Blog


← Back to BLOG

20
Sep
2022
Avoiding the Vulnerable App Trap with Third-Party Application Auditing

Avoiding the Vulnerable App Trap with Third-Party Application Auditing

Apps are an integral part of our everyday lives. We use apps to check weather forecast, order takeout or delivery from local restaurants, and follow our favorite sports teams. While many apps we use are first-party applications, others come from third parties like DocuSign, LumApps, and Mailmeteor, among others¹. They serve a variety of functions, from quick eSignature integration to sending thousands of personalized emails simultaneously¹. However, installing and using third-party apps brings its fair share of risks. 

Consider General Electric’s 2020 data breach, for example. ISACA outlines that with security measures lacking for both GE and Canon Business Process Services, its third-party partner, the breach exposed 200,000 current and former employees’ personal and health benefits records². This is not a favorable outcome for any business, let alone a global powerhouse. 

Of course, the dangers of using third-party apps are not just limited to multinational corporations like GE. They can be hazardous to your business as well, particularly regarding the level of access your employees have to corporate data³. For example, suppose you work for a company with a bring-your-own-device (BYOD) policy³. You extensively use your iPhone to access your Gmail account and Google Drive documents, but then you decide to install a third-party app requesting permission to access your Google account during the installation process³. Now, place yourself in the employer’s shoes and ask, “How do I protect my business from falling into the trap of vulnerable third-party apps?” 

Enter third-party application auditing. This process allows network administrators to act on multiple third-party applications that users or other admins have installed within their domains, either by revoking or approving access⁴. In this article, we will learn more about third-party app auditing and its benefits for your business.  

A third-party apps audit allows administrators to approve or revoke access to certain apps by organizing them into three distinct categories: (1) Block List, (2) Allow List, or (3) Unresolved⁴. The Block List revokes access to applications for all users who install a particular app, even if they uninstall and subsequently reinstall it⁴. However, the Allow List serves the opposite purpose⁴. It enables users on the domain to use and install the application⁴. Meanwhile, if you list apps as Unresolved, you have not yet reviewed them for placement either on the Allow or Block list⁴. 

Remember that before auditing, there are several vital steps you must take. First, take note of any installed third-party applications on your domain, then narrow the search to the ones that have requested and/or been granted access to your Gmail or Google Drive account⁵. Those accounts store your sensitive information and important data, so it’s crucial to be sure you can trust any applications that have been granted access. One way to determine if an application has malicious intentions is to consider if the permission request is fitting for the app’s purpose; as an example, games that ask for access to Google Drive may not be trustworthy⁵. You should also evaluate new applications daily and decide whether to whitelist or blacklist each app⁵. 

Now that you know how third-party app auditing works, we will now explain some of its advantages for your business. One benefit of third-party app auditing is that it gives you a better idea of the apps your employees install and utilize every day³. By running a daily automated scan of all apps your users install, third-party auditing produces reports you can use as a valuable tool³. Each report lists all the apps with an at-a-glance, color-coded view of their risk level: low, medium, or high³. In short, third-party auditing helps you keep track of your applications and ensure that employees are not installing potentially malicious apps on your computer’s computer systems³. 

While third-party app auditing helps you block risky apps quickly and easily, it also has specific benefits for Google G Suite administrators. If you are a G Suite admin, third-party app audits enable you to monitor all applications with access to your corporate data³. Thus, you can discover immediately if any of your employees have violated company policies, such as the data access policy³. For instance, you can find whether any of your employees have downloaded sensitive data to their private accounts³. This shows that regular third-party app auditing is essential for effective application management. 

Navitend can help you. Call 973.448.0070 or setup an appointment today. 

Sources: 

¹Chrome Unboxed. “Google lists their recommended third-party apps for Google Workspace” by Johanna Romero. Retrieved from https://chromeunboxed.com/2022-recommended-workspace-third-party-apps.  

²ISACA. “How to Identify Vulnerable Third-Party Software” by Victor Gamra. Retrieved from https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2021/how-to-identify-vulnerable-third-party-software

³Spin Technology, Inc. “Third-Party Applications Audit: Complete Guide.” Retrieved from https://spinbackup.com/blog/third-party-applications-audit/

⁴BetterCloud. “Third Party Apps Audit” by Chris Fadell. Retrieved from https://support.bettercloud.com/s/article/Third-Party-Apps-Audit-bc60076.  

⁵BetterCloud. “Third-Party Apps Auditing & Compliance Out of Beta, Suggested Policies.” Retrieved from https://www.bettercloud.com/monitor/third-party-apps-auditing-compliance-beta-suggested-policies

Contact us at 973.448.0070

Testimonials

  • "This company is the best! I feel for the guys that have to help us who are not so tech savvy! Never have I been disappointed at the great service Navitend provides! Corey was especially helpful and I highly recommend Navitend for all your IT needs! You will be extremely satisfied!"

    Kathleen Cwienkala
  • "I am truly impressed by the focus the team places on the requests from our company. Truly an excellent team!!"

    Josefina and Christian Abboud
  • "The staff at Navitend is very professional and strives to meet the needs of their clients. As a Small Business owner trust and professionalism are keys to conducting business. Navitend sets a high standard of ensuring their clients trust their decisions are for the interest of their business."

    Christopher Schaefer
  • "Corey was outstanding today in the services he provided - efficient, professional, knowlegable, kind, and understanding with someone who has no clue about computers. Thank you! 😊"

    Mertie Potter
  • "My customer service experience with Navitend was absolutely amazing. My computer crashed and we needed to order a new one. Navitend was there to help and get us a new computer and set it up from start to finish. The tech Corey that came out was very pleasant to work with. From start to finish he made sure that all of my programs were working properly again from my old machine. I even had follow-up phone calls from him making sure I was happy with how everything was set up. I have never experienced such exceptional customer service."

    Brian Matthews
  • "I have been working with Navitend for 10+ years. Great group of talented professionals!"

    Anne Wisnewski
  • "Corey came to my rescue by getting Quick Books working for me. He is excellent at what he does. Very knowledgeable in the Tech field. I don't know what we at Equity Environmental would ever do without him. Thank you Corey!!!!"

    Lucille Favale
  • "Thanks so much again for taking care of everything in such an expedient manner. It's a pleasure to work with navitend and its staff as always!"

    Lawrence Wolfin / Textol Systems, Inc.
  • "I cannot say enough about Navitend's expertise, customer service, knowledge and professionalism! They have been a great partner with our company for all of our IT needs."

    Margaret Davis
  • "I highly recommend navitend for their professionalism, integrity, down-to-earth advice and thoughtful recommendations. Every solution that they offer is unique and the most appropriate to their customers' needs."

    Paula Muller
  • "Navitend is always providing prompt response, strong technical skills and excellent customer service. Corey, Jeffrey and the other technical support team members are very helpful and user-friendly. Thank you all very much for your fabulous work!"

    Chenghan Liu
  • "I look forward to working with you again in the future. Once again, thanks to your organization for your prompt response."

    Luke Wolters / Luke Wolters Tax Consultants
  • "Awesome managed services provider."

    Rick Smith
  • "Andrea always goes above and beyond with meeting expectations and customer satisfaction! Navitend provides great IT services."

    George Zauflik
  • "We wholeheartedly recommend Navitend for their exceptional IT solutions and services; they have undoubtedly earned our trust and loyalty for future endeavors."

    Benjamin Triggiani
  • "I wanted to personally thank Corey for always helping me with any concerns I have about my software inquiry issues. He is quick with his responses and I am always up to date with all my connectivity. Always a great experience! Thank you!"

    Blerina Pano
  • "I have done business with Navitend for 10+ years and have found their products and professionalism to be 1st rate. And, from a “service after the sale” perspective … even though my company is California based, my customer experience couldn’t be better. Frank Ableson and his team are top tier professionals. Proud to be one of their customers!"

    Bryan Hyzdu
  • "Their technicians? Unsurpassed, each and every one of them. They make me and my co-workers feel as though they are just sitting in their office waiting for us to call them with a problem so they can solve it right away. They treat us as if we are their only client. Talk about great customer service. Call them, you'll be glad you did."

    Kathy Molyneaux
  • "My firm has used Navitend for our IT needs for over 10 years and we are highly satisfied. We’ve found the navitend team to be professional, friendly, and, knowledgeable. They are sensitive to our changing IT needs and the shifting compliance landscape within the financial services industry. We recently completed a server migration and had the pleasure of working with Tony & Andrea who handled the project extremely well, ensuring a smooth transition. We are pleased to call Navitend our trusted IT partner!"

    Kristin Strunk
  • "Over the years that Navitend has been supporting my network and hosting our web site they have always been responsive, professional, and highly skilled. On a few occasions, I have turned away other vendors that have tried to get their foot in the door. Very satisfied."

    M B
  • "Our company uses navitend for all of our IT needs. Rick and team worked for many hours today repairing an issue they had never seen before. With a project deadline of 5pm today, they were able to figure out the issue and get me back to work. The persistence, urgency and professionalism are 2nd to none. Thank you!!"

    Matthew Bick
  • "We've dedicated our lives to growing our retail and ecommerce business and it's a relief to have found a company like navitend who treats our business likes it's their own. navitend's personal approach to project management and problem solving are top-notch."

    Stamatis, Co-owner Twisted Lily, Fragrance Boutique and Apothecary
  • “Navitend’s expertise helped our firm over the past year to effectively elevate our I.T. game, powering our website into a highly interactive tool. Well done to Frank and his team!”  

    Chuck Steege, CFP®, CEP, President, SFG Wealth Planning Services, Inc.
  • "Thank you to Anthony at navitend for the time and effort he put into trying to resolve the issues my laptop was experiencing. I so appreciated his tenacity, professionalism and good humor as we tried (and tried) to figure out a solution. Anthony made sure I understood what was happening at all times, explained things thoroughly and followed up when promised."

    Maria DG
  • "Our company uses Navitend for all its IT needs and every time I've had to ask them for help, they've fixed the issue within hours. Thank you so much!"

    Chase Palmer
  • "Navitend was great and my experience was beyond excellent. Very professional, courteous, and responded in a timely manner. They go above and beyond for their clients. They are a pleasure to work with. Kudos to the Navitend Team - keep up the great job!"

    Ann “Schitzies” Henderson
  • "The nonprofit that I work for contracts with Navitend for tech support. I am so grateful for this service! The support team is highly trained, friendly, professional, and is able to figure out any and every situation that requires help. I recently had a rather lengthy software installation and worked with Andrea who was amazing. I can't recommend Navitend highly enough. I'd give more stars if I could!"

    Claire Lynch
  • "Corey and the group at Navitend are always so helpful and do everything they can to help. Thanks for your professionalism and continued help."

    Robin Ennis
  • "Navitend has consistently offered timely, professional, and courteous solutions to our business needs ranging from troubleshooting, purchase and setup of new computers and other advice. They are my 'go-to team' and continue to be a trusted support in our time of need."

    Laurie Placeres
  • "Corey is ... an IT genius!!!! This man deserves a major raise and weekly bonuses!!! Navitend is my go to for everything IT related, morning noon night and weekends!!! Love this crew!!"

    Heather C
  • "Great tech support."

    Ralph Blakeslee
  • "AMAZING!!!! Every time I have an issue or question, Navitend responds promptly and professionally. Each time I deal with one of their support technicians, I am always grateful for how quickly an issue is resolved and how courteous the staff is. I cannot recommend Navitend enough!!! Wonderful support in a day and age when customer service can be challenging."

    Jacqueline Balloutine
  • "I just had an excellent experience with Navitend! I got a new computer and I needed Microsoft Office installed and access to an additional e-mail account. The Navitend team was so professional, polite, and patient with me. I am not technologically savvy at all, so they were doing all that they could with the little bit of information that I gave them. They spent over an hour trying to help me. They went above and beyond in assisting me and I was able to get everything installed that I needed. The Navitend team is doing a great job!"

    Denise Taylor
  • "This IT firm has been extremely patient, helpful and professional and they are immediately available to troubleshoot and solve problems whenever they arise. Highly recommend them!"

    Kathy Kwasnik
  • "Their support staff is beyond good. They sorted out our company email server migration problem yesterday in record time. It's great to work with a team that has expertise in depth. There are so many one-man-bands out there. It was a good decision to go with the pros."

    Steve S
  • "Navitend is a professional company providing Quality service, great customer service and prompt response to service needs."

    Tammie Horsfield
  • "Anthony was very helpful and solved all my issues promptly. I appreciate all his hard work. Thank you Navitend and Anthony."

    Kyle Hersh
  • "Very helpful, courteous & professional. They do a great job and are pleasant to work with as well."

    Robert Linnett
  • "100% of all expectations met. Don't just consider Navitend, choose them and get back to YOUR mission!"

    C Baker
  • "Thanks so much!  You are a class act!  
    You and your team have really done an excellent job on this!"

    Steve Van Ooteghem, The C12 Group in Houston, Texas
  • "Navitend is a professional IT organization that I would recommend to my clients. Navitend builds strong relationships with their clients to better understand their needs. Navitend is community focused and does work to support local charities. Overall a great company."

    Michael Leyden
  • "De'Ana gave great insight on billing issues. I recommend Navitend for all IT services."

    Christian Majeste
  • "Corey helped me with what I thought would be a minor problem that snowballed in to some complex computer world wizardly stuff and he was so smooth and calming and had it fixed in 15 minutes!! YES!!!! Tuesday crisis obverted!!"

    Kari Maddox
  • "Navitend is an amazing resource for all your IT need! Navitend has been supporting Capitol Care Inc.'s IT needs for many years now and our relationship is wonderful! They are in the know on the latest tech trends and they are always working to enhance our security. Their support team is amazing and you are lucky to have the chance to work with Anthony DeRosa. He is professional, knowledgeable, and always willing to go the extra mile to assist us! HIGHLY RECOMMEND THIS COMPANY!!!"

    Nicole Shenise
  • "The tech's at Navitend are very knowledgeable and thorough. Cory was patient and kept looking into every avenue until he found the issue and fixed it. Thank you so much you guys are great."

    Lisa Palanchi, COO / Camp Six Inc.
  • "Navitend has gone above and beyond my highest expectations. Anthony was great! He was able to coordinate with an Adobe Rep and resolve issues that I had just put too much time into. Thank you again - It was a real pleasure working with you!"

    Forrest Schandel
  • "navitend has been a great IT partner for our company.  Their helpdesk response time is the best I have experienced in my 30 year career.  navitend has helped me to have great IT services without the need to have a full time, in house, technician at significant savings to our company."

    Bob Bradley, President, Bradley Graphics
  • "These folks are spectacular! They're contracted by my work to provide IT support, and they are SO responsive that my mind is blown every time! Just a quick email to request help, and I immediately get a response for a patient and friendly person to call me and walk me through the solutions."

    Hannah
  • "THE BEST!! I've never felt compelled to write a review for any service until having the pleasure to work with Navitend. The professional and supportive staff make an often frustrating technical situation, dare I say, enjoyable. They always go above and beyond to find answers to unique problems. Their response time is unbelievably fast. I could not more highly recommend!!"

    Stephanie Howland
  • "Navitend is a professional, responsive, and knowledgeable organization. They go above and beyond for their clients. The other day Corey Feinsod, one of their Network Technicians, helped resolve a challenging technical issue I experienced working remotely. I appreciate that their team finds value in customer service."

    Cheryl Proska
  • navitend’s approach to customer service is greatly appreciated here.  Ensuring that we are well protected from a technology standpoint provides us with peace of mind to continue our day to day operations and that they are looking out for our company's best interest. 

    Debbie
  • "I recently had to work from home for the first time, and Corey at Navitend provided EXCELLENT service. He was patient, kind, and followed through on all the details!"

    Penny Carbaugh
  • "Our company is more efficient and has grown as a result of navitend’s work. navitend helped us get to the next level."

    Greg Niccolai / Madison Insurance
  • "Best costumer service!! They are the nicest and most patient people. I highly highly recommend!!!!"

    Stephanie Samuel
  • "I appreciate that they didn’t just build the application. They made it better by bringing ideas to the table that not only made for a better user experience, but also kept the development costs down."

    Andy Lynch / North Star Marketing
  • "Navitend has been great with me and my colleagues as we go through a difficult transition to new technology! They are incredibly patient and helpful. I highly recommend them."

    Molly Debevoise Rennie
  • "Corey has been very helpful! Response to my concerns are always prompt and he makes it easy for me to understand exactly what he is doing. I am very grateful for his help!"

    Sue Livingston
  • "I needed to have the battery on my computer replaced. Andrea met me in person to complete that task. While with her, Andrea was able to assist me with a variety of software and computer setup issues. Andrea was pleasant, professional and patient with me and I greatly appreciated her assistance. She came to address one need but was able to fix several for which I am grateful. I think she is an asset to the Navitend team! Thanks again Andrea."

    George Xuereb
  • "Everyone at Navitend I have worked with has offered some of the best customer service I have had. They are patient, knowledgeable and somehow remember my and my colleagues' names. After working with other IT support, I am thrilled my organization is using their services."

    Robyn Ulmer
  • "Navitend has been a life-saver many times for me! They are diligent in troubleshooting problems - until they resolve it. I've worked many times with Corey Feinsod and he is fantastic - I can count on him to fix all my Outlook and computer problems. Overall, I highly recommend Navitend."

    TeleSearch