The sales manager leaves her jacket on the chair after a meeting. Her phone, tucked in the pocket, holds six months of client call notes, proposal drafts, and internal correspondence between senior staff. The phone never comes back. This scenario plays out in companies across Turkey regularly, and by the time management realizes the loss is not just a device but a data breach, the damage is already done.
When most businesses think about data security, they picture server rooms, firewalls, and network infrastructure. Yet the growing use of portable devices — laptops, PDAs, and smartphones — means these tools are no longer just communication aids; they function as genuine data repositories. When you consider that these devices travel outside the corporate network, in bags and pockets and taxis, the limitations of traditional security thinking become clear. The perimeter has moved, and most companies have not moved with it.
Three management principles form the foundation of mobile data security: encryption, access control, and remote intervention. Encryption ensures that even if a device is physically obtained by an unauthorized person, the data on it cannot be read. Laptop security software widely available today can encrypt hard drive contents using strong algorithms such as AES, meaning that a thief who pulls the drive and connects it to another machine sees nothing but unreadable data. On the smartphone and PDA side, encryption support varies significantly between devices and is not yet a standard feature across the market. This means that knowing which devices support encryption — and making purchasing decisions accordingly — is not a task to leave to IT alone; it belongs on the management agenda.
Access control is the area most companies still overlook. Every device that connects to corporate email or an internal system needs its own authentication policy. Username and password alone are not enough; password length, complexity, and renewal frequency need to be enforced at the device level as well. Beyond that, the question of which user can access which data — often resolved on desktop systems — typically goes unanswered on the mobile side. If a sales representative does not need access to the full customer database, that restriction should apply on a mobile device just as it does on a desktop terminal.
Remote wipe gives administrators the ability to erase the contents of a lost or stolen device over the network. This capability exists in certain server software platforms that integrate with corporate email infrastructure, but it only works if the device connects to the network at least once after the wipe command is issued. If the device is powered off or the SIM card is swapped, the command may never reach it. This means remote wipe is not a standalone solution; paired with encryption, however, it forms a meaningful layer of protection. Setting this up requires additional investment in IT infrastructure, but when you consider what a sales manager’s device might carry — client lists, pricing structures, internal forecasts — the cost of not doing it is considerably higher.
Beyond the technical measures, the biggest practical challenge is human behavior. Employees treat their devices as personal property and find even basic steps like setting a PIN or enabling a screen lock to be inconvenient. IT departments have full control over company-owned hardware, but when employees use personal phones for work purposes — a common reality — that authority disappears. This grey area cannot be resolved through technology alone. Which devices are permitted to access corporate data, under what conditions that access can be revoked, and what happens to data on a personal device when an employee leaves the company: all of these questions need written answers before any technical solution can be effective.
For a small or mid-sized business owner approaching this issue, a useful starting question is: ‘Where is our most sensitive data right now, who has it on which device, and what happens if that device disappears tomorrow?’ If the answer is unclear, the first step is an inventory — which devices hold corporate data and who owns them — followed by a written access policy. The tools for encryption and remote wipe exist and are accessible; but without a policy framework behind them, the security gap remains managerial rather than technical. Mobile device security is not an IT problem to be delegated. It is a management responsibility, and the cost of treating it otherwise tends to become visible at the worst possible moment.
This article was originally written in Turkish by Gökhan MERCANOĞLU on April 27, 2009 and has been automatically translated into English and other languages using machine translation.