Businesses Now Driving "Bring Your Own Device" Trend
snydeq writes "Companies are no longer waiting for users to bring in their own smartphones and tablets into business environments, they're encouraging it, InfoWorld reports. 'Two of the most highly regulated industries — financial services and health care (including life sciences) — are most likely to support BYOD. So are professional services and consulting, which are "well" regulated. ... The reason is devilishly simple, Herrema says: These businesses are very much based on using information, both as the service itself and to facilitate the delivery of their products and services. Mobile devices make it easier to work with information during more hours and at more locations. That means employees are more productive, which helps the company's bottom line.' Even those companies who haven't yet embraced bring your own device policies yet already have one in place, but don't know it, according to recent surveys."
Unless the employer provides ongoing cash payments to compensate the employee for use of thier device, this is a way of offloading IT cost onto the shoulders of employees. Add to that the fact that here in Canada, an employee of a company is not allowed to treat the cost fo a computer as a business expense (for tax purpoes), and the reduction in salary experienced by the employee is even greater than the benefit received by the employer.
FTFY.
Really, why buy equipment for your employees when you can just make them buy it on their own?
Palm trees and 8
with users bringing their own devices and loading sensitive data on them , customer data is lost in so many directions, its hard to point out the who actually "lost" the data in the first place.
This will not end well.
When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
Doesn't add any problems if you were already accessing software as a service over the internet, or if you were already providing software as a service to outsource partners etc.
Merely allowing employees access to the courtesy wifi internet access doesn't create new problems. Merely allowing employees to log into "internet" apps just like the contractors already do doesn't create any new problems.
Basically, its just a concept of getting rid of the "trusted" LAN and everyone and everything lives in the DMZ, both servers and clients. Once you reach the tipping point of moving your "IT" stuff into the internet DMZ, the process accelerates until its all there, and you are basically a colocated software as a service shop and a really small time ISP.
"Science flies us to the moon. Religion flies us into buildings." - Victor Stenger
Slashdot just posted this other Galen Gruman story based on how to get your user devices into your business behind IT's backs: http://it.slashdot.org/story/11/12/18/2154224/how-to-thwart-the-high-priests-in-it
Now another story about user devices getting into business behind IT's backs, also by Galen Gruman.
Enough already!
I8-D
I scanned TFA, and it looks like I will disagree with 70-90% of the assertions therein. I can't call them 'facts', because they aren't.
No mention of the security issues surrounding BYOD. For industries that reject bringing your own notebook to work, the assertion that financial services firms are embracing BYOD borders on the ludicrous, with a healthy dose of fantasy. Here at least, in a Fortune 50 financial services company, BYOD isn't even up for discussion. The security issues for Personally Identifiable Information alone rule out permitting any significant use of data on a device that is unsecured. And YOD is presumed to be unsecured, since it cannot be confirmed or assured by the people in data security that are responsible for preventing data loss. That's not 'minimizing' the loss, but preventing it. Nice try, Infoworld, but you're not fooling me into thinking I can load up my Android or iOS phone with corporate data. Not here anyways.
They then launch into how 'app-savvy' hardware is so great. Help me here - is 'app-savvy' another way of saying 'high-performance'? I thought so. Feh.
Good Devices may supply mobile device management systems to their customers, but I can name you a 50,000 seat company that may or may not use it, but if they do it's for captive devices - Blackberrys - that are never going to be BYOD. Quoting such a study is regurgitating their self-serving (and I expect nothing less, they are out for a propfit after all) hype and fantasy that with their services, BYOD is perfectly secure. Again, where I work, promises are not enough. Security is based on assurance. Little of it is provided by third parties. I can't even share data with co-workers in many/most cases. The concept of letting employees run mission-critical (data is mission-critical to a financial services company) or senstitive data apps would not be laughable here. It would be dismissed out of hand.
More to the point, however, the idea that somehow the device changes the nature of your work is both spot on and wide of the mark. If you're primarily displaying data, a table is par excellence. as soon as you need to enter data, it's a losing proposition. Depending on your role, tablets and smartphones offer some advantages.
My brother has been delivering real-time production data to his workforce worldwide (wherever there is a signal, WiFi, CDMA, GSM, or satellite) since Palm first made a phone. He's added native support for every OS as of last year. He sees the craze, and his boss asks him sometimes about how this 'Android thing' would work for them. And he responds that it has been working 'for a while now'.
And no, they do not do BYOD. They supply whatever is required for whatever geographic region the rep is in. But they could suport BYOD, since he supports some customers directly with the same apps, where they are BYOD only because it isn't 'his' device. And he sees the security issues. SSL is so flawed he considers it useless, but there is nothing else right now except for VPN tunnels. That's where he's at, and some Java sandboxing that he thinks is ensuring data is gone when the session is gone. But he knows that rooting devices will some day thwart that.
And since I can root most Android devices without a lot of effort, that alone makes BYOD for work just impossible.
Lastly, I read up on the link from IW that Android is making inroads into business environments that the IT staff are unaware of. Well, actually, I can't use any of my personal mail at work any more unless it's on my Android phone. I don't consider that a BYOD instance, since if I connected to the corporate WiFi, I wouldn't be able to use personal email on it then either. I can. theoretically, dump data to the phone via USB or a uSD card, but that would be logged and scanned, and PII would be captured and alarms sounded. Yes, my work notebook can be prevented from downloading data to a removable device, any sort of device. It can also check if the device is encrypted, which they all must be.
Hype. Misstatement. Fantasy. But it may sell more stuff, and that would be the point of TFA.
deleting the extra space after periods so i can stay relevant, yeah.
First off, those articles are very badly written. And they seem to be linked to InfoWorld's recent run of articles about how IT is PREVENTING such "adoption". Strange.
Secondly, he's quoting a guy from a firm that sells products to manage phones. He is NOT quoting ANYONE from ANY company in the health care industry.
What?
It is DECEMBER 2011. That's some fast action by "most companies" in a few months.
There's a HUGE difference between allowing such devices on the UNSECURED WIRELESS NETWORK and connecting them to the servers that hold private data.
He doesn't seem to be covering that difference.
And he doesn't have any quotes from companies that are doing what he claims.
This is twice the submitter is from the site that has the story, worse its nearly identical if not the same one (ain't going to read this slashvertisement) where they were went off on IT departments enforcing standards.
* Winners compare their achievements to their goals, losers compare theirs to that of others.
He's writing about how "most companies" are allowing users to bring in their own equipment ... while writing about how IT "priests" are preventing users from bringing in their own equipment.
But he isn't doing interviews with companies that are allowing users to connect to private. company data (the kind that would cause problems if leaked) via the users' own devices. Particularly companies covered by specific regulations such as health care.
Wouldn't at least one interview with the IT VP of a major hospital be appropriate by now? If nothing else, just to provide support for his claims.
Strange how that isn't happening.
My local HR was freaked out about my temporary lack of a landline
They need to reach you instantly, at any hour of the day? Then they need to buy you a cell phone. Maybe you spent the past few nights at your new girlfriend's house, or you had to accompany your spouse to a funeral, or you decided to spend a few hours walking along the beach to center yourself.
Ended up listing my cellphone as both home and cellphone
So you are basically paying by the minute when your employer calls you. Yes, I know modern cell phone plans sell you blocks of hundreds or thousands of minutes, but the point here is that you are paying to make yourself available to your employer when you are not even at your office/job site. It may be rude to say this, but this is not really a situation that you should be in.
Palm trees and 8
It just takes 1 piece of malware on your network or one security event to loose all the financial benefit.
But BYOD is better from a security perspective - those deveice are never on your network! The whole point is to move everything a user can pohysically touch into the DMZ, and limit the "trusted LAN" to the datacenter itself. It's a far, far better security model.
And if these BYODs actually hold any sensitive informaiton, you're doing it wrong. The end-user devices get only pixels! All the email and documents stay in the datacenter, the end-user devices only ever see a remote desktop.
Socialism: a lie told by totalitarians and believed by fools.
Then in the end they get their asses handed to them hard, and by hard, I mean reaalllly hard .
No competent IT person will ever agree to allow BYOD to propagate through the workplace. Not with access to any kind of sensitive data whatsoever that is not already passing through secured portals.
Secured websites that allow access, that they themselves are limited in what they can show, is one thing. That allows functionality not just in the workplace, but in the field. It also allows a lot more freedom in what kind of devices can be used. Tablets, phones, computers, etc. Freedom in operating systems is great too. If the employee can get everything done in a web browser, then you don't need the expensive Windows fat clients.
Bring your own personal computer in to work? Only the executives would think of something so "full-retard" like that.
I have always locked corporate down harder than East Germany. Nobody even knows the wireless passwords to access the corporate network, and executives who demand business laptops, get them configured by IT. Some places even get the Ethernet locked down further so that unauthorized devices cannot connect. They don't know the passwords either. No stupid Facebook, Twitter, etc. from within the corporate network.
To make it easier, I just provide a public wireless network with a simple password for all the employees to use. Separate IP address space, and not even remotely connected to the corporate network and VPNs. If they want Facebook, Twitter, and all the Social Media crap plus media streaming of YouTube, Pandora, etc. they can do it on another network that won't impact corporate operations. I make it a clear policy that they can use the public network with their own devices in any way they want because it is safer. The only thing they are not allowed to do is directly transfer or connect their devices to corporate hardware. You make it reasonable like that, and the vast majority of employees are happy and not trying to bypass your corporate security to get to Facebook while on break.
Security and Usability is a balancing act.
If the company execs want to shove Usability down IT's throat, despite common sense and valid warnings, and at the expense of security, just to gain some perceived ability to work employees harder for the bottom line ... then get your resume ready to jump ship.
You will have to jump ship. I have to be skeptical about this. Financial institutions and highly regulated companies doing this? I have to doubt this. Any security company that comes in to audit them or evaluate their security is going to have a field day killing several trees with reports to the execs about how insecure and vulnerable their network is. Would it pass PCI compliance? Doubtful.
All it takes is one really bad screwup. Lose a half million credit numbers (with full info) and then the executives might really understand the cost of letting employees bring in their tainted malware infested, porn overloaded, crap equipment from home.
I write this while downloading an ISO to fix an executives business laptop that they crapped up with malware.
It's already a never ending battle for IT to keep the corporate network and assets from being owned by hackers and malware. Handcuffing us and force marching us down a path to the 9th level of IT hell is just an oh-so-good idea. There is a really really good reason why IT has to control all hardware connected up to corporate. Any hardware we don't control is not just a point of failure, but a security vulnerability waiting to be exploited.
How many hacking groups out there are just waiting for that "big fat gold nugget" that is a laptop being connected up to a major financial institution from the inside?