Bring your own device

Bring your own device (BYOD /ˌb w ˈd/[1]) (also called bring your own technology (BYOT), bring your own phone (BYOP), and bring your own personal computer (BYOPC)) refers to being allowed to use one's personally owned device, rather than being required to use an officially provided device.

There are two major contexts in which this term is used. One is in the mobile phone industry, where it refers to carriers allowing customers to activate their existing phone (or other cellular device) on the network, rather than being forced to buy a new device from the carrier.[2][3][4]

The other, and the main focus of this article, is in the workplace, where it refers to a policy of permitting employees to bring personally owned devices (laptops, tablets, smartphones, etc.) to work, and to use those devices to access privileged company information and applications.[5] This phenomenon is commonly referred to as IT consumerization.[6]

BYOD is making significant inroads in the business world, with about 80% of employees in high-growth markets such as Brazil and Russia and 50% in developed markets already using their own technology at work.[7] Surveys have indicated that businesses are unable to stop employees from bringing personal devices into the workplace.[8] Research is divided on benefits. One survey shows around 95% of employees stating they use at least one personal device for work.

History

The term was initially used by a VoIP service provider BroadVoice[9] in 2004 (initially for AstriCon, but then continued as a core part of the business model) with a service allowing businesses to bring their own device for a more open service provider model. The phrase and the "BYOD" acronym is a take-off on "BYOB", a party invitation term first recorded in the 1970s, standing for "bring your own beer/booze/bottle".[10][11][12]

The term BYOD then entered common use in 2009, courtesy of Intel, when it recognized an increasing tendency among its employees to bring their own smartphones, tablets and laptop computers to work and connect them to the corporate network.[13] However, it took until early 2011 before the term achieved prominence, when IT services provider Unisys and software vendor Citrix Systems started to share their perceptions of this emergent trend. BYOD has been characterized as a feature of the "consumer enterprise" in which enterprises blend with consumers.[14] This is a role reversal in that businesses used to be the driving force behind consumer technology innovations and trends.[15]

In 2012, the U.S. Equal Employment Opportunity Commission adopted a BYOD policy, but many employees continued to use their government-issued BlackBerrys because of concerns about billing, and the lack of alternative devices.[16]

The proliferation of devices such as tablets and smartphones, now used by many people in their daily lives, has led to a number of companies, such as IBM, to allow employees to bring their own devices to work, due to perceived productivity gains and cost savings.[17] The idea was initially rejected because of security concerns but more and more companies are now looking to incorporate BYOD policies.

According to a 2018 study, only 17 percent of enterprises provide mobile phones to all employees, while 31 percent provide to none and instead rely entirely on BYOD.[18] The remaining 52 percent have some kind of hybrid approach where some employees receive corporate mobile phones and others are expected to bring their own.

Prevalence

The Middle East has one of the highest adoption rates (about 80%) of the practice worldwide in 2012.[19]

According to research by Logicalis, high-growth markets (including Brazil, Russia, India, UAE, and Malaysia) demonstrate a much higher propensity to use their own device at work. Almost 75% of users in these countries did so, compared to 44% in the more mature developed markets.[20]

In the UK, the CIPD Employee Outlook Survey 2013 revealed substantial variations by industry in the prevalence of BYOD.

Advantages

While some reports have indicated productivity gains by employees, the results have drawn skepticism.[21] Companies such as Workspot believe that BYOD may help employees be more productive.[22][23] Others say that using their own devices increases employee morale and convenience and makes the company look like a flexible and attractive employer.[24] Many feel that BYOD can even be a means to attract new hires, pointing to a survey that indicating that 44% of job seekers view an organization more positively if it supports their device.[25]

Some industries are adopting BYOD more quickly than others. A recent study[26] by Cisco partners of BYOD practices found that the education industry has the highest percentage of people using BYOD for work, at 95.25%.

A study[27] by IBM spin-off Kyndryl says that 82% of employees think that smartphones play a critical role in business. The study also suggests that the benefits of BYOD include increased productivity, employee satisfaction, and cost savings for the company. Increased productivity comes from a user being more comfortable with their personal device; being an expert user makes navigating the device easier, increasing productivity. Additionally, personal devices are often more up-to-date, as the devices may be renewed more frequently. BYOD increases employee satisfaction and job satisfaction, as the user can use the device they have selected as their own rather than one selected by the IT team. It also allows them to carry one device rather than one for work and one for personal use. The company can save money as they are not responsible for furnishing the employee with a device, though this is not guaranteed.

Disadvantages

Although the ability of staff to work at any time from anywhere and on any device provides real business benefits, it also brings significant risks. Companies must deploy security measures to prevent information ending up in the wrong hands.[28] According to an IDG survey, more than half of 1,600 senior IT security and technology purchase decision-makers reported serious violations of personal mobile device use.[29]

Various risks arise from BYOD, and agencies such as the UK Fraud Advisory Panel encourage organisations to consider these and adopt a BYOD policy.[30][31]

BYOD security relates strongly to the end node problem, whereby a device is used to access both sensitive and risky networks and services; risk-averse organizations issue devices specifically for Internet use (termed Inverse-BYOD).[32]

BYOD has resulted in data breaches.[33] For example, if an employee uses a smartphone to access the company network and then loses that phone, untrusted parties could retrieve any unsecured data on the phone.[34] Another type of security breach occurs when an employee leaves the company; they do not have to give back the device, so company applications and other data may still be present on their device.[35]

Furthermore, people may sell their devices and forget to wipe sensitive information before the handover. Family members may share devices such as tablets; a child could play games on a parent's tablet and accidentally share sensitive content via email or other means such as Dropbox.[36]

IT security departments wishing to monitor usage of personal devices must ensure that they monitor only activities that are work-related or access company data or information.[37]

Organizations adopting a BYOD policy must also consider how they will ensure that the devices which connect to the organisation's network infrastructure to access sensitive information will be protected from malware. Traditionally if the device was owned by the organisation, the organisation can dictate for what purposes the device may be used or what public sites may be accessed from the device. An organisation can typically expect users to use their own devices to connect to the Internet from private or public locations. The users could be susceptible from attacks originating from untethered browsing or could potentially access less secure or compromised sites that may contain harmful material and compromise the security of the device.[38]

Software developers and device manufacturers constantly release security patches to counteract threats from malware. IT departments that support organisations with a BYOD policy must have systems and processes to apply patches protecting systems against known vulnerabilities of the devices that users may use. Ideally, such departments should have agile systems that can quickly adopt the support necessary for new devices. Supporting a broad range of devices obviously carries a large administrative overhead. Organisations without a BYOD policy have the benefit of selecting a small number of devices to support, while organisations with a BYOD policy could also limit the number of supported devices, though this could defeat the objective of allowing users the freedom to choose their preferred device freely.[39]

Several market and policies have emerged to address BYOD security concerns, including mobile device management (MDM), containerization and app virtualization.[40] While MDM allows organizations to control applications and content on the device, research has revealed controversy related to employee privacy and usability issues that lead to resistance in some organizations.[41] Corporate liability issues have also emerged when businesses wipe devices after employees leave the organization.[42]

A key issue of BYOD which is often overlooked is BYOD's phone number problem, which raises the question of the ownership of the phone number. The issue becomes apparent when employees in sales or other customer-facing roles leave the company and take their phone number with them. Customers calling the number will then potentially be calling competitors, which can lead to loss of business for BYOD enterprises.[43]

International research reveals that only 20% of employees have signed a BYOD policy.[44]

It is more difficult for the firm to manage and control the consumer technologies and make sure they serve the needs of the business.[45] Firms need an efficient inventory management system that keeps track of the devices employees are using, where the device is located, whether it is being used, and what software it is equipped with.[45] If sensitive, classified, or criminal data lands on a U.S. government employee's device, the device is subject to confiscation.[46]

Another important issue with BYOD is of scalability and capability. Many organisations lack proper network infrastructure to handle the large traffic generated when employees use different devices at the same time. Nowadays, employees use mobile devices as their primary devices and they demand performance which they are accustomed to. Earlier smartphones used modest amounts of data that were easily handled by wireless LANs, but modern smartphones can access webpages as quickly as most PCs do and may use radio and voice at high bandwidths, increasing demand on WLAN infrastructure.

Finally, there is confusion regarding the reimbursement for the use of a personal device. A recent court ruling in California indicates the need of reimbursement if an employee is required to use their personal device for work. In other cases, companies can have trouble navigating the tax implications of reimbursement and the best practices surrounding reimbursement for personal device use. A 2018 study found that 89 percent of organizations with a BYOD policy provide a full or partial stipend to compensate employees for their mobile phone expenses.[47] On average, these organizations paid employees $36 per month as a BYOD stipend.[47]

Personally owned, company enabled (POCE)

A personally owned device is any technology device that was purchased by an individual and was not issued by the agency. A personal device includes any portable technology such as cameras, USB flash drives, mobile wireless devices, tablets, laptops or personal desktop computers.

Corporate-owned, personally enabled (COPE)

As part of enterprise mobility, an alternative approach are corporate-owned, personally enabled devices (COPE). Under such policies, the company purchases and provides devices to their employees, but the functionality of a private device is enabled to allow personal usage. The company maintains all of these devices similarly to simplify its IT management; the organization will have permission to delete all data on the device remotely without incurring penalties and without violating the privacy of its employees.

BYOD policy

A BYOD policy must be created based on the company's requirements.[48] BYOD can be dangerous to organizations, as mobile devices may carry malware. If an infected device connects to the company network, data breaches may occur. If a mobile device has access to business computing systems, the company's IT administrator should have control over it.[49] A BYOD policy helps eliminate the risk of having malware in the network, as the management team can monitor all contents of the device and erase data if any suspicious event is captured. BYOD policies may specify that the company is responsible for any devices connected to a company network.[50]

Additional policies

BYOD policies can vary greatly from organization to organization depending on the concerns, risks, threats, and culture, so differ in the level of flexibility given to employees to select device types. Some policies dictate a narrow range of devices; others allow a broader range of devices. Related to this, policies can be structured to prevent IT from having an unmanageable number of different device types to support. It is also important to state clearly which areas of service and support are the employees' responsibilities versus the company's responsibility.[51]

BYOD users may get help paying for their data plans with a stipend from their company. The policy may also specify whether an employee is paid overtime for answering phone calls or checking email after hours or on weekends. Additional policy aspects may include how to authorize use, prohibited use, perform systems management, handle policy violations, and handle liability issues.[52]

For consistency and clarity, BYOD policy should be integrated with the overall security policy and the acceptable use policy.[51] To help ensure policy compliance and understanding, a user communication and training process should be in place and ongoing.

See also

References

  1. ^ "Pronunciation of BYOD". Macmillan Dictionary. London. 2018. Retrieved March 7, 2020.{{cite encyclopedia}}: CS1 maint: location missing publisher (link)
  2. ^ "Bring Your Own Phone to AT&T". AT&T Wireless... 2020. Frequently asked questions: What does "Bring Your Own Device" or "BYOD" mean?. Retrieved March 7, 2020.
  3. ^ "Bring your own device (BYOD) guide". support.t-mobile.com. Archived from the original on August 3, 2019. Retrieved August 2, 2019.
  4. ^ "Bring Your Own Device And Switch To Verizon Today". Verizon Wireless... Verizon. 2018. Retrieved March 7, 2020.
  5. ^ BYOD on pcworld.com[permanent dead link]
  6. ^ "Enterprise & Gateway Suites – Trend Micro". Trend Micro.
  7. ^ "BYOD – Research findings". Logicalis. Archived from the original on March 18, 2021. Retrieved February 12, 2013.
  8. ^ Rene Millman, ITPro. "Surge in BYOD sees 7/10 employees using their own devices." August 12, 2012. Retrieved June 5, 2013.
  9. ^ "Broadvoice". March 21, 2004. Archived from the original on March 21, 2004. Retrieved October 23, 2019.
  10. ^ "New words notes December 2014". Oxford English Dictionary. December 1, 2014. Retrieved August 2, 2019.
  11. ^ "Definition of BYOB". Merriam-Webster. Retrieved August 2, 2019.
  12. ^ "Definition of byob | Dictionary.com". Dictionary.com. Retrieved August 2, 2019.
  13. ^ "Mobile: Learn from Intel's CISO on Securing Employee-Owned Devices". Gov Info Security. Retrieved January 10, 2013.
  14. ^ "Rise of the 'consumer enterprise'". June 24, 2013.
  15. ^ Lisa Ellis; Jeffrey Saret; Peter Weed (2012). "BYOD: From company-issued to employee-owned devices".
  16. ^ "BlackBerry Strategizes For More U.S. Government Clients". January 7, 2013. Archived from the original on February 15, 2013.
  17. ^ "Support BYOD and a smarter workforce". IBM. Archived from the original on February 7, 2015. Retrieved December 29, 2014.
  18. ^ "The State of Enterprise Mobility in 2018: Five Key Trends". Samsung Business Insights. June 6, 2018. Retrieved October 19, 2019.
  19. ^ El Ajou, Nadeen (September 24, 2012). "Bring Your Own Device trend is ICT industry's hottest talking point at GITEX Technology Week". Forward-edge.net. Archived from the original on May 28, 2015. Retrieved September 26, 2012.
  20. ^ "BYOD research findings". Logicalis. Archived from the original on March 18, 2021. Retrieved February 12, 2013.
  21. ^ UC Strategies (May 1, 2013). "BYOD's Productivity Gains Are "Hard to Calculate" – Study Says". Archived from the original on July 14, 2014. Retrieved July 11, 2014.
  22. ^ Gina Smith (February 16, 2012). "10 myths of BYOD in the enterprise". TechRepublic. Archived from the original on September 26, 2013. Retrieved May 21, 2012.
  23. ^ "Cisco ASA + Workspot = BYOD". Workspot. Archived from the original on July 14, 2014.
  24. ^ Bernice Hurst (August 6, 2012). "Happiness Is ... Bringing Your Own Computer Devices to Work". RetailWire.
  25. ^ Kevin Casey (November 19, 2012). "Risks Your BYOD Policy Must Address". InformationWeek. Retrieved June 19, 2013.
  26. ^ "90% American workers use their own smartphones for work". Archived from the original on December 3, 2013. Retrieved November 23, 2013.
  27. ^ "What is bring your own device?". IBM.
  28. ^ "Release details". Archived from the original on February 13, 2015. Retrieved February 13, 2015.
  29. ^ "Threat, Violation and Consumerization Impact" (PDF). forescout.com.
  30. ^ "Bring your own device (BYOD) policies" (PDF). Fraud Advisory Panel. June 23, 2014. Retrieved June 23, 2014.[permanent dead link]
  31. ^ "The Rise and Risk of BYOD – Druva". September 22, 2014.
  32. ^ The U.S. Air Force Research Lab's (AFRL) Leader iPad Pilot used this method to provide its researchers unfiltered access to the Internet, reserving its filtered, sensitive network for other use.
  33. ^ "Nearly half of firms supporting BYOD report data breaches".
  34. ^ 4 Steps to Securing Mobile Devices and Apps in the Workplace – eSecurityPlanet.com
  35. ^ Wiech, Dean. "The Benefits And Risks Of BYOD". Manufacturing Business Technology. Archived from the original on October 24, 2013. Retrieved January 28, 2013.
  36. ^ "Greatest Threat to Enterprise Mobility: Employee's Children". May 1, 2013. Archived from the original on August 22, 2013.
  37. ^ "Bring your own device: Security and risk considerations for your mobile device program" (PDF). September 2013.
  38. ^ "Enterprise & Gateway Suites – Trend Micro". Trend Micro.
  39. ^ "Implementing BYOD Plans: Are You Letting Malware In?" (PDF). Retrieved August 26, 2017.
  40. ^ David Weldon, FierceMobileIT. "No one-size-fits-all solution for BYOD policies, panel reveals Archived July 16, 2014, at the Wayback Machine." May 13, 2014. Retrieved July 11, 2014.
  41. ^ Tom Kaneshige, CIO. "Attack of the BYOD-Killing MDM Software." February 4, 2014. Retrieved July 15, 2014.
  42. ^ Lauren Weber, Wall Street Journal. "BYOD? Leaving a Job Can Mean Losing Pictures of Grandma." January 21, 2014. Retrieved July 15, 2014.
  43. ^ Kaneshige, Tom. "BYOD's Phone Number Problem". Archived from the original on March 1, 2014. Retrieved March 26, 2013.
  44. ^ "BYOD Policy". Logicalis. Archived from the original on February 26, 2013. Retrieved February 12, 2013.
  45. ^ a b Kenneth C. Laudon, Jane P. Laudon, "Management of Information Systems"
  46. ^ Jarrett, Marshall. "Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations" (PDF). Office of Legal Education. Retrieved May 15, 2013.
  47. ^ a b "How Much Should You Compensate BYOD Employees for Mobile Expenses?". Samsung Business Insights. June 2, 2018. Retrieved October 19, 2019.
  48. ^ Bettanin, Eric (January 2013). "11 considerations to underpin your company's BYOD strategic planning". Information Age. Sydney: Australian Computer Society.
  49. ^ Cassidy, Steve (January 2015). "Mobile device management". PC Pro. London: Dennis Publishing Ltd. ISSN 1355-4603 – via ProQuest Central.
  50. ^ "As Mobile Devices Catch On with Businesses, Data Breach Risks Grow | PropertyCasualty360". PropertyCasualty360. Retrieved December 3, 2018.
  51. ^ a b Hassell, Jonathan. "7 Tips for Establishing a Successful BYOD Policy". CIO. Retrieved February 25, 2017.
  52. ^ Emery, Scott (2012). "Factors for Consideration when Developing a Bring Your Own Device (BYOD)" (PDF). University of Oregon Interdisciplinary Studies Program Presentation. Archived from the original (PDF) on July 14, 2018. Retrieved February 25, 2017.