Security

BYOD Security: Risks, Policies, and Device Management Best Practices

The growing BYOD trend in workplaces offers benefits like employee satisfaction and hardware cost savings but poses significant security challenges, necessitating clear IT policies, effective monitoring, and robust security software.

Jacob Haug

Wednesday, December 30, 2020

BYOD Security: Risks, Policies, and Device Management Best Practices

A growing trend in IT is employees bringing their own devices for use on the company network. Employees may prefer their personal laptops or want to use a single cell phone for work and personal tasks. When employees own the devices they’re using, they’re often happier. However, securing many types, manufacturers, and operating systems of employee devices can be a challenge for IT teams.

Supporting bring-your-own-device (BYOD) introduces significant BYOD security concerns, too. With employees adding new devices regularly, IT teams need to ensure that data policies and best practices are followed across those personal devices. In this article, we’ll explore common bring your own device BYOD security risks and mitigating strategies that can help organizations support employee-owned devices without sacrificing visibility or security.

Officially Supported?

One of the first questions you’ll want to answer is: “Do we officially support BYOD at our organization?”

It’s much simpler not to support BYOD. If you choose to go this route, your organization will supply devices to every employee. This usually means buying laptops for everyone, but if an employee needs a mobile phone or tablet to do their job, you should supply that as well. Because the company owns all the devices in use, it’s much easier to keep inventory and enforce security policies. Of course, buying hardware for everyone is more expensive than BYOD, but the company owns those assets.

Nevertheless, employees are often happier when they can bring their own devices. Additionally, the company saves money on hardware costs. The tradeoff is that IT has to support all kinds of devices, and creating policies or choosing software for all your devices is much trickier.

In either case, whether you officially support BYOD or not, you’re likely to have employee-owned devices entering the corporate network at some point. If they’re undocumented devices, they become part of your company’s “shadow IT,” infrastructure that exists inside the company but isn’t explicitly supported or tracked by IT.

BYOD Policies: Laying the Ground Rules

Supporting BYOD means putting some infrastructure in place. None is more important than creating good policies and documentation on how to add a personal device to the company network.

These policies should cover:

  1. Types of approved devices, such as laptops, phones, and tablets
  2. Approved manufacturers and operating systems, including versions
  3. Password requirements for device access
  4. Data security and file storage policies
  5. Levels of support given to personal devices from IT
  6. Monitoring and security software required on personal devices

Within these policies, go into detail about the exact vendors and service providers your company uses. You may even go so far as to restrict or ban certain software and vendors in favor of the officially supported provider.

These controls help address some of the most common BYOD security concerns, including outdated operating systems, unapproved applications, insufficient access controls, and devices that IT cannot adequately monitor.

Bring Your Own Device Management Software

As the number of personal endpoints grows, manually keeping track of every device quickly becomes impractical. Bring your own device management software can give IT teams greater visibility into which endpoints are accessing company resources and whether those devices meet organizational requirements.

Adding management and security software allows you to keep an inventory of connected devices and the software they have installed. Additionally, this inventory allows you to apply appropriate access and security policies on a per-device basis.

The best remote monitoring and management software will allow your IT teams to provide support to personal devices across supported operating systems. As the organization grows, this access to each device becomes invaluable. Monitoring software also allows IT teams to check security updates and determine whether installed software is current and has the latest security fixes.

For MSPs, device visibility becomes particularly important as the number of endpoints and customers grows. If you’re starting your own MSP, establishing standardized policies for endpoint monitoring, patching, access, and BYOD management early can make it easier to support a growing customer base consistently.

Anti-malware scanning software should also be a standard part of all BYOD installations for security purposes. Your company’s data is only as secure as the weakest link, so a baseline of security across all company devices is critical.

Provisioning & Deprovisioning Personal Devices

With policies in place, you’re now ready to create checklists and procedures that enforce those policies any time someone wants to add a new device to the company network.

Ideally, there should be safeguards in place that prevent access to company data until all necessary onboarding BYOD steps are completed. These could include VPNs, requiring MFA, checking that the monitoring agent is installed, and verifying that the endpoint meets your minimum security requirements.

When employees leave the company, internal data shouldn’t remain on personal devices. Therefore, a reverse version of the checklist for deprovisioning company data from personal devices is also essential. Ultimately, deprovisioning personal devices is one of the most difficult parts of a BYOD policy to enforce, so having a clear process makes a huge difference.

Managing BYOD Security Risks

The biggest challenge with BYOD is that IT does not completely control the hardware employees use. A personal endpoint may be outdated, misconfigured, infected with malware, or running unsupported software while still accessing company resources.

Organizations can reduce these risks by establishing minimum security requirements before allowing devices to connect. These can include MFA, encryption, current operating system versions, anti-malware protection, automatic patching, approved applications, and endpoint monitoring.

IT teams should also have a process for identifying devices that fall out of compliance. A device that was secure when initially provisioned may become vulnerable later because of missed patches, disabled security controls, or outdated applications.

This combination of policy, monitoring, access control, and regular patching helps address BYOD security concerns without requiring the organization to take complete ownership of employees’ devices.

BYOD Security & Data Privacy

Workers are often happier when they can use their own devices. It also saves on hardware costs for IT infrastructure. However, BYOD creates security and privacy challenges because company and personal information may coexist on the same endpoint.

Organizations should clearly document what IT can monitor, what company data can be remotely managed or removed, and what remains private to the employee. These boundaries should be established before a personal device is enrolled.

With clear policies in place, you can address most of these security concerns so you can reap the benefits of BYOD in an increasingly distributed workplace.

Frequently Asked Questions About BYOD Security

What are the biggest BYOD security risks?

Common risks include outdated operating systems, unpatched applications, malware, weak authentication, unauthorized applications, lost or stolen devices, and company information remaining on an endpoint after an employee leaves. Establishing minimum security standards and continuously monitoring enrolled endpoints can reduce these risks.

How can IT tell if a personal Windows device needs attention?

Operating system errors and update warnings can provide early indications that an endpoint needs investigation. For example, a user reporting “your device ran into a problem” may be experiencing a Windows system failure that IT should investigate before allowing continued access to sensitive resources.

Similarly, a Windows Update warning that “your device is missing important security and quality fixes” can indicate that an endpoint has not received required updates. For a BYOD environment, unresolved update issues can become a security concern if the device continues accessing company resources.

What should bring your own device management software do?

A BYOD management solution should help IT maintain endpoint visibility, enforce security requirements, monitor device health, track software and operating system status, and support provisioning and deprovisioning workflows. Depending on the organization’s requirements, it may also be combined with RMM, endpoint security, identity, and access-management tools.

How should organizations balance BYOD security and employee privacy?

Organizations should define exactly what IT can monitor or manage before an employee enrolls a personal device. Policies should distinguish between corporate data and an employee’s personal information and explain what happens to company data when the device is deprovisioned.

Level: Simplify IT Management

At Level, we understand the modern challenges faced by IT professionals. That's why we've crafted a robust, browser-based Remote Monitoring and Management (RMM) platform that's as flexible as it is secure. Whether your team operates on Windows, Mac, or Linux, Level equips you with the tools to manage, monitor, and control your company's devices seamlessly from anywhere.

Ready to revolutionize how your IT team works? Experience the power of managing a thousand devices as effortlessly as one. Start with Level today—sign up for a free trial or book a demo to see Level in action.