Online Exclusive: Laying the Groundwork for BYOD Security

As the war over mobile-device market share wages on–especially with the launch of several new phones and tablets into the market–we can expect a continued rise of security issues in the workplace.

Laying the Groundwork for BYOD Security

Gartner predicts that by 2017, half of employers will require employees to supply their own device for work.  With the number of personal devices showing up in the workplace expected to increase, bring your own device (BYOD) to work is certainly a security issue that companies of all sizes are starting to take seriously.   However, for most businesses, simply putting a BYOD policy in place is not sufficient. Communication with employees on BYOD policies is critical. Companies need to identify whose job it is to communicate with employees, and make sure that employees know who to go to when something does happen and the repercussions of a lost or stolen device.

For example, when an employee uses a personal phone or tablet for work, both their personal information and corporate information are stored on the device.  While the employee may be able to distinguish between personal and business information, the security team whose policy it is to remotely wipe all data from a phone or tablet that goes missing cannot make such a distinction.  As such, an employee stands to lose not only the business information stored, but also all of their personal phone numbers, images and text messages.  In this situation, it is important employees know what to expect so that they can be prepared by backing up their personal data regularly.

IT security at many companies is already laying out policies to address potential issues that may arise when company data and personal devices mix.  Such policies include:

Backup and compliance: According to Fulbright’s 9th Annual Litigation Trends Survey Report, the number of regulatory investigations has reached a five-year high, making data retention for the purpose of compliance a top priority for businesses. Regardless of whether a personal device or company device is used, it’s the company data that is the critical issue. Once company data is involved, compliance requirements apply. But, is it the employees' responsibility to save their own data at specific intervals, or do the company's IT specialists take care of that? What tool is used to conduct the backup, who makes it available and who monitors compliance?

Data loss: Memory on mobile devices is easily damaged, so what if the data is important and hasn’t been backed up? A professional expert may be able to help, but who has to arrange for this and who will foot the bill–the company or the employee? Many do not realize that it is not possible to distinguish between company and private data during data recovery process. When a data recovery is performed, data will simply be restored. Often, the file names can no longer be read, so all files have to be opened and checked in order to disentangle private and company data.

Loss of device: When a device is lost or stolen, two issues come to mind: who will replace it and is there an obligation to inform the employer. Does the company have rules in place for how soon it must be informed about the loss? Does the company intend to take quick action, such as remotely blocking access or deleting data?

Remote deletion: Before a company agrees to allow the use of personal devices, it may want to consider requiring employees to install an application on their device that allows data to be deleted remotely in case of loss or theft. Many people do not realize that the deletion is not specific to company data, but affects personal data as well.

End of the employment contract: Most people change employers sooner or later, making the ongoing protection of confidential information post-termination critical for data security. What happens to the company data on the private device in that case? Who checks that it has been deleted? Will care be taken to ensure that private data is not lost during the employee exiting process?

As precautions, companies should consider encryption to prevent unauthorized access to information. In addition, the emergence of business-developed apps and cloud-type solutions can be used to ensure that business information is only accessed through an employee-owned device, but never stored on it. As companies embrace BYOD, it is important to remember that creating or amending policies is only the first step. Effectively communicating data security and retention implications ensures those partaking in the program are in compliance with those policies, understand the implications of leveraging their personal device for work and know what to do when loss or theft occurs.

For more information and insight from Kroll Ontrack’s data recovery experts, check out The Data Recovery Blog.

Featured

  • It Always Rains in Florida

    Over the years, and many trips to various cities, I have experienced some of the craziest memorable things. One thing I always count on when going to Orlando is a massive rainstorm after the tradeshow has concluded the first day. Count on it, it is going to rain Monday evening. Expect that it will be a gully washer. Read Now

    • Industry Events
  • Live from GSX 2024 Preview

    It’s hard to believe, but GSX 2024 is almost here. This year’s show runs from Monday, September 23 to Wednesday, September 25 at the Orange County Convention Center in Orlando, Fla. The Campus Security Today and Security Today staff will be on hand to provide live updates about the security industry’s latest innovations, trends, and products. Whether you’re attending the show or keeping tabs on it from afar, we’ve got you covered. Make sure to follow the Live from GSX page for photos, videos, interviews, product demonstrations, announcements, commentary, and more from the heart of the show floor! Read Now

    • Industry Events
  • Elevate Your Business

    In today’s dynamic business environment, companies specializing in physical security are constantly evolving to remain competitive. One strategic shift these businesses can make to give them the advantage is a full or partial transition to a recurring revenue model, popularly called a subscription service. This approach will bring numerous benefits that not only enhance business stability but also improve customer relationships and drive innovation. Recurring monthly revenue (RMR) or recurring annual revenue (RAR) are two recurring cadence choices that work simply and effectively. Read Now

  • Playing a Crucial Role

    Physical security technology plays a crucial role in detecting and preventing insider cybersecurity threats. While it might seem like a stretch to connect physical security with cyber threats, the two are closely intertwined. Here’s how physical security technology can be leveraged to address both external and internal threats. Read Now

Featured Cybersecurity

Webinars

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3