Legal and technical BYOD pitfalls highlighted at RSA security conference

Companies that don't protect themselves through policies place themselves at risk

Allowing employees to bring their own devices to work is causing new challenges, including what happens when a device needs to be wiped or employees want to sell their smartphone or tablet.

Mobile security and BYOD (bring your own device) are main themes at the European edition of RSA's security conference, which takes place this week in London.

Letting employees use their own smartphones or tablets for work represents a loss of control for IT departments. Also, if personal data isn't handled correctly, the company may end up being sued, said Cesare Garlati, vice president of mobile security at Trend Micro and the moderator of a conference session called "The Dark Side of BYOD."

"If companies don't protect themselves through policies they are really exposed," said Garlati.

For example, using Microsoft's ActiveSync technology to remotely wipe a device becomes more complicated because when data is deleted from the device everything is removed, including the user's personal photos, videos, songs and so on, according to Garlati.

"The question is who is responsible for that," said Garlati.

So, initiating a remote wipe when a user has entered the wrong password too many times, when an employee has been let go, or simply by mistake could have serious repercussions.

There are both technical and legal ways for an organization to address this.

More advanced mobile device management products allow enterprises to create containers that separate personal and enterprise information and can delete just the latter, according to Garlati.

However, for that to work, information has to be tagged correctly or stored in the right place and some enterprises feel they can't trust that is the case, according to Leif-Olof Wallin, research vice president at Gartner.

"For example, on an iPad there is a good chance that the employee has stored notes from a sensitive meeting outside the container. So to be on the safe side, they wipe the whole device," said Wallin in a separate interview.

The solution is to put in place an acceptable-use policy that clearly states employees can connect to the enterprise network, but if something goes wrong, the IT department can initiate a remote wipe that also deletes personal information, according to Garlati. The rules of the policy then have to be reiterated on a regular basis, he said.

Part of that is also telling users to back up personal data if they don't want to lose it, Wallin said.

People and their devices can also be affected if their employer gets involved in litigation.

"The other party can go to the judge and say that to preserve and discover evidence, I require all the devices involved in the litigation to be seized and sent to a forensics expert for analysis," said Garlati.

The user loses their device and will again want some form of compensation, according to Garlati.

The technical solution here is to use desktop virtualization, which means all of the corporate information is stored on servers. Doing the same with at least tablets would be good, but the technology isn't there yet, Garlati said.

When handing over information relevant to a legal case is enough, the IT department needs to have a process in place for gathering the data from PCs, smartphones and tablets, according to Wallin. Allowing the IT department to do that also needs to be part of the policy workers agree to, he said.

Enterprises also have to plan for what happens when a user wants to upgrade to a new device and get rid of the old one. Doing that is mandatory for any BYOD program, according to Wallin.

One way to ensure corporate data doesn't end up in the wrong hands is for enterprises to outright buy old devices. Another alternative is to discount the cost of a new smartphone, according to Garlati.

"My company actually gives me a discount on the AT&T price of a device if I buy through them, but there is a catch because I have to return the old device," said Garlati.

Purchasing phones from employees isn't a very feasible option, since enterprises are adopting BYOD to get away from buying hardware, according to Wallin. His alternative is to rely on the mobile device management solution or getting users to wipe their phone.

"Users have to be told that if they are let go, retire, leave or buy a new device, all corporate information has to be deleted, including potential physical or cloud-based back-ups ... Some organizations want to verify the information has been deleted, while others check a sample or trust the employee," said Wallin.

Send news tips and comments to

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Mikael Ricknäs

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?