In our modern working world, new methods are constantly being developed to facilitate collaboration. When employees had to work from home overnight during the coronavirus pandemic, this reinforced the already growing BYOD trend. Find out how this concept works and what companies need to consider when introducing Bring Your Own Device here.

 

What is BYOD?

BYOD is the abbreviation for "Bring your own Device", which means "Bring your own end device". This term refers to the fact that private smartphones, laptops and tablets are integrated into closed networks. These include schools, universities and libraries as well as those of companies.

BYOD concept in companies: How does it work?

More and more employees are allowed to work with their own devices - and according to a recent Analysis by the market research company Mordor Intelligence continues to rise. For companies, this means that employees are using their preferred laptops or smartphones for work. They then download company-specific applications and programs onto their personal devices. This allows them to carry out their work on their personal laptop at any time and from anywhere.

BYOD models: The 3 levels

There are three levels for Bring your own Device, which differ in terms of how secure they are for the respective company.

 

Level 1: Informal BYOD (Unofficial BYOD):

The first level of BYOD is the unregulated form. It allows employees to use their private devices for business purposes without any guidelines or security measures from the company. This leads to considerable security risks, as company data is stored unencrypted on external devices.

 

Level 2: Bring Your Own Device with guidelines (Policy-Based BYOD):

In the second level of BYOD, companies have established firm security guidelines, privacy policies and regulations for the use of personal devices in the workplace. Although this level offers significantly more security than the first, it requires a certain degree of personal responsibility on the part of employees. After all, it is up to them to adhere to these regulations - if they don't, sensitive data can fall into the wrong hands.

 

Level 3: Managed BYOD (Fully Managed BYOD):

The third level describes a fully managed BYOD model in which companies implement strict security and management measures for BYOD devices. This can include only allowing employees to use devices and operating systems that the employer deems secure. It also allows companies to manage and remotely access the devices concerned, for example. This level offers the highest level of security and the greatest control for the company.

BYOD data protection: How secure is the concept?

 

The security of the Bring Your Own Device (BYOD) concept depends on various factors. As described above, this includes the level of security measures that companies implement. In addition, compliance with guidelines and employee awareness of data protection and security are also important.

 

What options are there for improving safety through BOYD guidelines?

BYOD guidelines should address the following points in particular:

  • Security policies include the use of passwords or PIN codes, updating operating systems and applications, encrypting data and activating remote wipe functions for lost or stolen devices.
  • The Implementation of mobile device management (MDM) significantly improves the security of BYOD devices. MDM enables companies to manage devices, enforce security policies, protect company data and delete data in an emergency.
  • Companies must ensure that the processing of personal data on BYOD devices complies with the applicable data protection laws and compliance regulations .
  • Employee training ensure that they are aware of best security practices for BYOD devices. These include avoiding insecure Wi-Fi networks, using apps securely and identifying phishing attacks.
  • The data encryption of business information on BYOD devices is also important to prevent the serious consequences of theft or loss.
  • In such cases, so-called remote wiping, which allows companies to delete data on BYOD devices remotely, also helps.
  • Company-internal BYOD guidelines should also stipulate that IT administrators are not permitted to Control over every device that can access the company network. In this way, security updates can be deployed from a central location, applications installed and devices checked for malware.

 

Legal basis

According to Art. 4 No. 7 GDPR the employer is responsible for the devices on which business-related processes are carried out, even if they do not belong to him and he only has limited access. Restricted access refers to the fact that only company-specific data may be viewed by the IT administrator on private end devices. This means that it is much more difficult to detect threats, as not all programs can be accessed.

 

Is BYOD even GDPR-compliant?

BYOD allows employees to process personal data on personal devices. For this to be GDPR-compliant, companies must comply with the applicable data protection laws and regulations that govern the protection of personal data. This may include obtaining consent from employees to process their data, implementing appropriate data protection measures and reporting data breaches.

BYOD employment law: risks for employers

The Employment law firm Taylor Wessing clarifies: In principle, the employer is obliged to provide the work equipment required for work performance. If the employer fails to do so, the employee can use their own device for work purposes under certain conditions. In this case, it is essential that it is determined in advance who will bear the costs of the device in the event of loss, theft or damage. However, not every employee is convinced by BYOD, as companies have deep access to personal end devices. This can give the impression that the employer is stingy, which in turn can reduce acceptance of the concept as well as employee satisfaction and motivation.

There are also risks for the employer in that private and company data are not clearly separated from each other on a private laptop. This increases the risk of sensitive data being stored or copied without authorization and falling into the hands of third parties. To avoid this, detailed BYOD guidelines based on current data protection concepts are a must.

Creating a BYOD policy: Which points are important?

Before companies allow their employees to handle business matters on their own devices, a policy is essential. Computerweekly recommends that the policy covers the following points:

 

  • Encrypted connection (VPN) for access to company systems
  • Security controls on the device
  • Prescribe components such as SSL certificates (Secure Sockets Layer) for device authentication and user identity
  • Define the company's rights to change the applications and data on the device - especially in the event of loss or theft
  • Encryption of stored data
  • Prohibition of storing passwords for business applications
  • Protection of device passwords
  • Registration of devices with an MDM platform or in UEM (Unified Endpoint Management)

BYOD sample company agreement

Templates such as the one from Haufe on "§ 6 Transfer and use of work equipment / VI. works agreement: Bring Your Own Device (BYOD)" are suitable for concluding such a works agreement.

What advantages does BYOD offer?

 

  • Cost savings for companies: If employees use their private end devices, there are no acquisition costs for companies. In addition, devices already in the company wear out more slowly if employees prefer to use their own.
  • Productivity: Employees know their own devices and are confident and familiar with them. As they are intuitive and familiar with them, they are often more productive with their own end devices. This may also be due to the fact that they are more modern than the hardware available to them in the company.
  • Employee satisfaction: As a rule, employees enjoy working with their preferred devices. This increases employee satisfaction and also has a positive effect on loyalty to the company.
  • Flexibility: If employees not only have a modern end device, but can also use it for business purposes at any time and from any location, meetings can take place more flexibly. Emails are also often answered more quickly.

What are the disadvantages of BYOD?

 

  • Complexity: Different end devices with different operating systems make the IT landscape in companies more complex. This harbors security risks. The IT security in the home office is therefore not nearly as high as in the company itself and provides a gateway for malware.
  • Control: IT administrators are responsible for controlling business applications and processes on private end devices. This requires not only training time, but also the cooperation of employees.
  • Data protection: In order to ensure personal data protection despite private devices, detailed guidelines and control measures are necessary. In addition, internal data can fall into the hands of unauthorized third parties if a cell phone or laptop is lost or stolen.
  • Gateway for malware: As IT administrators are only allowed to control the applications used for business purposes, viruses can get onto privately used end devices and access internal company data in other ways.

What BYOD solutions are available?

BYOD solutions are technologies, strategies and approaches that companies use to enable the use of their employees' personal devices in the workplace - while ensuring the security of company data and compliance with company policies. These include:

 

  • BYOD Management

BYOD management takes over the management and control of personal devices used by employees in a company for business purposes. The aim of BYOD management is to ensure the security, compliance and efficiency of these devices.

  • BYOD App

The BYOD app is a software application that is installed on employees' private devices and gives them access to business applications. The BYOD app enables the clear separation of professional and personal data. It also increases the security of company-specific information, as it can be monitored and managed remotely.

BYOD strategy

  • Best Practices

Managing BYOD with the cloud-based software solution Microsoft Intune has proven its worth. This gives administrators access to all mobile devices in the company network so that they can update and uninstall applications. To ensure that this solution can be used optimally in practice with an existing UEM application, the acmp Intune Connector. This provides a better overview and standardizes the interfaces in the acmp Console.

  • Prerequisites

In addition to the technical requirements - i.e. that every employee has the necessary mobile devices for private use - the legal requirements must also be ensured. Furthermore, the use of private work equipment is subject to co-determination by the works council in accordance with Works Constitution Act § 87 Co-determination rights by § 87 Para. 1 No. 6 BetrVG (introduction and use of technical equipment), § 87 Para. 1 No. 1 BetrVG (organization of the company with specifications on usage behavior) and § 87 Para. 1 No. 2, 3 BetrVG (working hours).

  • What needs to be considered?

If a company introduces a BYOD strategy, it is essential that all employees are aware of it and agree to it. In addition, various training courses on malware and guidelines are necessary so that every employee can work with their end device without causing damage to the company.

  • Organizational and technical measures for implementation

Once written guidelines have been drawn up and all employees have been trained, technical measures such as MDM, encryption, authentication, network access controls and security monitoring are introduced.

Alternative concepts: COPE, CYOD, COBO

Model BYOD COPE CYOD COBO
Significance Bring your own device Corporate-owned, personally enabled Choose your own Device Corporate, Business only
Summary Employees may use private devices for business purposes. Company provides employees with devices not only for business purposes but also for private use. Company provides employees with a selection of mobile devices from which they may choose which one they use for business purposes. Device provided by the company may only be used for business purposes.
Pro Employees have control over device selection.

 

 

Employers control the range of devices they support. Employees have a certain choice of equipment. The IT department controls the device and the applications on it to ensure maximum security and simple management.
Pro Employees use the same phone for business and personal use. Employees receive the benefits of a mobile device without bearing all or part of the associated costs. The IT department determines the scope of device diversity, e.g. that only Apple iOS products are used. The workforce is mobile.
Contra Comprehensive BYOD guidelines are necessary to ensure data protection and privacy. Employees expect the freedom to choose, upgrade and share mobile devices - restrictions are undesirable. Employees may already have a personal mobile device. Employees have limited flexibility and control.
Contra IT department manages an unlimited number of devices and operating systems. Cost and management trade-offs with a mobile device plan. Companies are responsible for devices on which personal information and applications are stored. The company is responsible for the cost and management of the devices.
Use Case In companies where employees already install work emails and other applications on private devices. In companies with security and compliance restrictions that still want to enable a mobile, flexible workforce. In companies where employees do not already have personal mobile devices or where the IT department needs to streamline the management of mobile devices. Workstations that require certain applications/mobile device functions outside the workplace. The devices can be shared by employees.

Conclusion: BYOD

Although BYOD offers many benefits such as flexibility and cost savings, it also brings challenges in terms of security and data protection. Companies need to address these challenges by implementing appropriate security measures, ensuring compliance and training employees in security awareness and practices. With the right measures and precautions, BYOD can be deployed safely and effectively in an organization.

Noch Fragen? Wir helfen Ihnen gerne weiter oder vereinbaren Sie direkt einen Termin unter:

 +49 2921 789 200 oder sales@aagon.com