New security threat at work: Bring-your-own-network
Education and contracts with employees can help curb security risks
Computerworld - Even as IT pros wrestle with the bring-your-own-device (BYOD) trend, corporate security is being further complicated by another emerging trend: bring your own network (BYON).
BYON is a by-product of increasingly common technology that allows users to create their own mobile networks, usually through mobile wireless hotspots. Security professionals say BYON requires a new approach to security because some internal networks may now be as insecure as consumer devices.
Jim Kunick, an attorney with the Chicago law firm Much Shelist, said BYON represents a more dangerous threat to data security than employees who bring their own smartphones or tablets into the office. "The network thing blows this up completely, because it takes the data out of the network the company protects," he said. "There's no way to ensure the security of that data. People are running corporate apps and processing corporate and client data using networks that may or may not be secure.
"I mean, no one is sure the Boingo network is secure," he said.
Kunick, an intellectual property attorney, said BYON is cropping up in start-ups, particularly at software development firms and entities that rely on cloud services.
"[BYON] allows people to run applications in three different cloud-based environments at one time because they're on their own network, they're on a network that they contracted with and they're on the corporate network," he said.
Initially, BYON should be seen as a policy issue where a company sets rules that ban employees from running private networks. Employees who use hotspots also have contracts with network service providers, he said, and they need to understand how data on that network may be used or further disclosed.
"In any major corporation, I'd assume they control [access] by means of a firewall. And, I have a medical device client [corporation] that encrypts all of their corporate data so you can't even bring your own device into the company," Kunick said. "You have to use a laptop that they provide. So it's without question that you can't bring your own network in."
Ted Schadler, a vice president and principal analyst at Forrester Research, said there are even some companies that ask wireless service providers to move their towers.
"I'm aware of certain companies, such as large call centers, asking AT&T and Verizon to move their cell towers from around their buildings because they're so concerned about unsupervised workers," he said. "It just exacerbates the challenges."
Schadler, who spoke at the Consumerization of IT in the Enterprise (CITE) Conference in New York City this week, said that in terms of physical security, there is little companies can do to avert data being shared over hotspot network links.
Steve Damadeo, IT Operations Manager Festo Corp., a producer of pneumatic and electric drive technology, said his first approach with employees who want to use personal technology at work is to educate them. "We try to spend a lot of time talking to employees about why it's important to make sure when you're inside our environment that you're using corporate secure resources," he said.
Festo hasn't used wireless jamming or blocking technology because it is trying to keep wireless communications as open as possible.
Like many enterprises, Festo has multiple secure wireless networks, three of which its employees can access. The company's primary wireless network is used for access to internal systems and data via authorized mobile devices; users of it are managed via custom-built mobile device management software.
A second network is offered to employees who want connectivity to the World Wide Web via their own mobile devices; that one allows access through a VPN. "We've not enabled full BYOD within the company, so at this point we're able to provide VPN capabilities to them," Damadeo said.
The third wireless network is for guests, and it is made available on a rotating encryption/key basis for visitors.
One other method of controlling how employees use wireless communications is to have them sign contracts, so that they understand they, too, are responsible for any lost data, Schadler said.
They're "basically requiring employees sign their life away and indemnify the company against damages, and that makes them think twice," he said.
Lucas Mearian covers storage, disaster recovery and business continuity, financial services infrastructure and health care IT for Computerworld. Follow Lucas on Twitter at
@lucasmearian or subscribe to Lucas's RSS feed
. His e-mail address is lmearian@computerworld.com.
See more by Lucas Mearian on Computerworld.com.
Consumerization of IT
- IT departments won't exist in five years
- The time is right for an 'IT petting zoo'
- The next corporate revolution will be power to the peons
- Dual persona smartphones non grata at Starz
- Google Glass breaks into business
- BYOD, or else. Companies will soon require that workers use their own smartphone on the job
- 'Dual personality' could morph into Jekyll and Hyde for Samsung and BlackBerry
- Muted excitement for latest Toshiba Android tablet
- Muted excitement for latest Toshiba Android tablet
- BYOD gets attention at Mobile World Congress
Read more about Consumerization of IT in Computerworld's Consumerization of IT Topic Center.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Integrated Systems and Streamlined Practices Propel New, Responsive IT Organizations This paper characterizes a significant IT transformation that's underway for firms just beginning the journey or those already in the middle of the...
- Expert Integrated Systems: A Next Generation Computing Platform This white paper discusses an important sea change happening in IT: the development of expert integrated systems. Learn More.
- Businesses are ready for a new approach to IT The IBM PureSystems family is comprised of platform systems and infrastructure systems that include built-in "patterns of expertise" to address complex business and...
- Forrester Report: IT Leaders Must Regain Trust and Become a Strategic Partner in Commerce Read this report to get the results of a survey of nearly 400 business leaders in commerce-related roles and learn about the new...
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Williams & Fudge on Transforming IT with EMC Watch Williams & Fudge Data Center Director Phillip Reynolds discuss why this accounts receivable management firm turned to EMC. All Consumerization of IT White Papers | Webcasts
