ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

BYOD in the digital age

Jasson Casey at Beyond Identity explores the balance between security and privacy in today’s remote working landscape

 

Bring Your Own Device (BYOD) is an approach to using personal technology for work that has only become widely popularised in the last 15 years or so but, as a concept, has been around for much longer. Back in the 1980s, for instance, pocket computers from the likes of Casio, Compaq and Psion brought miniaturised tech to workers everywhere.

 

Fast forward a few years, and the arrival of email-enabled mobile devices at the turn of the millennium signalled the start of a growth and decline story that peaked in 2011 when over 50 million Blackberry devices alone were shipped worldwide.

 

This, however, pales into insignificance when compared to the unprecedented rise in the adoption of smartphones and connected laptops. Fuelled by these innovations, BYOD became a way for people to build more convenience and balance into their working lives. On the one hand, having access to emails and other digital assets while out of the office was incredibly handy for millions of workers. On the flipside, however, there were new and troubling security risks.

 

Indeed, in the years before the Covid pandemic, organisations everywhere were grappling with the trade-off between the benefits of mobile working and the opportunities offered to cybercriminals looking for new ways to access corporate networks. The dramatic rise in remote working seen in the last few years has changed the BYOD dynamic yet again with 60% of companies expanding their BYOD programs during the pandemic, according to industry research.

 

Today, organisations everywhere no longer have a shared physical office presence and millions of employees now use their own devices for work by default.  At the beginning of 2023, around 40% of UK working adults reported having worked from home. Even for those workers whose employers don’t offer remote working as an option, BYOD still retains the potential to widen the network perimeter cybersecurity teams must try to protect.

 

While organisations can sometimes insist that employees use Mobile Device Management (MDM), this method can often infringe on employee privacy, with many members of the workforce reluctant to install it. Adding to this, currently there are 1.4 million freelancers and contractors in the UK.

 

These individuals need to access company resources within their personal devices but are not required to follow business security protocols, leading to complications. Both remote employees and contractors can cause a security headache for today’s organisations.

 

Bring your own danger?

Without a doubt, BYOD creates friction between employers, their employees, contractors and consultants. Security must be balanced with privacy to create a working environment that facilitates tech-led processes without leaving the door wide open to bad actors.

 

So, accepting the premise that BYOD is – for many organisations – an inescapable requirement of operating in the digital, and nomadic economy, how can they design a solution that works for each group of stakeholders?

 

Many organisations have looked to Mobile Device Management (MDM) technologies to separate work and personal activities on employee-owned devices. In effect, however, this gives control of the device to the employer who can exercise the option of wiping the device remotely depending on specific circumstances and levels of risk.

 

While these rights are only supposed to apply to work-related apps and data, there have certainly been instances where personal data has also been deleted – sometimes by accident – leading to wider privacy concerns.

 

The justifiable privacy concerns don’t stop there because most MDM tools give companies access to sensitive employee information, even beyond the virtual personal partition. For instance, by implementing MDM solutions, organisations can often gain access to employees’ browsing history, leading to all kinds of difficult situations, such as if the employer learns that a member of their team is looking for a new job.

 

What’s more, MDM also provides companies with access to location data, allowing them to potentially monitor employees who call in sick or track people working from home. In these circumstances, important privacy boundaries are easily crossed.

 

Generally speaking, organisations will determine if a device is “managed” before allowing access. In practical terms, however, there are multiple ways to manage devices with each approach offering varying levels of effectiveness. For example, while MDM is the most commonly used solution, other options include enterprise mobility management (EMM), mobile application management (MAM) and unified endpoint management (UEM).

 

The point is, there is no ‘one size fits all solution’ and each approach brings its own set of challenges.

 

New solutions for the new normal

The ideal solution for highly connected environments is to implement authentication technology that provides both security and employee privacy. Cryptographically binding identity to each device establishes high trust in the user authenticating, providing proof that it is an authorised user and an authorised device. However, this does not inherently prove whether the device is trustworthy.

 

Organisations also need to ensure that the device meets security posture requirements, such as having the firewall turned on. Guaranteeing that the required security controls are actually implemented establishes trust in the device.

 

It is important to note that device security posture is subject to change, be it through the companies making changes or the employee modifying settings themselves. Because of this, there is a need for continuous checks to ensure that the device remains secure over long periods of time, and not just at inception.

 

Bringing together identity binding to ensure continuous monitoring of the device’s security posture, is key to having a secure identity authentication process. This allows organisations to close security blind spots in unmanaged endpoints without the negative impacts associated with traditional MDM solutions that risk employee privacy.

 

Despite the powerful trends that have impacted the nature of remote work and BYOD in recent years, many organisations find themselves still using device management technologies that were designed for the ‘old normal’.

 

In moving towards a strategy that is more fit for purpose, IT and security teams should focus on balancing security, privacy and employee experience. In doing so, they can deliver a win-win, building secure and agile tech-led teams who are empowered to deliver on business objectives.

 


 

Jasson Casey is Chief Technology Officer at Beyond Identity

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543