You’ve lost the battle, can you win the war?

Opinion
Aug 2, 20113 mins

Last issue we talked about the survey Sailpoint had commissioned to judge employee attitudes about improper access to and disposal of sensitive corporate data. Today there’s another survey to examine.

Last issue we talked about the survey SailPoint had commissioned to judge employee attitudes about improper access to and disposal of sensitive corporate data. Today there’s another survey to examine.

Courion corporation commissioned Davies Murphy Group to survey IT decision-makers at large enterprises worldwide, and collected responses from 988 (73% with more than 1,000 employees). The survey results indicate that enterprises are fairly confident that they can assure appropriate user access to resources on-premise, but become much less confident when users connect via the cloud or on mobile devices or laptops.

ANALYSIS: Debate rages over how to manage personal mobile devices used for work

The scariest result: 2 out of every 3 large enterprises report that they have employees that are connecting their own personal mobile devices to the corporate network, and yet more than 1 out of every 5 organizations do not have a policy in place to govern this use, or are not even aware if a policy exists. This has led to a situation in which nearly 10% of enterprises have been faced with a data breach following the loss of a mobile device that has accessed their network.

Among the key data points derived from the survey are:

• On a scale of 0-5, with 5 being very confident, 57% of respondents marked either a 4 or a 5 to indicate their level of confidence that they could control access to resources on their corporate network. That number dropped to 34% when asked about cloud access, and 40% when handling employee access via mobile devices and laptops.

• 88 enterprise (nearly 1 in 10) respondents admitted to having experienced a data breach as a result of a lost mobile device.

• 69% of enterprises say their employees are using personally owned mobile devices (not company-issued) to connect to the corporate network.

• Nearly one-quarter of enterprises (21%) either do not have a policy in place to govern the use of personal mobile devices on their network, or don’t know if one exists.

This is the tip of the iceberg of a new phenomenon, which my colleague Martin Kuppinger addressed last month: “BYOD: Again one of these acronyms. It stands for ‘Bring Your Own Device.’ You’d also say that it stands for IT departments accepting that they’ve lost against their users. They have lost the discussion about which devices shall be allowed in corporate environments.”

IT, and by extension the enterprise, has lost control over the devices attaching to its corporate domain and its resources. Users are willing, some even eager, to plunder those resources. What are you doing about it? What can you do about it? Tell me, and I’ll share the answers.