Online Exclusive: Laying the Groundwork for BYOD Security

As the war over mobile-device market share wages on–especially with the launch of several new phones and tablets into the market–we can expect a continued rise of security issues in the workplace.

Laying the Groundwork for BYOD Security

Gartner predicts that by 2017, half of employers will require employees to supply their own device for work.  With the number of personal devices showing up in the workplace expected to increase, bring your own device (BYOD) to work is certainly a security issue that companies of all sizes are starting to take seriously.   However, for most businesses, simply putting a BYOD policy in place is not sufficient. Communication with employees on BYOD policies is critical. Companies need to identify whose job it is to communicate with employees, and make sure that employees know who to go to when something does happen and the repercussions of a lost or stolen device.

For example, when an employee uses a personal phone or tablet for work, both their personal information and corporate information are stored on the device.  While the employee may be able to distinguish between personal and business information, the security team whose policy it is to remotely wipe all data from a phone or tablet that goes missing cannot make such a distinction.  As such, an employee stands to lose not only the business information stored, but also all of their personal phone numbers, images and text messages.  In this situation, it is important employees know what to expect so that they can be prepared by backing up their personal data regularly.

IT security at many companies is already laying out policies to address potential issues that may arise when company data and personal devices mix.  Such policies include:

Backup and compliance: According to Fulbright’s 9th Annual Litigation Trends Survey Report, the number of regulatory investigations has reached a five-year high, making data retention for the purpose of compliance a top priority for businesses. Regardless of whether a personal device or company device is used, it’s the company data that is the critical issue. Once company data is involved, compliance requirements apply. But, is it the employees' responsibility to save their own data at specific intervals, or do the company's IT specialists take care of that? What tool is used to conduct the backup, who makes it available and who monitors compliance?

Data loss: Memory on mobile devices is easily damaged, so what if the data is important and hasn’t been backed up? A professional expert may be able to help, but who has to arrange for this and who will foot the bill–the company or the employee? Many do not realize that it is not possible to distinguish between company and private data during data recovery process. When a data recovery is performed, data will simply be restored. Often, the file names can no longer be read, so all files have to be opened and checked in order to disentangle private and company data.

Loss of device: When a device is lost or stolen, two issues come to mind: who will replace it and is there an obligation to inform the employer. Does the company have rules in place for how soon it must be informed about the loss? Does the company intend to take quick action, such as remotely blocking access or deleting data?

Remote deletion: Before a company agrees to allow the use of personal devices, it may want to consider requiring employees to install an application on their device that allows data to be deleted remotely in case of loss or theft. Many people do not realize that the deletion is not specific to company data, but affects personal data as well.

End of the employment contract: Most people change employers sooner or later, making the ongoing protection of confidential information post-termination critical for data security. What happens to the company data on the private device in that case? Who checks that it has been deleted? Will care be taken to ensure that private data is not lost during the employee exiting process?

As precautions, companies should consider encryption to prevent unauthorized access to information. In addition, the emergence of business-developed apps and cloud-type solutions can be used to ensure that business information is only accessed through an employee-owned device, but never stored on it. As companies embrace BYOD, it is important to remember that creating or amending policies is only the first step. Effectively communicating data security and retention implications ensures those partaking in the program are in compliance with those policies, understand the implications of leveraging their personal device for work and know what to do when loss or theft occurs.

For more information and insight from Kroll Ontrack’s data recovery experts, check out The Data Recovery Blog.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.