{"id":4210,"date":"2021-05-13T16:08:35","date_gmt":"2021-05-13T13:08:35","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=4210"},"modified":"2023-12-18T12:04:23","modified_gmt":"2023-12-18T09:04:23","slug":"5-steps-to-secure-data-on-macs-in-the-enterprise","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/5-steps-to-secure-data-on-macs-in-the-enterprise\/","title":{"rendered":"5 Steps to Secure Data on Macs in the Enterprise"},"content":{"rendered":"<p>Over the last twenty years, Macs have cemented their place in the enterprise, first as a specialized tool for professionals in the creative fields, then as a device of choice in the office. The introduction of choose-your-own-device (CYOD) and bring-your-own-device (BYOD) policies have greatly benefitted Macs\u2019 presence in the enterprise. A recent\u00a0<a href=\"https:\/\/resources.jamf.com\/documents\/books\/survey-the-impact-of-device-choice-on-the-employee-experience.pdf\" target=\"_blank\" rel=\"noopener\">JAMF survey<\/a>\u00a0revealed that, when given the option, a staggering 72% of employees chose Apple devices over PCs.<\/p>\n<p>Apple also showed its commitment to enterprise-ready Macs through its efforts to boost the operating system\u2019s security. With macOS Big Sur, the company began <a href=\"https:\/\/www.endpointprotector.com\/blog\/kext-less-dlp-for-macos\/\" target=\"_blank\" rel=\"noopener\">deprecating kernel extensions<\/a> in favor of new system extensions that allowed code to be executed only in a controlled user space. This move eliminated a popular attack vector for macOS which targeted the operating system through malicious kernel extensions such as rootkits.<\/p>\n<p>Although at first glance Macs come with a higher price tag than PCs, according to <a href=\"https:\/\/www.jamf.com\/blog\/total-cost-of-ownership-mac-versus-pc-in-the-enterprise\/\" target=\"_blank\" rel=\"noopener\">an IBM report<\/a>, companies can save $273 &#8211; $543 per Mac deployed compared to PCs. There are several reasons for this. For one, Macs are built with high-end specs that are meant to last a long time. They do not require a separate license for macOS but come with the operating system preinstalled. Macs include built-in solutions which PC users may need to purchase separately. Among them, encryption tool FileVault and antimalware software XProtect. But one of the biggest reasons for the difference in ownership cost between Macs and PCs is the amount of helpdesk support inquiries they generate.<\/p>\n<p>IBM, which has deployed nearly 200,000 Macs, reported that their IT support helpdesk receives twice as many support calls for PCs than for Macs. Additionally, only 5% of support tickets opened for Macs require an in-person visit versus 27% for PCs. Companies running Macs, therefore, spend less on IT staff and support services, significantly reducing the total cost of ownership.<\/p>\n<p>With the adoption of Macs in the enterprise increasing, so does the risk of data security incidents. Although more secure by design thanks to their solid Unix-based architecture, there is one threat Macs are just as vulnerable to as PCs: users themselves. From human error, negligence with sensitive data, and security fatigue to the intentional disclosure or theft of confidential data, <a href=\"https:\/\/www.endpointprotector.com\/blog\/macs-in-the-enterprise-insider-threats\/\" target=\"_blank\" rel=\"noopener\">insiders account for 23% of all data breaches<\/a>. A further 7% of malicious attacks have insiders as a root cause and another 17% are due to attacks such as phishing and social engineering which target employees directly.<\/p>\n<p>Here are five steps companies can take to mitigate these threats and keep their sensitive data secure:<\/p>\n<h2>1. Encrypt hard drives<\/h2>\n<p>Data stored on Macs isn\u2019t automatically encrypted. Many users are not aware that they need to enable encryption themselves. Apple\u2019s native encryption solution, FileVault, secures Macs\u2019 hard drives requiring users to input a password whenever they start up their Macs. Should a device be stolen, FileVault prevents the data at rest on a turned-off Mac from being extractable in any effective way. Turning on FileVault also enables the remote wipe feature of Find My Device, an added safety precaution in case of theft.<\/p>\n<p>IT administrators can enable FileVault for all users at once using an enterprise management application such as Jamf that leverages Apple\u2019s build-in Mobile Device Management framework and additional software to remotely manage Macs.<\/p>\n<h2>2. Manage iCloud backups responsibly<\/h2>\n<p>For individuals, having data such as contacts, settings, calendars, bookmarks, and photos backed up on iCloud can be useful and ensure a smooth transition to new Apple devices in the future.<\/p>\n<p>However, when individuals use their Macs in an enterprise setting, companies run the risk of confidential company data being synced into their employees\u2019 iCloud accounts. Companies should therefore disable the iCloud backup option and the iCloud document sync on enterprise Macs. IT administrators can also enforce encrypted backups.<\/p>\n<h2>3. Use a VPN on public networks<\/h2>\n<p>Requiring the use of a Virtual Private Network (VPN) outside the office is vital for the protection of sensitive data from attackers using unsecure public networks to intercept communications and gain access to confidential data. With a VPN, a secure connection is created, adding a protective encryption layer to all data transferred to and from a Mac.<\/p>\n<h2>4. Encrypt the Time Machine Backup<\/h2>\n<p>The Time Machine backup is a built-in feature that keeps an up-to-date copy of all files on a Mac and helps users restore their Macs in case of hardware failure. However, the backup is unencrypted. Even if FileVault is enabled, Time Machine backups are not encrypted by default. IT administrators must therefore encrypt backups separately.<\/p>\n<h2>5. Address insider threats with DLP<\/h2>\n<p>To protect data from insider threats, businesses should implement Data Loss Prevention (DLP) solutions. DLP tools use predefined and custom policies and complex content inspection and contextual scanning of data to identify, monitor, limit or block the transfer of sensitive data. Whether it\u2019s personally identifiable information (PII) protected under data protection laws such as <a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>, <a href=\"https:\/\/www.endpointprotector.com\/blog\/all-you-need-to-know-about-hipaa-compliance\/\" target=\"_blank\" rel=\"noopener\">HIPAA<\/a>, or <a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener\">CCPA<\/a> or <a href=\"https:\/\/www.endpointprotector.com\/blog\/how-can-dlp-help-you-protect-corporate-information\/?__hstc=23781221.7988bab6120782a435a6a92f5f8d421b.1620172800101.1620172800102.1620172800103.1&amp;__hssc=23781221.1.1620172800104&amp;__hsfp=1794773680\" target=\"_blank\" rel=\"noopener\">confidential information<\/a> such as proprietary algorithms or patents, DLP technology, when applied on the endpoint, can protect sensitive data whether employees are in the office or working from home.<\/p>\n<p>Its monitoring capabilities, which flag any attempts to violate policies, can help companies identify malicious insiders and problem areas that may need to be addressed in data security employee training. DLP solutions also allow companies to control peripheral and USB ports, blocking or limiting the use of <a href=\"https:\/\/www.endpointprotector.com\/blog\/how-to-control-usbs-and-removable-devices-with-endpoint-protector\/\">removable devices<\/a> to company-issued ones. Some, such as <a href=\"https:\/\/www.endpointprotector.com\/\" target=\"_blank\" rel=\"noopener\">Endpoint Protector<\/a>, even include Enforced Encryption features which ensure that any files copied onto a USB device connected to a Mac are automatically encrypted.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the last twenty years, Macs have cemented their place in the enterprise, first as a specialized tool for professionals in the creative fields, then as a device of choice in the office. The introduction of choose-your-own-device (CYOD) and bring-your-own-device (BYOD) policies have greatly benefitted Macs\u2019 presence in the enterprise. A recent\u00a0JAMF survey\u00a0revealed that, when &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/5-steps-to-secure-data-on-macs-in-the-enterprise\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;5 Steps to Secure Data on Macs in the Enterprise&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":4215,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,23],"tags":[],"class_list":["post-4210","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-loss-prevention","category-macs-in-the-enterprise","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=4210"}],"version-history":[{"count":5,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4210\/revisions"}],"predecessor-version":[{"id":7755,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4210\/revisions\/7755"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/4215"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=4210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=4210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=4210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}