Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

8 Phones left in each London taxi each year, leads to security concerns

by The Gurus
October 14, 2020
in Editor's News
Share on FacebookShare on Twitter

Around 190,000 mobile phones are found in the back of London’s taxis every year.

Research by ESET of 300 London taxi drivers found that the average taxi driver finds eight mobile phones in the back of their cab every year, and with 24,000 black cabs in London, this equates to 190,000 devices.

The survey also found that half of the devices found in taxis are completely unlocked, while two-thirds (68 per cent) admitted that they would have a look at the phone if they found it to be unlocked. A quarter admitted that they often hand devices into the police, while only 14 per cent would contact the owner.

Mark James, security specialist at ESET, said: “Our study shows that despite the huge publicity cyber crime receives in the media today, consumers still do not see themselves as a real target. This is naïve and wrong. Cyber criminals are well aware of the fact that our mobiles contain connections to corporate networks and sensitive information and they will take advantage of this.

“Consumers should as an absolute minimum use a password to protect their device in case it is ever lost, however a good security posture would include encryption and a remote wipe facility. While our study has proven just how honest taxi drivers are, sadly not everyone who finds a phone will take the same approach. I imagine the majority of people who find a phone will actually have a look around and see if there is anything of any interest or value to be found.”

Rowenna Fielding, information governance manager at the Alzheimer’s Society, told IT Security Guru that a recent risk assessment highlighted that it doesn’t occur to the average individual that data on phones could be monetised and misused, unless it is pointed out to them.

She said: “Those of us in the business have to think like the ‘bad guys’ in order to protect against them, perhaps sometimes we forget that this is a specific mindset which is not shared by the population at large.

“It may be that some organisations have conducted a cost/benefit analysis and decided that the time, effort and expense of enforcing locking of phones actually outweighs the risk of data loss or exposure from lost or stolen phones. This may have been an acceptable trade-off for older ‘dumbphones’ which have limited data storage, no apps, no enterprise management tools and clunky interfaces, but smartphones introduce a whole new level of risk and any organisation that hasn’t updated their risk assessment to incorporate new technology may be in for a nasty surprise one day.”

In the risk assessment, Rowenna said that she and colleagues were balancing the need to protect information on phones by locking the keypad, against the need for staff to be able to quickly access the lone workers monitoring system, which uses a keypad shortcut to operate.

She said: “We came to the conclusion that the phones should have an automatic keyguard lock on a timeout which requires a PIN to unlock: the risk to the organisation and the people we support from exposure of the data on lost or stolen phones was greater than the risk to staff who may need lone working support in a hurry, since locked phones could still be used to call the emergency services if needed. A lot of work involved in securing a small lump of plastic and metal!”

Jon Baines, chair of the National Association of Data Protection Officers (NADPO) said that if these figures are correct, it shows an extraordinarily lax approach to de
vice security by a huge number of people.

“It’s not difficult to implement basic lockdown and encryption measures which would defeat most attempts to access private information on phones,” he said.

“If some of these unlocked devices are used for business purposes, then serious data protection concerns are raised. The law requires companies who handle personal data to have appropriate security measures in place to safeguard the data against loss. Failure to do so exposes those companies to enforcement action. Last year a sole trader was given a £5,000 penalty by the Information Commissioner after an unencrypted laptop was stolen from his car while he was sitting in traffic, and I could easily imagine similar, or larger, penalties being handed to firms who lose unsecure mobile phones.”

Asked if the case was employees not really caring about corporate devices, Fielding said that some organisations deduct the cost of a lost device from the worker’s salary to encourage more care of company mobiles, but that may soak up just as much expense in the effort of administration as the hardware was worth in the first place.

She recommended a layered approach to mitigate the risk from lost devices, including: user communications; policy, police and process; and the use of technology such as mobile device management.

James said: “What people need to start asking themselves is – could any of the data held on my mobile compromise me personally or professionally if it fell into the wrong hands? If the answer is yes, which I expect it will be, then security on your mobile device must be a priority, not an afterthought.”

Tags: ESETinformation securityLondonSurveyTaxi
ShareTweet
Previous Post

HP to split into two separate companies

Next Post

Dispelling the myths of virtualisation security

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol