{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T18:46:33Z","timestamp":1784918793599,"version":"3.55.0"},"reference-count":59,"publisher":"Emerald","issue":"1","license":[{"start":{"date-parts":[[2014,3,4]],"date-time":"2014-03-04T00:00:00Z","timestamp":1393891200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014,3,4]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>\u2013 This paper's purpose is to identify and accentuate the dilemma faced by small- to medium-sized enterprises (SMEs) who use mobile devices as part of their mobility business strategy. While large enterprises have the resources to implement emerging security recommendations for mobile devices, such as smartphones and tablets, SMEs often lack the IT resources and capabilities needed. The SME mobile device business dilemma is to invest in more expensive maximum security technologies, invest in less expensive minimum security technologies with increased risk, or postpone the business mobility strategy in order to protect enterprise and customer data and information. This paper investigates mobile device security and the implications of security recommendations for SMEs.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>\u2013 This conceptual paper reviews mobile device security research, identifies increased security risks, and recommends security practices for SMEs.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>\u2013 This paper identifies emerging mobile device security risks and provides a set of minimum mobile device security recommendations practical for SMEs. However, SMEs would still have increased security risks versus large enterprises who can implement maximum mobile device security recommendations. SMEs are faced with a dilemma: embrace the mobility business strategy and adopt and invest in the necessary security technology, implement minimum precautions with increased risk, or give up their mobility business strategy.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>\u2013 This paper develops a practical list of minimum mobile device security recommendations for SMEs. It also increases the awareness of potential security risks for SMEs from mobile devices.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>\u2013 This paper expands previous research investigating SME adoption of computers, broadband internet-based services, and Wi-Fi by adding mobile devices. It describes the SME competitive advantages from adopting mobile devices for enterprise business mobility, while accentuating the increased business risks and implications for SMEs.<\/jats:p><\/jats:sec>","DOI":"10.1108\/imcs-03-2013-0019","type":"journal-article","created":{"date-parts":[[2014,1,24]],"date-time":"2014-01-24T23:21:25Z","timestamp":1390605685000},"page":"97-114","source":"Crossref","is-referenced-by-count":66,"title":["Mobile device security considerations for small- and medium-sized enterprise business mobility"],"prefix":"10.1108","volume":"22","author":[{"given":"Mark","family":"A. Harris","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Karen","family":"P. Patten","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","reference":[{"key":"key2021010301101541700_b1","unstructured":"Android-Mag (2013), PlaceRaider: The \u201cLegal\u201d Android Trojan, available at: www.androidmag.com\/placeraider-%E2%80%98legal%E2%80%99-android-trojan (accessed 9 February 2013)."},{"key":"key2021010301101541700_b2","unstructured":"Arxan (2012), State of Security in the App Economy: Mobile Apps Under Attack, available at: www.arxan.com\/assets\/1\/7\/state-of-security-app-economy.pdf (accessed 9 February 2013)."},{"key":"key2021010301101541700_b3","doi-asserted-by":"crossref","unstructured":"Audretsch, D. (2001), \u201cWhat's new about the new economy? Sources of growth in the managed and entrepreneurial economies\u201d, Change, Vol. 10 No. 1, pp. 267-315.","DOI":"10.1093\/icc\/10.1.267"},{"key":"key2021010301101541700_b4","unstructured":"Bradbard, D.A. , Norris, D.R. and Kahai, P.H. (1990), \u201cComputer security in small business: an empirical study\u201d, Journal of Small Business Management, Vol. 28 No. 1, pp. 9-19."},{"key":"key2021010301101541700_b5","unstructured":"Bradshaw, T. (2012), Android Apps Put Pressure on Apple, available at: www.ft.com\/cms\/s\/0\/95338878-4daa-11e2-a0fc-00144feab49a.html (accessed 10 February 2013)."},{"key":"key2021010301101541700_b6","unstructured":"Chaudhury, R. , Covaleda, A. and Ross, R. (2011), \u201cThe wireless battle for small business customers\u201d, Connected Planet, available at: www.connectedplanetonline.com\/3g4g\/news\/the-wireless-battle-for-small-business-customers-0919 (accessed 12 December 2012)."},{"key":"key2021010301101541700_b7","unstructured":"Chetan-Sharma (2013), Chetan Sharma: Technology and Strategy Consulting, available at: www.chetansharma.com\/index.htm (accessed 4 March 2013)."},{"key":"key2021010301101541700_b9","unstructured":"Commission of European Communities (2003), \u201cCommission recommendation concerning the definition of micro, small- and medium-sized enterprise adopted by the commission\u201d, Official Journal of the European Union, 2003\/361\/EC."},{"key":"key2021010301101541700_b8","unstructured":"Comscore (2011), Smartphones and Tablets Drive Nearly 7 Percent of Total US Digital Traffic, available at: www.comscore.com\/Press_Events\/Press_Releases\/2011\/10\/Smartphones_and_Tablets_Drive_Nearly_7_Percent_of_Total_U.S._Digital_Traffic (accessed 15 February 2013)."},{"key":"key2021010301101541700_b10","unstructured":"Coninsync (2013), Why You Should Avoid Saving Passwords on Your Smartphone?, available at: http:\/\/coninsync.com\/why-you-should-avoid-saving-passwords-on-your-smartphone\/ (accessed 17 February 2013)."},{"key":"key2021010301101541700_b11","unstructured":"Dennis, W.J. Jr (2005), \u201cThe state of technology\u201d, NFIB National Small Business Poll, Vol. 5 No. 5."},{"key":"key2021010301101541700_b12","unstructured":"Ernst &Young (2012), Mobile Device Security: Understanding Vulnerabilities and Managing Risks, available at: www.ey.com\/Publication\/vwLUAssets\/Mobile_Device_Security\/$FILE\/Mobile-security-devices_AU1070.pdf (accessed 2 May 2013)."},{"key":"key2021010301101541700_b13","unstructured":"ESET (2013), Trends for 2013, available at: http:\/\/go.eset.com\/us\/resources\/white-papers\/Trends_for_2013_preview.pdf (accessed 7 March 2013)."},{"key":"key2021010301101541700_b14","unstructured":"FBI (2012), Smartphone Users Should Be Aware of Malware Targeting Mobile Devices and the Safety Measures to Help Avoid Compromise, available at: www.fbi.gov\/sandiego\/press-releases\/2012\/smartphone-users-should-be-aware-of-malware-targeting-mobile-devices-and-the-safety-measures-to-help-avoid-compromise (accessed 11 February 2013)."},{"key":"key2021010301101541700_b15","unstructured":"Gartner (2012), Magic Quadrant for Mobile Device Management Software, available at: www.gartner.com\/technology\/reprints.do?id=1-1AKKJNN&ct=120518&st=sb (accessed 29 January 2013)."},{"key":"key2021010301101541700_b17","unstructured":"Gold, S. (2011a), \u201cCracking cellular networks via femtocells\u201d, Network Security, Vol. 2011 No. 9, pp. 5-8."},{"key":"key2021010301101541700_b16","unstructured":"Gold, S. (2011b), \u201cCracking wireless networks\u201d, Network Security, Vol. 2011 No. 11, pp. 14-18."},{"key":"key2021010301101541700_b18","unstructured":"Gordon, L.A. , Loeh, M.P. , Lucyshyn, W. and Richardson, R. (2004), Ninth Annual CSI\/FBI Computer Crime and Security Survey, Computer Security Institute, available at: www.theiia.org\/iia\/download (accessed 9 February 2013)."},{"key":"key2021010301101541700_b19","unstructured":"Greenberg, A. (2012), \u201cGoogle gets serious about android security: now auto-scans app market for malware\u201d, Forbes, available at: www.forbes.com\/sites\/andygreenberg\/2012\/02\/02\/google-gets-serious-about-android-security-now-auto-scans-app-market-for-malware\/ (accessed 11 February 2013)."},{"key":"key2021010301101541700_b20","unstructured":"Greenberg, A. (2013), \u201cEvasion is the most popular jailbreak ever: nearly seven million iOS devices hacked in four days\u201d, Forbes, available at: www.forbes.com\/sites\/andygreenberg\/2013\/02\/08\/evasi0n-is-the-most-popular-jailbreak-ever-nearly-seven-million-ios-devices-hacked-in-four-days\/ (accessed 12 February 2013)."},{"key":"key2021010301101541700_b21","doi-asserted-by":"crossref","unstructured":"Henri, I. and Aurelie, L. (2006), \u201cGive me a mobile phone, and I will work harder: assessing the value of mobile technology in organizations \u2013 an exploratory research\u201d, Proceedings of the International Conference on Mobile Business (ICMB'06), IEEE Computer Society, Copenhagen, Denmark, Paper 18, 26-27 June.","DOI":"10.1109\/ICMB.2006.20"},{"key":"key2021010301101541700_b22","unstructured":"Hoffman, D. (2013), \u201cExposing your personal information: there's an app [\u2026]\u201d, J-Net Community, available at: http:\/\/forums.juniper.net\/t5\/Security-Mobility-Now\/Exposing-Your-Personal-Information-There-s-An-App-for-That\/ba-p\/166058 (accessed 9 February 2013)."},{"key":"key2021010301101541700_b23","unstructured":"Homeland Security (2013), Cyber-Security Tips, available at: www.dhs.gov\/cybersecurity-tips (accessed 2 May 2013)."},{"key":"key2021010301101541700_b24","unstructured":"ICSB (2008), Results of the 2008 Dell\/ICSM International Business Survey, International Center for Small Business, available at: www.icsb.org\/know_research.asp (accessed 12 December 2012)."},{"key":"key2021010301101541700_b25","doi-asserted-by":"crossref","unstructured":"Johnson, D.W. and Koch, H. (2006), \u201cComputer security risks in the internet era: are small business owners aware and proactive?\u201d, Proceedings of the 39th Hawaii International Conference on System Sciences, IEEE, Washington, DC.","DOI":"10.1109\/HICSS.2006.91"},{"key":"key2021010301101541700_b26","unstructured":"Kaseya (2012), MSP Global Pricing Survey, available at: www.kaseya.com\/lps\/en\/lp\/2012\/MSPGlobalPricingSurvey_Q4.aspx (accessed 21 January 2013)."},{"key":"key2021010301101541700_b27","unstructured":"Kaspersky (2013), Find and Call: Leak and Spam, available at: www.securelist.com\/en\/blog\/208193641\/Find_and_Call_Leak_and_Spam (accessed 11 February 2013)."},{"key":"key2021010301101541700_b28","unstructured":"Kemshall, A. (2011), \u201cSecurity should not cost the world\u201d, ChannelWeb.Co.UK, December 22, available at: www.channelweb.co.uk\/crn-uk\/opinion\/2134340\/security-cost-earth (accessed 22 February 2012)."},{"key":"key2021010301101541700_b29","doi-asserted-by":"crossref","unstructured":"Koch, H. and Johnson, D. (2008), \u201cAre home-based sales representatives aware and proactive regarding security risks in the internet era?\u201d, Journal of Internet Commerce, Vol. 7 No. 3, pp. 379-402.","DOI":"10.1080\/15332860802250492"},{"key":"key2021010301101541700_b30","unstructured":"Lookout (2011), Lookout Mobile Treat Report, available at: www.mylookout.com\/_downloads\/lookout-mobile-threat-report-2011.pdf (accessed 22 February 2012)."},{"key":"key2021010301101541700_b31","unstructured":"Lookout (2012), State of Mobile Security 2012, available at: www.lookout.com\/resources\/reports\/state-of-mobile-security-2012 (accessed 13 January 2013)."},{"key":"key2021010301101541700_b32","unstructured":"Lookout (2013), 2013 Mobile Threat Predictions, available at: https:\/\/blog.lookout.com\/blog\/2012\/12\/13\/2013-mobile-threat-predictions\/ (accessed 11 February 2013)."},{"key":"key2021010301101541700_b33","unstructured":"Mansfield-Devine, S. (2012a), \u201cAndroid architecture: attacking the weak points\u201d, Network Security, Vol. 2012 No. 10, pp. 5-12."},{"key":"key2021010301101541700_b34","unstructured":"Mansfield-Devine, S. (2012b), \u201cParanoid android: just how insecure is the most popular mobile platform?\u201d, Network Security, Vol. 2012 No. 9, pp. 5-10."},{"key":"key2021010301101541700_b35","doi-asserted-by":"crossref","unstructured":"Mansfield-Devine, S. (2013), \u201cSecurity review: the past year\u201d, Computer Fraud & Security, Vol. 2013 No. 1, pp. 5-11.","DOI":"10.1016\/S1361-3723(13)70006-X"},{"key":"key2021010301101541700_b36","unstructured":"Mitchell, B. (2013), Enable MAC Address Filtering on Wireless Access Points and Routers, available at: http:\/\/compnetworking.about.com\/cs\/wirelessproducts\/qt\/macaddress.htm (accessed 30 April 2013)."},{"key":"key2021010301101541700_b37","unstructured":"MIT-Tech-Review (2013), \u201cPlaceRaider: the military smartphone malware designed to steal your life\u201d, MIT Technology Review, available at: www.technologyreview.com\/view\/429394\/placeraider-the-military-smartphone-malware-designed-to-steal-your-life\/ (accessed 9 February 2013)."},{"key":"key2021010301101541700_b38","doi-asserted-by":"crossref","unstructured":"Mylonas, A. , Kastania, A. and Gritzalis, D. (2012), \u201cDelegate the smartphone user? Security awareness in smartphone platforms\u201d, Computers & Security, Vol. 34, pp. 47-66.","DOI":"10.1016\/j.cose.2012.11.004"},{"key":"key2021010301101541700_b39","unstructured":"NIST (2012), Guidelines for Managing and Securing Mobile Devices in the Enterprise (Draft), available at: http:\/\/csrc.nist.gov\/publications\/drafts\/800-124r1\/draft_sp800-124-rev1.pdf (accessed 2 May 2013)."},{"key":"key2021010301101541700_b40","unstructured":"Nokia White Paper (2006), A Holistic Approach to Business Mobility, Wiley, London, available at: http:\/\/dailywireless.tradepub.com\/free-offer\/a-holistic-approach-to-business-mobility\/w_aaaa993?sr=ct&_t=ct:Tele (accessed 1 March 2012)."},{"key":"key2021010301101541700_b42","unstructured":"Osterman Research (2012a), Achieving Rapid Payback with Mobile Device Management, available at: www.ostermanresearch.com\/whitepapers\/orwp_0175.pdf (accessed 21 January 2013)."},{"key":"key2021010301101541700_b41","unstructured":"Osterman Research (2012b), Mobile Devices in the Enterprise: MDM Usage and Adoption Trends, available at: www.ostermanresearch.com\/whitepapers\/orwp_0164.pdf (accessed 21 January 2013)."},{"key":"key2021010301101541700_b43","doi-asserted-by":"crossref","unstructured":"Passerini, K. , El Tarabishy, A. and Patten, K. (2012), Information Technology for Small Business: Managing the Digital Enterprise, Springer, New York, NY.","DOI":"10.1007\/978-1-4614-3040-7"},{"key":"key2021010301101541700_b44","unstructured":"Patten, K. and Passerini, K. (2007), \u201cNext generation small and medium enterprises mobility strategy roadmap\u201d, Proceedings of ISOneWorldConference, Las Vegas, NV, 11-13 April."},{"key":"key2021010301101541700_b45","unstructured":"Platform-Versions (2013), Platform Versions, available at: http:\/\/developer.android.com\/about\/dashboards\/index.html (accessed 5 February 2013)."},{"key":"key2021010301101541700_b46","unstructured":"Ponemon, L. (2005), Lost Customer Information: What Does a Data Breach Cost Companies? Ponemon Institute, Tucson, AZ, available at: www.securitymanagement.com\/library\/Ponemon_DataStudy0106.pdf (accessed 9 February 2013)."},{"key":"key2021010301101541700_b47","doi-asserted-by":"crossref","unstructured":"Romano, N.C. and Fjermestad, J. (2007), \u201cPrivacy and security in the age of electronic customer relationship management\u201d, International Journal of Information Security and Privacy, Vol. 1 No. 1, pp. 85-106.","DOI":"10.4018\/jisp.2007010105"},{"key":"key2021010301101541700_b48","unstructured":"Rubens, P. (2012), Mobile Device Management (MDM) Platform Buying Guide, available at: www.enterprisenetworkingplanet.com\/netsecur\/mobile-device-management-mdm-buying-guide-1.html (accessed 21 January 2013)."},{"key":"key2021010301101541700_b49","doi-asserted-by":"crossref","unstructured":"Spinellis, D. , Kokolakis, S. and Gritzalis, S. (1999), \u201cSecurity requirements, risks, and recommendations for small enterprise and home-office environments\u201d, Information Management and Computer Security, Vol. 7 No. 3, pp. 121-128.","DOI":"10.1108\/09685229910371071"},{"key":"key2021010301101541700_b50","unstructured":"Statcounter (2013), \u201cTop 8 mobile operating systems in the United States from Jan 2012 to Jan 2013\u201d, StatCounter Global Stats, available at: http:\/\/gs.statcounter.com\/#mobile_os-US-monthly-201201-201301 (accessed 12 February 2013)."},{"key":"key2021010301101541700_b51","unstructured":"Strohmeyer, R. (2011), \u201cWhy I get apps from Amazon, not Google\u201d, PCWorld, available at: www.pcworld.com\/article\/239270\/why_i_get_apps_from_amazon_not_google.html (accessed 11 February 2013)."},{"key":"key2021010301101541700_b52","unstructured":"Sybase (2011), Mobility Advantage: Why Secure Your Mobile Devices?, available at: www.sybase.com\/files\/White_Papers\/Sybase_Afaria_WhySecurity_wp.pdf (accessed 7 February 2013)."},{"key":"key2021010301101541700_b53","unstructured":"Trend-Micro (2012), Repeating History, available at: www.trendmicro.com\/cloud-content\/us\/pdfs\/security-intelligence\/reports\/rpt-repeating-history.pdf (accessed 9 February 2013)."},{"key":"key2021010301101541700_b57","unstructured":"United States Small Business Administration (2013), \u201cFAQs: advocacy small business statistics and research\u201d, Office of Advocacy, available at: www.sba.gov\/faqs\/faqindex.cfm?areaID=24 (accessed 9 February 2013)."},{"key":"key2021010301101541700_b54","unstructured":"US-CERT (2011a), Cyber Threats to Mobile Phones, United States Computer Emergency Readiness Team, available at: www.us-cert.gov\/sites\/default\/files\/publications\/cyber_threats-to_mobile_phones.pdf (accessed 9 February 2013)."},{"key":"key2021010301101541700_b55","unstructured":"US-CERT (2011b), Protecting Portable Devices: Physical Security, United States Computer Emergency Readiness Team, available at: www.us-cert.gov\/ncas\/tips\/ST04-017 (accessed 2 May 2013)."},{"key":"key2021010301101541700_b56","unstructured":"USDL (2005), \u201cNew quarterly data from BLS on business employment dynamic by size of firm\u201d, United States Department of Labor, Bureau of Labor Statistics, Washington, DC, USDL 05-2277, December 8."},{"key":"key2021010301101541700_b58","unstructured":"Waltz, M. (2011), \u201cMobility threats\u201d, Mobile Enterprise, 7 March, available at: http:\/\/mobileenterprise.edgl.com\/top-stories\/Mobility-Threats71022 (accessed 9 February 2013)."},{"key":"key2021010301101541700_b59","unstructured":"ZDNet (2013), \u201cDoes jailbreaking or rooting devices and BYOD mix?\u201d, ZDNet, available at: www.zdnet.com\/does-jailbreaking-or-rooting-devices-and-byod-mix-7000011069\/ (accessed 12 February 2013)."}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/IMCS-03-2013-0019","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMCS-03-2013-0019\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMCS-03-2013-0019\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:50:45Z","timestamp":1753393845000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/22\/1\/97-114\/175991"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,3,4]]},"references-count":59,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2014,3,4]]}},"alternative-id":["10.1108\/IMCS-03-2013-0019"],"URL":"https:\/\/doi.org\/10.1108\/imcs-03-2013-0019","relation":{},"ISSN":["0968-5227"],"issn-type":[{"value":"0968-5227","type":"print"}],"subject":[],"published":{"date-parts":[[2014,3,4]]}}}