Security Risks

Back to Infographic

Key considerations for AR Security

 

  • Augmented Reality headsets open up new, unique, and significant threat potential to enterprise assets. They represent doorways through which bad actors can surveille, infiltrate, and potentially commandeer and misdirect critical resources and functions.
  • AR cyber security will require a suite of tools and approaches to be effective. Assuming conventional Mobile Device Management / Mobile Application Management (MDM/MAM) tools or mobile security approaches can be easily extended to wearable AR solutions is both inaccurate and dangerous. MDM/MAM suites can help with some, but not all, aspects of securing AR headsets. Enterprise Mobility device certification and practices must be reevaluated to accommodate new factors and threats introduced by AR solutions.
  • Augmented Reality security is a shared responsibility. There is a current tendency for stakeholders to “pass the buck” when it comes to taking ownership: device vendors say it is the job of the customer and can probably be handled by MDM applications; MDM providers have not seen enough deployments to extend their platforms for AR-unique needs, which would not be sufficient in any case; AR project teams look to Enterprise IT for guidance; and Enterprise IT and Mobility departments hesitate to open up their networks to these unconventional solutions without defined processes and practices for certifying and managing them. It is essential that the AR community, device vendors, and enterprise stakeholders work together to understand and protect against the new cyber threats enabled by wearable AR headsets and smart glasses. AR security specialists should augment existing Enterprise Mobility and security teams and create a methodical approach to identify and mitigate risks to enterprise assets and operations. Stakeholders should initiate coordinated studies to instill cyber security elements early into AR proofs-of-concepts and pilot programs, not wait until right before production roll-outs.
  • AR devices are tightly linked to the environment in which they operate, and sense process, store, and possibly expose a large range of important information related to business facilities, personnel locations, resources, and activities related to planning, operations/production, maintenance, and more. To a much greater degree than conventional mobile devices, AR headsets nearly constantly gather data while in use, in standby mode, and even when powered down. This data can include detailed 3Dmaps of user surroundings and captured audio, video, locational and positional data. Some of this data can be accessed remotely without the user even being aware it is happening.
  • In order to exploit the many benefits of establishing remote connectivity with AR systems, wearable AR applications will require access to data stored in public / private / hybrid cloud computing environments, increasing the number and types of trust boundaries that must be protected beyond the device, itself.
  • Voice, gesture, and biosensor interfaces, and team-sharing of AR headsets, can present complicated challenges for secure user authentication because they are easily observed and can potentially be spoofed by cyber criminals.
  • It is essential that the AR community, device vendors, and enterprise stakeholders work together to understand and protect against the new cyber threats enabled by wearable AR headsets and smart glasses. AR security specialists should augment existing enterprise Mobility and security teams to create a comprehensive, methodical approach for identifying and mitigating risks to enterprise assets and operations.
  • Finally, this section is only a preliminary step in the direction of a comprehensive security framework and practical test protocol for AR solutions in enterprise environments. Recommendations for follow-on opportunities are presented, below. Ecosystem cooperation in continuing to build out these tools will prove invaluable for facilitating more near-term deployments.