joanie_wexler
Writer

Employee-owned devices are double-edged swords

Opinion
Mar 8, 20113 mins

Can you balance what you save in Capex with risk and related losses?

Increasingly, employees are buying their own mobile devices and bringing them into the enterprise. But just because you didn’t foot the bill for the gear doesn’t mean that your company’s off the hook for compliance responsibilities.

User-owned smartphones and tablets are considered individual-liable (IL) devices, meaning that the people who buy them are responsible for paying the service bill every month. However, any corporate e-mail and data access activity running through them remains subject to compliance regulations and auditing and discovery rules.

STRICT POLICY: Wells Fargo says no to personal smartphones and tablets, period

This is the uncomfortable conundrum in which most IT departments currently find themselves. Sure, most people have a mobile device of their own these days. So why not ditch the capital expense of buying everybody mobile computers and phones, particularly given the generally becalmed state of today’s IT budgets? People don’t want to carry separate gadgets for work and for personal use, anyway, so you might as well piggyback on the employees’ equipment for work access, too.

That’s a strong argument, for sure. Yet ensuring security and compliance (not to mention a whole slew of provisioning, troubleshooting/help desk, expense management and other issues) simply gets harder to do when you don’t own the devices.

So points out Aberdeen Group, which last month released a report, “Improve Efficiency and Reduce Costs by Automating Mobility Management.”

Aberdeen research found that 64% of organizations use at least some IL devices and, of those, 91% allowed users to run corporate e-mail on the devices. These dual-purpose devices, warns Aberdeen, are subject to e-discovery rules such as the United States Federal Rules of Civil Procedure (FRCP), which require the company to supply records in a civil suit without delay.

That said, however, Aberdeen reports that only 6% of those companies allowing IL devices to access corporate e-mail and data had access to all the call detail associated with them. And Aberdeen survey respondents reported that the average cost of an FRCP breach is $650,000.

Yikes — that means 94% would be depending on employees’ own record keeping to avoid such hefty penalties.

Aberdeen recommends building a clear action plan to automate workflows for managing enterprise mobility. And that’s the crossroads where so many enterprise IT departments find themselves now: wondering where to begin.

There are plenty of partial and comprehensive solutions out there and more coming from virtually every type of company in the networking business. Time to brew some strong coffee: Figuring out which one(s) is a fit will make for some long workdays in the coming year.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author