lev
Of Course. And of course, TechOnPurpose Founder and CEO rocking that merch, Matt Tankersley.
Matt Tankersley
Hey, thanks, Lauren. I’m certain of all of our top- Well, first off, guys, welcome back. It’s good to have you. Obviously, we love each of these partners. We work with you all day every day, as we obviously recommend most of our clients here as well. And we’ve got ways for you to do that. So why would you do that? Well, that’s part of the reason why we’re having this series. So of all of our TOPcyber21 topics, you know, everyone can be rightly classified as a can of worms. And you know, each one is worthy of deep thought and consideration and discussion. But we’ve got only 50 minutes here. So we’ll get focused and into it with our cast promptly. How about that? So to get us started, let’s put it into context once more, the massive migration of our workforce, Lauren talked about that. From working in the office to working from home and everywhere else. Now you mix in the influx of countless types of new devices, including BYOD (Bring Your Own Device). And we’ve introduced some very unique attack vectors that are ripe for malicious actors to exploit. So as companies are transitioning into these workplace strategies, these unique security challenges must be addressed. And one of the most important parts of that isn’t just do I have that device secured? How am I managing it? Right? And endpoint security is going to be looking more for malicious kind of activity going on those devices. Maybe you’ve got some EDR/XDR and it’s monitoring logs and looking for malicious activity. But how do we just sort of prevent that in the first place using some things like geographic location? Right, what network am I connected to? Is it wired? Is it wireless? Is it a company device? Or is it my device? That’s mobile device management. And that’s what we’re here to talk about today. And so, Lauren, I say, take it away, and let’s kick it off to the folks that know a whole lot more than I do.
Lauren Lev
And a whole lot more than I do too, so before we dive into it, Jim, you’re up first, remind us who you are and what you do.
Jim Bowers
Lauren, thanks again. And gosh, I love being on these video blogs. TechOnPurpose, I love you guys. Love the TOP21 security, but Jim Bowers, Security Architect at TBI. TBI is a technology distribution organization. I’m responsible for not only providing architectural resources for our 4000 partners, but also designing and developing our security vendor portfolio. You know, it’s very relevant for these types of solutions for all of our partners. But glad to be here, love being here. Anytime you want me here, I’ll be here. You guys are awesome. Thanks for having me again.
Lauren Lev
Careful what you wish for. All right, who is Chase Doelling and what does he do at JumpCloud?
Chase Doelling
Great question. Sometimes we try to figure that out every day. But for the most part, you know, for those that are not familiar, JumpCloud- So we’re a cloud directory. But what’s interesting about us is we’re able to combine a lot of that cloud identity access with how we’re managing devices and other resources and helping enable a lot of organizations, you know, either deal with remote or coming back in the hybrid, or whatever your flex is, right. But for us, managing those devices is crucial. We often think that devices are the gateway for a lot of work to be done, and so excited to dive in a little bit deeper and see what that looks like.
Lauren Lev
Perfect. Yisbel, you’re up next.
Yisbel Calzada
Thanks, Lauren. So what I do at Cisco Meraki, I am the System Engineer covering all US South East regions. So for customers that are basically looking to start or continue their IT journey on the cloud, I’m the technical point of contact or the trust advisor that will guide them through the trial showing them powerful and simple ways to manage and deploy their IT infrastructure or platform. For those that don’t know what Meraki is, we deliver cloud managed IT solutions, like for an SD1, Cloud, firewalls, switches, IoT, cameras, access points, and of course, mobile device management solution. So basically, we optimize that IT experience, which is our main goal to secure the locations and centrally connect people, places and things.
Lauren Lev
So Jim, help us out. Explain to our audience what mobile device management is and why should we care?
Jim Bowers
Mobile device management- So Mobile Device Manager is really the ability for an organization to put some type of controls and mechanism around mobile devices. And now really, the next iteration of that is universal endpoint management, right? It’s taking mobile device management and including that into our laptops, our desktops, our Windows machines, our Apple machines, and now ChromeBooks, and so forth, right. But it gives the ability for an organization to put some parameters and controls around it. And let me kind of talk a little further about that. And that’s, let’s say, you want to lock down the USB port. You don’t want somebody plugging a device or something into the USB port, you can do that with a mobile device management solution. Let’s say: for example, like the Meraki solution, which I have deployed for a very large, fast food chain that starts with a chick- I won’t go any further than that, but it enables them to have a lot of employees that are out using iPads. So they can restrict what is installed on those iPads, what they can use. Maybe I can’t use my camera, maybe I don’t want you to take a picture of their cars. Right? I learned the hard way when I started working at Secure Works. I actually had gotten my new laptop, which had universal endpoint management on it, and I decided to plug an external USB hard drive into it. They had some movies because I was in Atlanta and wanted to watch some movies, and then all of a sudden it started encrypting my drive. So I was not able to and it corrupted my drive because I yanked it out too quickly. And I wasn’t able to watch my movie. So especially in today’s environment, with this huge influx of remote workforce, it’s more critical than ever today, simply for the fact that the huge increase of BYOD devices. Matt, you talked about it earlier, those are devices that are corporate assigned. So this provides them some ability to provide some protection in and processes and in restricting things on devices they go on to. So it’s a very critical component in your TOP21 Security.
Lauren Lev
Yisbel, over to you. What is your take on mobile device management?
Yisbel Calzada
Absolutely. So with the mobile device management, kind of like adding a little bit more what IT says it allows it to manage, secure and deploy corporate resources and applications on any device from a single console providing full visibility into the status of those applications that have been deployed, the data points and connections as well, while also collecting data that helps to evaluate performance metrics and execute corporate policies across the network. As we know, open endpoints these days are a threat and can become an easy target for hackers. As organizations have expanded their digital footprint to the cloud, or enable remote workforces without an MDM solution, IT administrators struggle to track, update and secure all those devices that they connect to their business network. So we normally know that when we actually are on premises or administrators trying to scan the network and while the critical to high vulnerabilities are often prioritized, it’s actually the medium or low vulnerable devices that can place risk in your organization. So overlooking these vulnerabilities on say, like a printer, or medical equipment, or an iPhone that hasn’t been upgraded lately, or other connected devices is what enables threat actors to gain entry in your network. I will say, like 55% of organizations have recently reported an increase in their endpoint security risk. If one hacker infiltrates a single remote laptop, they can access an organization’s network files, sensitive information, or data and potentially paralyze the business. So what an MDM solution can offer is it will increase the visibility. So obtaining a complete view of all the endpoints like Apple’s iOS devices, Android devices, any device that could be owned by the company, or could be as well, what we normally call be BYOD device or customers own devices, since we know that our organization as well has expanded to or let the customers/the users bring their own devices and connect to the network as well and building residents. So basically, for corporate owned and managed systems that can be deployed to distributed workforces, and organizations as well, like I mentioned, allow those personal devices into the mix. Each one can be incorporated into the safety of the network using corporate approved policies, software and security measures.
Lauren Lev
You just reminded me that I need to update something, so that’s important, thank you. All right. Chase, over to you.
Chase Doelling
Well, I don’t have too much to add on to that. I think just to boil it down. Usually what we’ll think about is, it’s the ability for organizations to have visibility and then take action, right? Visibility on what’s happening on the device, who’s on the device, who’s doing what, what applications are there? And then the important piece of taking action, right? And this, for the most part, we’re thinking about preventative action, right? So blocking USBs, encrypting drives, making sure that all those elements are put together, but making it easy for organizations to essentially deploy that. Because when you’re thinking about, you know, the evolution of MDM, right, because typically, it was like, Oh, the traveling salespeople don’t worry about that like people just kind of get we need to see what’s happening, right, in case they leave it on a plane. But now, for most organizations, and let’s say most people on the call, right, this is like, that’s the only device that you have, right? And it’s the only thing that’s kind of given from the organization. Even though I’d say a lot of intellectual property, and other things are now starting to reside on third-party apps, there’s still a lot of components, it’s still the biggest attack center because it’s the only one, right? It’s the only thing that we have in front of us. And there might be a little bit of a mix depending on, you know, phones and other things, kind of if you want to think about access points coming from there, but it’s just the ways for organizations to kind of manage everything that they can get access to, right? And making sure that it’s visible within the network, so that you can start to, you know, hopefully put a good foot forward, but then also, you know, take reactionary measures if you need to.
Matt Tankersley
So Lauren, I think we’ve talked a little about what MDM is, right? And we’re going to jump in as we usually do. And we’re going to ask each of our cast members to tell us a little about their unique solution and their unique approach to MDM. And for our viewing audience, let me throw a couple of thoughts at you right now. And if any of this hasn’t just clicked, because hopefully, you’re not doing IT all day, every day. Hopefully, you’re out there running your business. And, you know, and selling dogs that get up on people’s keyboards and cats and you know, dry cleaning, and you know, whatever it is your business does that’s not IT, right? So a lot of this stuff might fly over your head. But imagine that you’ve got this workforce that used to all come into the office and whatever IT infrastructure and team you had, it was all sort of contained in that building. And now you’re waking up and you’ve got this workforce that’s working in their PJs at home or from the Starbucks down the street. And they’re not just using devices that you’ve issued, but there’s other devices, right? And imagine, you know, the idea of how quickly you can onboard them to have the applications that they need on that device to do the job? And how much data do you want them to be able to have and store on that device? If it’s their device versus your device? What happens when that person leaves? Right? And they’re no longer going to be an employee? How do you get that data off of that device and remove those applications and free up the license for the person that’s gonna replace that person to the point that maybe you’ve got somebody out there that’s, you know, God forbid, just doing the wrong thing you know they shouldn’t be. And the ability to hit a button and instantly lock them out of that device, right? We did mention that somewhere along the way- Imagine you’ve got important data on a device and that device gets stolen. Right? Well, there’s finding that device, there’s the whole insurance implications of that different topic, different day, but imagine if you can wipe that device completely. So even though it’s been compromised, the second they turn it on it comes on, and now they’re sitting there with something that won’t even boot. Right? That’s the application for you listeners on what we’re gonna be talking about MDM, and it’s kind of just the tip of the iceberg. And so, Lauren, let’s follow your lead. We’re going to go around the room and end with Jim and talk about specific solutions that each of you brings- JumpCloud, Chase, and Meraki. And then Jim will close us out on the topic when we get towards the end. And as always, questions and answers jump in, guys.
Lauren Lev
Perfect. Okay, before Jim and Yisbel take all the good lines, Chase, you can go first and talk about JumpCloud’s solution to MDM.
Chase Doelling
Yeah, absolutely. I think there’s a couple different ways that we think about it. One of the elements that make us a little bit more unique is that we cover multiple different operating systems kind of all at once. Which is really helpful because most organizations aren’t fully windows, aren’t fully Mac, maybe there’s some Linux infrastructure there. And the beauty around JumpCloud is we’re able to manage all of those different pieces kind of within one view, leveraging our agent. So that’s nice, right? But then the next piece around that is how we’re able to combine identity and access management with managing those devices. So because we are also the directory, we’re also having kind of that person’s profile living locally on that account. And so, kind of when you’re thinking about it from an offboarding scenario, right, if you go to the extreme example, you can imagine that where you’re removing that identity from the device you’re removing, wiping the device clean, kind of all those other pieces. But it also allows us to do some nights, like I’d say just basic things for organizations where you’re able to lay down policies like fully encrypting the drive, making sure that you’re, you know, blocking USBs, changing background colors. Like all of those different things coming from one area is really nice and easy. And I think that’s one of the pieces that we spend a lot of time thinking about. Because it is like, you know, the device is the gateway for everything and for a lot of people to get their jobs done. And so, if there’s a way that we can trust that device, right, making sure that their certificates are on it. And we’re also able to do some interesting things where you can actually change your password on the device, right? So you don’t- if there’s emails or spoofing, kind of like doing password changes, you know, that you can go directly from the device level to have that done. And then finally, in terms of getting employees in the door in the first place, right, because a lot of us are working remotely and other things. What we’re able to do is actually dropship those things and because our identities already on that, you’d have an amazing onboarding experience where you can open up the box, you type in your JumpCloud password and you have access to everything there because software has been downloaded, network access has been granted, all of those applications are there ready for you. And so, you’re actually teeing your employees up and new employees for great onboarding experience, while maintaining a seamless security pro throughout that whole process.
Lauren Lev
With that Yisbel, you’re up next.
Yisbel Calzada
MDM with the Meraki solution, or normally called System Manager- besides offering the support of the variety of the platforms like iOS, Windows, Android, TBOS, ChromeBooks as well as the manage of the features that you can actually set or block under the devices. What distinguishes Meraki MDM solution as well is that it’s basically natively integrated with the Meraki portfolio. What I’m saying what that is like is you can actually use sentry enrollment to integrate with Meraki access points, which enables network administrators to only allow devices that have been enrolled in System Manager to access the network or provision using a zero touch deployment through our user self service portal as well as the sentry WiFi. So the settings that can be automatically put into the devices to allow them to connect to the whitelist that has been set up or configured in the network using certificate based authentication or provision unique certificates. Without the need to manage a certificate authority as well as central VPN for those customers that already have a Nexus Deploy and already have the user or client VPN or enable client VPN for those remote workers. That can be like in a hospital, connecting to an outside hotspot. That we know- how unsecure those networks are. You can actually put those those configurations and provision out automatically as well as manage the AnyConnect installation of those devices to have more security on those sentry policies. So with the network settings, such as firewall rules, traffic shaping policies, that a customer already has owned or the network as well as content field three can be dynamically changed and push to those mobile devices using mobile identity information, network access control, all those type of updates. And then also where it comes as well with an MDM solution, how you can actually manage those patches for your devices, for your windows, your Mac, how you keep your devices up today. You can actually create profiles for your devices, depending on what the roles of the end users in your network are and you can set certain restrictions. Like you mentioned before, don’t allow them to use cameras, contain the information for those applications. So when you’re pushing it to those devices or applications that have been already installed in the device, it’s how you allow them to share that information and you allow them that by example. Let’s say like a law firm, that they are using personal devices, or you allow them to take pictures with the cameras on their devices for contracts, or the email attachment that they actually have stored under the device that you allowed, all their personal information that they have. Our applications allow them to access those devices to be sending out kind of preventing that data leak. So summarizing, with System Manager, we provide a mechanism to prevent enterprise data from getting into their own hands.
Matt Tankersley
You know, we’re big Meraki flag waivers around here. And it blows my mind, Jim and Yisbel, that we’ve not-we haven’t been smarter about this as it relates to your capabilities with MDM. And so, we said from the beginning, Lauren, that we were going to learn in this journey as well with the TOPcyber21. We know we got some great partners along the way and I love that we’re learning new things about our partners at every step of the way, too. So glad you’re joining us, man. Well look, we’re doing a quick episode, we’re short a cast member. So that always works out, we’re moving quickly. We’re on topic. I wish we had folks that could just call and ask us questions. But that’s not our format, right. So Lauren, before Jim wraps us up, did you hear anything new there or any questions that you have that might help you do your job better and more secure for our listening audience?
Lauren Lev
Are you calling me out? Honestly, everything like researching the episodes, editing the episodes and listening to you guys, everything is a learning opportunity for me. And it’s genuinely helping me to become not only a better cyber safe employee obviously in my professional life, but also in my personal life. There was a new iOS update on iPhones, and typically I would push it off until my phone was about to explode. But now I’m like, I’m right on top of these things. So it’s- as the host of the show, it’s been instrumental in me protecting myself as much as possible.
Matt Tankersley
If you’ve been reading between the lines, one of the things you’ll learn about these MDM platforms is that we can enforce policies like you can’t access company data if you don’t have this update on your device. Right? You can’t access the system if you don’t have your hard drive encrypted or your device encrypted. Right. So Lauren, great, great point, man.
Chase Doelling
Yeah, just to add on to that, I think they’re having a patch device, right is a secure device as well, making sure that all of those are starting to flow through those elements and different, how you’re managing that right, and how employees can upgrade and what that looks like. And creating separate groups is really important, kind of as we talk about creating the foundation, but keeping it up to date is the most secure way to keep that going right.
Lauren Lev
I’ll say one more thing, and then I’ll send it to Jim. But the other point that you guys have brought up, I constantly lose things on a daily basis. And this makes me feel this much more okay with losing my device. Especially probably for Matt, because he’s going to be the first phone call I make. So those are my two big, like behavioral takeaways from today.
Matt Tankersley
I think it’s interesting and is worth noting and Jim, we’ll let you close this out. We talk about policy, right? We’re talking about enforcing a policy that says you can’t access this network, you can’t access the device, the data, the systems, right, if you don’t have these, you know, variables in place, this version of patching, etc, this version of encrypting, but then the question begins, you know, how do you go from policy to application? Right? The beautiful thing that we’ve had and there’s this huge convergence that’s been happening in the marketplace for some time between traditional managed IT and secure cyber management, right. And so, we’ve been providing our clients for years patch management technologies for their Window’s endpoints in particular, now Mac’s and so forth. And JumpCloud’s a huge enabler of MDM, you know, Apple management in that regard. But yeah, you know, I’m anxious to see. And as I learn more about each of your technologies, I see an eventual obsolescence of the older patch management tools as we’re seeing the folks that have developed MDM platforms actually move beyond policy into enforcement and application. I’m gonna monitor these trends, guys. And hopefully that’s on the roadmap for you guys if it’s not already there.
Jim Bowers
You know, I think MDM is going to evolve, right? Universal endpoint management will match simply for the fact of this, look how the workforce is. I really don’t think we’re going to go back to pre-pandemic levels. I think we’re going to continue with work from anywhere solutions, you know, I’ve got one of these. So what we’re starting to see is we’re getting fabulous, right? We’re getting the phones that open up that Apple’s coming out with. So we’re gonna start using these devices and these types of devices more, and we need to be able to have these controls around it, right? Also, let’s think about what’s about to happen. And we all know security is a constant cat and mouse game. But I think a bigger thing that’s going to happen where mobile device management is going to be more critical, is look at 5g. Let’s look at ultra capacity, let’s look at the ultra wide band. I could sit here in my house and get a GIG wireless to my phone. And what does that mean? That means all that traffic that was traversing across a fiber line or a copper line or cable on it was coming out from our house is now going to move up to the Wild Wild West, out in the open in the wireless arena. So now I’ve got more chances to get man in the middle, right, it was a little harder for me to do that on a physical line. But now that data is moving out, so having stringent controls around that mobile device, or that iOS, or that iPad, Chromebook, I almost don’t even need to open my MacBook, I literally can do everything I want to do on my Android device, or my Samsung tablet. I do have a MacBook, but not completely sold it with Apple. I love Apple MacBook, but I don’t like iPhone and that’s me being a hacker, I can do more with my Android. But you know, I will say this that I think this is such a critical piece of the TOP21, simply because like when I used to do resting and testing, one thing inherent with devices is they have to – typically the USB port has to be open to allow to plug keyboards in, to plug printers in the port. And it’s so easy for me to take a little USB jump drive, plug it in, emulate that keyboard, make you think I’m keyboard and the next thing you know I’m going all throughout your network. So having that functionality of being locked out, having that functionality to be able to check for patches to check if you have certain applications installed is going to be critical moving forward because it’s just going to continue to grow. And as that remote workforce continues to grow, this will be a critical part in a nice consistent depth approach.
Matt Tankersley
Love that, learn more about USB management capabilities in episode eight on zero trust. Yisbel, final thoughts: how do we make folks understand how important this is and how much they should reach out to TechOnPurpose to learn more about Meraki MDM?
Yisbel Calzada
I’d say the challenges that they have today, we touched a couple of points here. In the sense, like right now where the corporations stand with this remote work or hybrid environments of employment. We use endpoints more often, we use laptops, we use phones to basically keep working from home or from any part of the world. So the challenge has become, are all your devices up to date, are your corporate policies to access your internet resources and not just your internal resources or your hosted cloud applications that you already have secure or enforced on those employees? So those types of questions are the ones that bring people to think about what they have been using and when they need to start using and the importance of the MDM. And like I always say, go contact any specialists, come to us, to JumpCloud, Meraki MDM, and end especially with an MDM solution. Talk about what are your challenges today with your IP and how they actually manage or are able to manage those endpoints or how secure are your endpoints?
Matt Tankersley
Yeah, let’s keep going around the room. I’m gonna add to that, I will tell you this came up this week. For years, we’ve seen people, literally this week, we’ve seen people in traditional enterprises and SMBs go window shop windows, windows windows, right. And now they’ve got a workforce that’s going “man, I want a Mac,” or you know, their Macs saying they want windows or whatever it is. And we are definitely dealing with a lot of Linux folks as well. And I can tell you that traditional – I mean for all of those SMBs that are out there already trying to be what they are right? Trying to add in a multi iOS platform, cross platform environment, is going to really stretch you beyond what you’ve already got. That’s going to increase your need to work with folks like TechOnPurpose from a managed service provider perspective. And these are the tools that we’re using to help you really simplify that project and that process, so you gotta have it. The world is not just one thing anymore. It really isn’t.
Chase Doelling
Absolutely, and I think one piece that I would add on to that is just like all elements of security right there, you kind of have a layered approach. And I think one of the pieces that we’re starting to see much more is, you know, hopefully the adoption of multi-factor authentication, right, kind of throughout that. But one element that JumpCloud has, is we’re actually, because we’re managing that device and we also have our own, pushing that they are actually able to kind of have that level of control at the device level as well, right? So if you want to take it to the nth degree, right, and make sure you are who you are, no matter where you are. That’s the best way to kind of enforce those elements’ policies, right? But then you always want to think about what are the conditions that you should go through an access, kind of in addition to maintaining a really good baseline of I have policies put in place, I have antivirus put around it, all that kind of safeguards that, as much as you can take within that device and including keeping it up to date. Having all those elements and then kind of taking it a little bit further, making sure right. Because it’s like, again, the only thing you got is the only device in front of us for the most part in making sure that that connection between if it’s coming from the device or kind of any other areas right into those target applications that are doing through a secure route.
Jim Bowers
Matt, I think we should have- I’m going to come up with a new brand Meraki Jump, because I like both Meraki and I like JumpCloud. But I will say another thing about MDM solutions is let’s think about the IP shortage problem. Matt, you touched on MSP outsourcing. There is a huge IT shortage problem, not just in cybersecurity but having an MDM UEM (“unified endpoint management”) solution will streamline efficiency for that poor IT guy that’s over tasked. It will enable him to do his job more effectively and not deal with as much stuff of when a laptop goes bad or worried about when it gets lost and erasing it and onboarding all of those mundane facets that an MDM device can automate and will create for those over tasked IT guys, giving them a little breathing room. Right? So that’s another benefit of having this MDM UEM solution as well.
Yisbel Calzada
There’s a phrase for that: work smarter not harder. So basically that is what an MDM solution will allow them to do.
Matt Tankersley
Listen business owners and SMBs out there, I had a nightmare situation with a client recently where we see an IT team that is limited with resources. Let’s be clear, they’re one guy, and they’re mad. And they’re managing, you know, multiple endpoints, dozens and dozens and dozens of endpoints across dozens of cities. And it’s impossible to do that. Well, it’s impossible to do that securely without the layered security and management approach. And we actually had a situation in the last month, where a business owner kind of came at us and said, Why am I seeing all these extra expenses and everything and he didn’t understand it. It was not what he was used to from 20 or 30 years of industry. And he didn’t value the cost. He doesn’t value the risk that he’s putting himself in. And he literally unplugged all this stuff. And said, we’re going to do all this in house with our one guy, back to what we were just talking about, our one guy. We can’t give that much control to somebody else. That is a horrific, tragic choice in this day and age. Guys, if you are running multiple devices and multiple endpoints, do not rely on yourself. Do not rely on one IT guy, it is not okay. It’s not going to end well for you.
Jim Bowers
Yeah, Matt, one more thing I want to throw in there if you don’t mind. You know, Lauren should have never told me I wasn’t talking too much because I’m going to make up for it. Cyber insurance, let’s stress that. We already see- I think Chase talked about multi-factor. I see it consistently, cyber insurance companies are not renewing policies or premiums are going up. I would really see this as being another requirement, especially with the continued work from anywhere. I would easily see cyber insurances saying you better have a UEM or MDM on any device for any remote worker. So I would not be surprised if we don’t start to see these types of stipulations put in place by cyber insurance as well.
Matt Tankersley
Yeah, we’re seeing it. We’re seeing that across the board. I’m surprised we haven’t seen this one in fact, and go back to Episode Four on IAM (identity and access management), which includes multi-factor authentication. I believe, Chase, you were on that one with us for all the right reasons. Man, if there’s one thing I can tell our listening audience if you’re confused by all the options, and you’re worried about the costs, well, let me tell you A) it costs a whole lot more to deal with compromise. We’re talking business ending stuff and life and stuff. But if there’s one thing that you’re going to do guys, and I’m going to flashback to episode four but implement MFA. I think that the statistic is like 98% of compromises are cut short by using MFA. Right? Doesn’t mean they don’t happen. It just means that they’re 98% less likely to happen, from my understanding of the data that’s in the industry. Implement MFA guys. And then if you got devices and you got a workforce, we need to talk MDM and everything else in the TOPcyber21. So Lauren, I think that’s all I got, you guys did a great job. I’m all ears for any closing comments. Great episode. Great topic, folks. Thanks for listening in. I think Lauren’s going to close this out. And as always, we’re grateful for each of you guys and showing up and helping us educate our marketplace on how to be secure, reliable and trusted in the adoption of their technology.
Lauren Lev
All right, that is mobile device management. As always, thank you guys for hanging out with me today. Always good to chat cybersecurity with you and I know you’ll always keep it sassy and savvy. Next week we’re on to network security. Experts say that damage from cybercrime has now outpaced the world’s yearly cost of natural disaster damage at $6 trillion. I don’t know about you, but I do not, unfortunately, have $6 trillion laying around. So you don’t think it could happen to you or your company, but in today’s world it’s not a matter of if, but when cyber criminals will take advantage of your cybersecurity vulnerabilities. Next week, we’ll be discussing how fortifying your network security will help protect your business from a disaster. Again, remember to like and subscribe and see all of our episodes on LinkedIn, YouTube, Facebook, and Spotify and get them delivered straight to your inbox by signing up at TechOnPurpose.net/blog to start a free trial from Cisco or JumpCloud- and not the bouncy house kind. Email us at and sign up for our free cybersecurity risk assessments at WhosInYour.Cloud. Well, that is all for us today and we will see you all next week!
Ready for your free cybersecurity survey?
Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology! Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.



















