Share this article
Employees in many industries and sectors are increasingly using their own devices for work in 2021. But is this the way forward? SRM consultant, Claire Greathead, takes a closer look at BYOD.
BYOD, or Bring Your Own Device, is not a new concept. In fact, it’s been fairly normal for people to use personal phones, tablets and laptops to perform various work activities over the last decade. This can range from the odd phone call to full-time PC usage, depending on the business and the job role. But with the COVID-19 pandemic forcing thousands of UK workers to adapt to remote working, BYOD is quickly transitioning from an option to the norm.
While BYOD undoubtedly has the power to change the way businesses approach procurement, resourcing and communications, there are also a number of risk factors that require greater consideration – particularly when it comes to cybersecurity.
But before we get into the pros and cons of this working model, let’s be a little clearer in our definition of BYOD:
Bring Your Own Devices involves giving staff the option to use their own devices for work, including laptops, smartphones and tablets. It can also include a portable hard drive or any consumer piece of tech that employees can use to fulfil their role within the business.
There are several key benefits to BYOD, which is why 45% of UK businesses currently welcome the initiative, according to date reported by Statista in 2020.
The first, and most obvious, of these is cost-based (not surprisingly). Investing in hardware for all staff can be hugely expensive and, at a time when many businesses are struggling, the additional overheads incurred by purchasing digital devices might be prohibitive. So, having employees use their own is an effective way to instantly cut costs and reduce the pressure on company cashflow. In fact, a report from Cisco found that businesses using BYOD save an average of $350 per person, per year.
But BYOD can save businesses time as well as money. The same study from Cisco found that workers saved an average of 81 minutes per week by using their own equipment, and this adds up to nine full working days every year. BYOD can improve productivity within your organisation by allowing staff to use devices that they are familiar with and comfortable using.
BYOD gives employees the chance to choose what works best for them. If a team member uses an Apple smartphone, Mac and tablet at home, they may find it hard to adjust to a Windows PC for work, and vice versa.
It’s clear that there are numerous benefits to letting staff use their own devices for work, but there are also security concerns that should not be ignored. Any device that’s used for work purposes is likely to connect with business networks and have access to sensitive company data. Employees using their own devices from remote locations to access company networks and documentation can present a whole host of security issues.
Personal devices typically have inferior security tools in place than hardware used specifically for business purposes. And what’s more, analysis by the tech company Tessian found that 52% of employees engage in riskier online behaviour when using their own devices for work at home.
While the risks are undoubtedly greater with BYOD, this doesn’t mean that the challenges are insurmountable. What is required, however, is a clear and easy-to-use BYOD policy that is aligned with an information security framework such as ISO27001. Even if an organisation doesn’t have any plans to officially achieve ISO27001 compliance, following the requirements of this security standard will ensure adherence to best practice in relation to personal device usage.
In particular, the following controls are most relevant for BYOD:
A.6.2.1 – Mobile device policy
A.6.2.2 – Teleworking
A.13.2.1 – Information transfer policies and procedures
A.13.2.3 – Electronic messaging
The main goal of any BYOD policy is to inform the behaviour of users within your business. On that basis, any policy should address:
In addition to this, a good BYOD policy should identify:
If remote working or hybrid working is likely to continue in your business beyond the pandemic, it is more critical than ever that your remote working and BYOD policies are clear and understood within your organisation. If you could do with help getting your policies and procedures in shape, why not get in touch with the ISO27001 consultants at SRM today by clicking here.