A CISO’s perspective on a TikTok ban and what it means for enterprises 

Be a part of high executives in San Francisco on July 11-12, to listen to how leaders are integrating and optimizing AI investments for achievement. Study Extra

The federal authorities is contemplating pushing an outright ban on the video-sharing app TikTok throughout the U.S., simply weeks after banning the app from all U.S. authorities gadgets. Citing information privateness considerations stemming from TikTok’s dad or mum firm, the Chinese language agency ByteDance, officers have made it clear that they consider the app might be used to spy on People’ private data and ship that information on to the Chinese language authorities, which is thought for cyber-theft of IR, commerce secrets and techniques and different proprietary data from Western firms to advance its personal nationwide safety priorities.

Contemplating what to do about TikTok

However for companies that use TikTok for advertising and marketing or make use of any of the 150 million People who’ve the app, what’s to be finished? The reply, for now, lies in following fundamental safety hygiene practices for all data-collecting apps, not simply TikTok. 

The truth is that it doesn’t matter what TikTok’s affiliation with the Chinese language authorities is, it’s not the one app that’s able to actively farming person information. Snapchat, Google and Meta all reap the benefits of person information to extra granularly goal adverts and perceive person habits.

No firm is resistant to cyber-breaches and information theft, a lot of that extremely private information will be doubtlessly uncovered by an adversary. TikTok does information assortment on a big scale due to the scale of its person base and present recognition, however typically, for those who’re not paying for the app or service, it’s utilizing your information to earn money.


Remodel 2023

Be a part of us in San Francisco on July 11-12, the place high executives will share how they’ve built-in and optimized AI investments for achievement and prevented widespread pitfalls.


Register Now

In fact, the explanation we — and Congress — are having this dialogue proper now could be that, in contrast to any of these social media firms, TikTok is owned by a overseas firm affiliated with China. Though we needs to be cautious when utilizing social media platforms, irrespective of who owns them, TikTok is amassing large quantities of knowledge from American customers, and we don’t know what that information is getting used for or if a overseas authorities has entry to the info.

Is BYOD best for you?

That is why enterprises that enable staff to carry their very own gadgets into the workplace or conduct work on them — “BYOD” — ought to instantly reevaluate their insurance policies. Extra particularly, they need to ensure that they’re conscious of the kinds of firm data staff have on their private gadgets, and take the required measures to make sure that data is separated from the remainder of the apps on these gadgets. 

There are controls that organizations can implement to make sure that delicate firm data isn’t being collected by any kind of app, TikTok or not. However typically, employers can not subject an outright ban on staff downloading no matter app they’d like onto a private system. Organizations can have acceptable use insurance policies (AUPs) that administratively require staff to not use social media, together with TikTok, whereas on firm time, however that isn’t a ban on having the app on the system. It additionally doesn’t stop the app from amassing data, which it does on a regular basis.

Technical options that may be put in on private gadgets to stop delicate work data from being collected by apps, or, for instance, downloading delicate paperwork from electronic mail, need to be arrange, maintained and monitored. That may be costly and time-consuming, and it requires a company to have good information dealing with practices in place already, together with classifying data and belongings and having visibility into how that data is processed and used on staff’ private gadgets. Enterprise safety leaders ought to perceive precisely what data they should defend to make higher danger selections about how that data is dealt with.

What about work telephones?

The choice route for enterprise involved about TikTok’s information assortment practices is to subject its personal gadgets to staff, pre-loaded with safety controls that stop unknown or unauthorized functions from being downloaded. If the group owns the system, they’ll management precisely what’s allowed to be finished and downloaded onto the system to make sure correct safety protocols are being adopted.

However issuing firm gadgets will also be costly, and enterprises contemplating the choice to buy laptops or telephones for workers need to bear in mind comfort, enterprise imperatives and knowledge safety danger. 

The particular dangers highlighted by the TikTok subject aren’t new however have reached a brand new stage of visibility because of the app’s unimaginable recognition. Whereas Congress deliberates on banning the app, enterprise safety leaders know that the difficult subject of information privateness and worker property doesn’t finish with TikTok, and discovering new options might be crucial as different data-collecting apps rise in utilization. There’s by no means been a greater time for these leaders to carry safety to the entrance and middle of their organizations’ priorities.

Adam Marrè is Chief Info Safety Officer at Arctic Wolf.


Welcome to the VentureBeat neighborhood!

DataDecisionMakers is the place consultants, together with the technical individuals doing information work, can share data-related insights and innovation.

If you wish to examine cutting-edge concepts and up-to-date data, finest practices, and the way forward for information and information tech, be a part of us at DataDecisionMakers.

You may even think about contributing an article of your individual!

Learn Extra From DataDecisionMakers

Related Articles


Please enter your comment!
Please enter your name here

Latest Articles