USB and Removable Media Security: Enterprise Control Without Blocking the Entire Channel

Sources:Honeywell 2025 USB Threat Report|Verizon 2025 DBIR: Physical Media Vectors|Microsoft Intune Device Control Documentation
52%
of malware affecting industrial control systems and OT environments in 2025 was delivered via USB media — Honeywell 2025 USB Threat Report
65%
of insider threat incidents that involved data theft used removable media as the exfiltration channel in 2025
48%
of employees who found a USB drive in a study plugged it into a computer — unchanged from prior years despite increased security awareness
1 in 3
organizations has experienced a security incident attributed to removable media use in the past 2 years — Ponemon

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

USB drives are the only threat vector that can simultaneously deliver malware inbound and exfiltrate data outbound with no network connection required. A complete block of all USB devices is the cleanest policy but creates significant operational friction in environments where removable media has legitimate business uses: transferring data to air-gapped systems, loading software on systems without internet access, and presenting files from personal devices in meeting rooms.

The practical approach for most enterprise environments is not a blanket ban but a device control program: approved devices registered by hardware ID are permitted, unknown devices are blocked, and a DLP layer monitors what data moves to any permitted removable media. This guide covers how to implement this program on Windows and macOS environments.

What USB threats look like in 2026

Understanding current USB threat patterns clarifies which controls are highest priority.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Windows USB device control with Intune and Defender

Microsoft Intune Device Control provides granular USB device management on Windows managed endpoints, controllable by device class, hardware ID, and vendor ID.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

macOS USB device control with Jamf

macOS provides less native granularity on USB device control than Windows. Third-party MDM solutions fill this gap.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The approved device program

A blanket USB ban creates shadow IT and workarounds that are worse than the original risk. An approved device program channels legitimate use into monitored, controlled devices.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Detection: behavioral monitoring for USB anomalies

Even with device control and DLP in place, behavioral monitoring provides a detection layer for policy circumvention and insider threat scenarios.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

USB device control is a case where the right policy is not the most restrictive policy — it is a program that closes the actual risk vectors (unknown drives, unmonitored data transfer) while enabling legitimate use through approved, encrypted, inventoried devices. A blanket ban drives workarounds; a controlled program creates a defensible perimeter for removable media use that is auditable and enforceable.

Frequently asked questions

What is a USB rubber ducky attack?

A USB Rubber Ducky (Hak5 product) is a device that appears as a standard USB keyboard to a computer's operating system — bypassing USB storage class controls — and automatically types pre-programmed keystrokes at high speed when plugged in. Because it presents as a keyboard, device control policies that block USB storage do not stop it. Defense: physical USB port blockers for sensitive machines, BIOS-level USB port disabling, and policies that require UAC confirmation for actions that require elevated privileges.

Should we block USB entirely in high-security environments?

In high-security or classified environments (government, defense, financial trading), a complete USB block including HID devices (using wireless peripherals instead) and physical port blockers is appropriate. For OT/industrial environments, where USB is the primary data transfer path to air-gapped systems, implement a USB sanitization station: all drives must pass through an isolated scanning system before being permitted on the OT network, rather than blocking the channel entirely.

Does BitLocker To Go satisfy the encrypted removable media requirement?

BitLocker To Go encrypts removable drives using a password or smart card. It satisfies the 'data is encrypted at rest' requirement for compliance frameworks (this prevents a lost drive from exposing data). It does not prevent the drive from being used on non-domain computers — a BitLocker To Go drive can be unlocked on any Windows machine where the user knows the password. For a stricter program, hardware-encrypted drives that require the hardware PIN (not a software password) and cannot be unlocked outside the organization's approved systems provide stronger control.

Sources & references

  1. Honeywell 2025 USB Threat Report
  2. Verizon 2025 DBIR: Physical Media Vectors
  3. Microsoft Intune Device Control Documentation

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.