Mobile applications are the first media we use to access information from our smartphones and tablets. We easily trust them with sensitive data, but what do we know about their security levels? Organizations develop mobile applications at a fast pace to keep up with business needs and often leave aside security measures.
In a recent survey aiming at diagnosing companies GDPR compliance, Pradeo asked 382 security leaders about the way they develop mobile applications, the data they manipulate and the security process they go through.
Check the statistics we published last week about security related to organizations’ mobile devices.
Here are the main highlights of this research:
Among the organizations that develop mobile applications, 83% fully externalize their developments and 79% embed third-party libraries within their apps. When they don't undergo security testing, third-party developments often cause unexpected behaviors and data leakage without their distributors knowledge.
4 in 5 organizations
externalize their apps development
Data privacy regulations (GDPR, PIPEDA…) are enforced around the world to protect personal data. When a mobile application manipulates users’ contact list, pictures, email, etc., it must comply with those regulations by ensuring data protection and transparent process.
Respondents stated that the applications they develop manipulate:
While most of their mobile applications handle sensitive data, some organizations still do not secure them.
Furthermore, only 58% of organizations which applications manipulate personal data stated they record data processing activities related to their mobile apps. However, it constitutes a direct infraction to the GDPR Article 30 which requires organizations to “maintain a record of processing activities under their responsibility”.
Download Our Mobile Application Security Guide