09:06 AM
Marilyn Cohodas
Marilyn Cohodas
Connect Directly

BYOD: 'We Have Met the Enemy & He Is Us'

As smartphone adoption continues at an unrelenting pace, the issues surrounding BYOD will become an even more challenging mobile security management issue.

When it comes to BYOD, Pogo, the central character of a long-running American comic strip, said it best: "We have met the enemy and he is us." It was 1971 when Walt Kelly penned the cartoon with the celebrated quote; Pogo, who lived in a swamp, was talking about Earth Day. Today, the same sentiment could apply to the phenomenon of bring-your-own-device to work.

Last week, Ericsson predicted that by 2019 the total number of devices subscribed to mobile networks will reach 9.3 billion, smartphone subscriptions will triple and smartphone traffic on broadband networks will increase 10 times. This should not be an earthshaking revelation for anyone in IT who has been grappling with the explosion of mobile devices in the workplace.

But the rapid and unrelenting pace of the smartphone uptake adds a new urgency to the problem. "It took more than five years to reach the first billion smartphone subscriptions," Ericsson senior vice president and head of strategy Douglas Gilstrap noted in a press release. "But it will take less than two to hit the 2 billion mark."

We already know that the issues surrounding mobile security and BYOD are complex, solutions elusive, and in some cases, surprisingly non-existent. InformationWeek’s recently released 2013 Mobile Security Survey shows that although corporate mobile security practices are improving, many security fundamentals aren’t being implemented. For example, 78 percent of respondents identify lost/stolen devices as a primary security concern, but just 28 percent require either hardware or software encryption, and only 39 percent have mobile device management (MDM) systems that could remotely wipe corporate content from a device.

In terms of BYOD policy, the vast majority of respondents -- 88 percent -- say their companies allow or will soon allow employees to bring their own mobile devices into the workplace to access corporate systems and store sensitive data. Yet only 39 percent of organizations have widely deployed MDM or other technologies considered to be an essential element in effectively managing and securing those devices.

Beyond the practical decisions about MDM or the best authentication practices for smartphones and tablets are new challenges springing from social media. Where do you draw the line between the personal and professional when social business collaboration via LinkedIn, Twitter, Google+, and Facebook is becoming an increasingly accepted -- and even encouraged -- part of the job description? How do you know if employees are watching cat videos or a substantive interview with an industry thought leader on a YouTube business channel? How do you mitigate the security risk these services introduce?

These are all issues I hope to explore with you in InformationWeek’s new security community. Just like any other community -- sci-fi nerds, sports fans, or Girl Scouts -- what binds people together are the unique memes, experiences, private jokes, and lingo that they share. Some have described that bond as a kind of secret handshake. In the coming weeks I hope to be "shaking hands" with you all as we hash over a wide range of IT security issues, everything from applications to zero-day exploits.

To kick things off, take a look at our flash poll on BYOD. We want to know your views on the best policy to manage bring-your-own-device. Your choices:

  • Make BYOD mandatory
  • Laissez faire -- anyone can bring in any device
  • Allow a restricted set of devices
  • Offer employer subsidies for approved devices
  • Forbid all employee-owned devices

And, if you have another idea or point of view, be sure to share it in the comments so that others can weigh in.

At the end of the day, when it comes to BYOD and every other security concern, there are no easy answers. As Pogo said 40-some years ago, the enemy is "us." And it will be up to all of us -- technology experts and end-users -- to figure out what to do about it. I look forward to the conversation.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
11/19/2013 | 11:16:24 PM
BYOD is here to stay
BYOD trend has already started and is happening. As the stats shown in this article, BYOD is here to stay. The appeal of BYOD is the increase in productivity and ease of use that end-users enjoy. I understand the risk and reservation from IT and that is exactly why an enterprise grade solution with same ease of use and productivity enhancement is important. 
User Rank: Apprentice
11/19/2013 | 3:24:53 PM
BYOD Challenges
I can understand the IT people that are against BYOD. However, I don't think they can do anything to stop it. It's already happening, whether officially sanctioned or not. So the question becomes - how to deal with it?

Does BYOD come with headaches? Of course it does. However, security issues and IT management headaches (how do I support all those devices?) can be addressed by using new HTML5 technologies that enable users to connect to applications and systems without requiring IT staff to install anything on user devices.
User Rank: Apprentice
11/18/2013 | 6:54:06 PM
Re: BYOD Backlash
The appeal of BYOD baffles me. Companies face management problems, and employees have to pay for their own devices out of their own pockets. How does ANYBODY win in this scenario?

That said: I have a personal iPhone and iPad and use both for work. So it goes. 
User Rank: Apprentice
11/18/2013 | 5:59:04 PM
BYOD challenges
BYOD creates so many challenges on multiple fronts. On the technical side, security controls get complicated due to all the different mobile platforms. On the legal side, issues of personal vs. corporate data and corporate control over personal devices are just starting to play out, making it tough to devise corporate policies.
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
11/18/2013 | 10:04:23 AM
Re: BYOD Backlash
A nightmare might be an understatement, Alison! I think part of the difficulty is that it's not purely a technical issue or a problem that can be totally resolved by a technology solution, even one as simple as keeping separate smartphones for work and office use. As mobile technology continues to blur the lines between work and personal, it's going to be harder not easier to sort out.
Alison Diana
Alison Diana,
User Rank: Apprentice
11/18/2013 | 9:31:35 AM
BYOD Backlash
I spoke to many CIOs last week -- and to a person, they all agreed that BYOD is a time-consuming nightmare. While employees and c-levels want this policy, CIOs themselves often continue to carry around two phones because they get the legal ramifications facing users who blur the lines between 'what's mine' and 'what's the company's' data. I foresee lots of work for attorneys as more employees face wiped and destroyed mobile devices.
SEC: Companies Must Disclose More Info on Cybersecurity Attacks & Risks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  2/22/2018
Facebook Aims to Make Security More Social
Kelly Sheridan, Associate Editor, Dark Reading,  2/20/2018
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.