Corporate policies vary on who buys the devices and who covers the monthly fees
As enterprises implement BYOD initiatives, IT managers have some key decisions to make: who purchases the devices, who pays for data plans and carrier contracts, and how does the company manage a mix of corporate and personal access to data on the devices.
At Wells Fargo, employees are responsible for paying data charges, says Jim Spicer, executive vice president and CIO for Corporate Technology and Data.
Spicer says now that industry and vendor offerings have matured, the company has implemented a pilot program with 3,000 employees. The goal of the experiment is to provide technologies that better enable workers to support the bank’s customers.
“It’s always been part of our strategy to test and evaluate products before bringing them to the enterprise. The pilot is where the rubber meets the road. We decided our team members would be responsible for data plans at this time,” says Spicer.
At Massachusetts Mutual Life Insurance Co., a BYOD program implemented in 2010 has led to half of the company’s employees personally owning their devices, and they pay for their own data plans. However, the company reimburses employees in cases where data access is work-related, says CTO Allan Campbell.
[ALSO: 10 BYOD worker types]
“In most cases, workers have their own smartphone anyway, and that’s their preference. If the applications they use are heavily weighted toward work, they’ll get reimbursed for the data charges,” he says.
Reimbursement hasn’t been an issue because the company doesn’t get many requests for it. Especially if the employee uses a smartphone primarily for personal reasons, adds Campbell.
“In circumstances where there’s a lot of personal use, we won’t offer reimbursement. If they have the type of job where they use their own email or calendaring software for work, we’ll reimburse for that. But a sales person on the road will opt for corporate applications, which we pay for,” he says.
Aetna pays data charges for employees if they’re using a company-supplied smartphone, but not for personally owned devices, says CIO Rich Leonard.
“Business departments are responsible for monthly data charges for corporate-owned devices and the limited number of shared devices. Individuals are responsible for their own data plans for their personal devices. However, Aetna has discount programs for most of the major carriers as an employee benefit,” he says.
When workers are subsidized for smartphone expense, the amount depends on where the company is located, says David Willis, an analyst at Gartner.
“The subsidized amount varies widely throughout the world. In the United States, employees who receive a subsidy for smartphone usage typically receive $30 to $40 per month for voice, data and text. Most large organizations are pursuing a mix of fully funded, partially funded, and unsubsidized devices, based on the user’s need for mobility in their job,” he says.
Many times it’s the employee who covers data plans. If they want to use the device of their choice, they have to cover it, says David Johnson, an analyst at Forrester
“Data charges are either handled as part of centralized billing on a corporate plan or expensed monthly by individual employees, but not all of them are eligible, and they end up paying the data charges or even the voice plan for smartphones out of their own pocket in order to get the device of their choice,” says David Johnson, an analyst at Forrester Research.
As more companies support both iOS and Android devices and begin to give them to employees, they limit roaming charges to ensure that employees cut down on data usage if they travel abroad.
At other companies, enterprises should subsidize only the service plan, says Gartner’s Willis.
“What happens if you buy a device for an employee and they leave the job a month later? How are you going to settle up? Better to keep it simple. The employee owns the device, and your company helps to cover usage costs,” he says.
Managing the mix of corporate and personal data
Wells Fargo’s Spicer says that in cases where a device is lost or stolen, the company can remotely wipe data format.
“While companies would like to think their employees wouldn’t lose their devices in the first place, it’s another piece of the puzzle that has to be factored in. One benefit is our ability to remote-wipe data from a lost or stolen mobile device,” he says.
Mass Mutual’s Campbell says the company scrutinizes smartphone usage to help determine how it handles reimbursement.
“We want to maintain a healthy balance between company and personal use. It’s not the wild, wild west. We look at individual cases and make adjustments from there,” he says.
When they put personal information on a company-owned device, they have to expect that due to privacy and security, they could lose the data.— David Johnson
Company policies that govern personal data workers put on their mobile devices are a common method of preventing them from having to deal with privacy or security issues. When they put personal information on a company-owned device, they have to expect that due to privacy and security, they could lose the data, adds Forrester’s Johnson.
“Unless the device is single-purpose and totally locked down, there is no practical way to prevent someone from capturing things on the device of a personal nature, so a policy is the most common remedy. Policies for putting personal information on a company-owned device usually include language that ensures that the company will take no responsibility for either the privacy of personal data, or its security. They generally reserve the right to wipe or confiscate the device at termination of employment, or if the device is lost or stolen, and the employee needs to accept that the company may not be able to get their personal information back,” he says.
Aetna’s mobile device policies covering corporate data access depend on an employee’s work function, and state that personal information beyond what is needed for their role in the company should not be stored on corporate computing devices.
“Employees that receive corporate-owned devices agree to policies that cover the management of the mobile devices. If the device is owned by the employee, Aetna applies policies that limit cut and paste between the Aetna secure container and personal storage and apps,” says Aetna’s Leonard.
“We’re finally reaching the point where IT officially recognizes what has always been going on. That is that people use their business device for personal stuff as well as for business. Once you realize that, you’ll understand the need to protect data in another way besides locking down the full device,” says Gartner’s Willis.
Containerization
Containerization technology has become a feature of mobile device management and security software to create separate, encrypted areas on smartphones. Because this allows a limited number of corporate applications and data to be stored separately from personal data, a company can shape its policies to govern only what resides in the container.
“Containerization is a way to separate church and state, to keep corporate data from being combined with personal data. We review applications used by employees, and things like data that could be accessing the cloud. It’s a challenge. We look at visibility and risk. Using containerization, certain applications can be walled off, for example, to prevent a document from being shared,” says Mass Mutual’s Campbell.
Wells Fargo’s Spicer also has found containerization to be a convenient way to separate corporate and personal data.
“Our team has looked at various technologies. We landed on using a container solution because it made the most sense for our business. It’s easy for our team members to use. It’s like an extra application on their device, but we’re able to manage, monitor and enforce mobile security policies. When your personal device is used for work, there is often a lack of separation between corporate and personal data. A container solution allows us to clearly define, manage and control security in what we call a company compartment, while allowing our team members to use the device personally outside of the container,” he says.
Even though a number of companies have found a containerization approach can help keep corporate and personal data separate, but the technology typically hasn’t been shown to be effective, according to Forrester’s Johnson
“Containerization will happen on an application-by-application basis, with technologies like app wrapping, but the user experience of having two complete smartphone environments on the same device is generally very poor. Apple doesn’t permit this on iOS anyway, so I don’t see virtual compartmentalization as a viable approach with the current state of technology,” he says.
Gartner’s Willis agrees that containerization is not well implemented by IT managers.
“Containerization is an option that is looking more attractive, but the problem so far is that containers have been poorly implemented from the user’s perspective. They’ve just been too difficult to use. If you constantly badger the user for security credentials and force them into an interface from a bygone era, they rebel,” he says.
However, Aetna’s Leonard has seen benefits to the technology. “The company takes a containerization approach between personal and corporate spaces. We have used this approach for over two years on thousands of devices without issue,” he says.
Webster is a freelance writer. He can be reached at johnwebstervt@gmail.com.




