Security report reveals disparity between mobile app security perception and reality

Arxan Technologies, aย provider of application protection solutions, hasย announced the publication of its 5th Annual State of Application Security Report. The new research is based on the analysis of 126 popular mobile health and finance apps from the US, UK, Germany, and Japan, as well as a study examining security perspectives of consumers and app security professionals.

Arxan discovered a wide disparity between consumer confidence in the level of security incorporated into mobile health and finance apps and the degree to which organisations address known application vulnerabilities. While the majority of app users and app executives indicate that they believe their apps to be secure, nearly all the apps Arxan assessed, including popular banking and payment apps and FDA-approved health apps, proved to be vulnerable to at least two of the top 10 serious security risks.

Among the research findings:2016 State of Application Security

  • Consumers and app executives believe their mobile health and finance apps are secure. A combined 84 per cent of mobile app users and mobile app executives believe that their mobile health and finance apps are โ€œadequately secure,โ€ and 63 per cent believe that app providers are doing โ€œeverything they canโ€ to protect their mobile health and finance apps.
  • The majority of mobile health and finance appsย contain critical security vulnerabilities.ย 90 per cent of the mobile health and finance apps tested had at least two of the Open Web Application Security Project (OWASP) Mobile Top 10 Risks. More than 80 per cent of the health apps tested that were approved by the US Food and Drug Administration (FDA) or the UK National Health Service (NHS) were also found to have at least two of the OWASP Mobile Top 10 Risks.
  • The security and safety risks are real and significant. 98 per cent of the mobile apps tested lacked binary protection โ€“ this was the most prevalent security vulnerability identified. 83 per cent of the mobile apps had insufficient transport layer protection. Such vulnerabilities could result in application code tampering, reverse-engineering, privacy violations, and data theft. In addition to sensitive data being taken, the vulnerabilities could lead to a health app being reprogrammed to deliver a lethal dose of medication, or a finance app to redirect the transfer of money.
  • Most consumers would change providers if they knew their apps were not secure. 80 per cent of mobile app users would change providers if they knew the apps they were using were not secure. 82 per cent would change providers if they knew alternative apps offered by similar service providers were more secure.

โ€œMobile apps are often used by organisations to help keep customers โ€˜sticky,โ€™ yet in the rush to bring new apps to market, organisations tend to overlook critical security measures that are proving crucial to consumer loyalty,โ€ said Patrick Kehoe, CMO of Arxan Technologies. โ€œOur research in Arxanโ€™s 2016 State of App Security Report demonstrates that mobile app security is an important element in customer retention. Baking in robust mobile app security is not only a smart technology investment to keep the bad guys out, but also a smart business investment to help organisations differentiate from the competition and to achieve customer loyalty based on trust.โ€

+ posts

The editorial team behind Compare the Cloud made up a unique group of IT specialists, digital marketers and cloud specialists. We understand the industry from both the IT managerโ€™s perspective and the perspective of the IT service provider.

Unlocking Cloud Secrets and How to Stay Ahead in Tech with James Moore

Newsletter

Related articles

A Business Continuity Cheat Sheet

Right, let's be honest. When you hear "business continuity,"...

Challenges of Cloud & Ultima’s Solution to Transform Business

With the way that AWS and Microsoft dominate technology...

Data privacy concerns linger around LLMs training

We have all witnessed the accelerated capabilities of Large...

Securing Benefits Administration to Protect Your Business Data

Managing sensitive company information is a growing challenge. Multiple...

Which Cloud Type Suits You โ€“ Public, Private, Hybrid?

Valuable lessons have been learnt about cloud deployments over...