Monday, May 09, 2011

BYOD Security Paranoia or Necessity

Not too long ago, IT departments faced the challenge of integrating a new consumer device into the corporate infrastructure; this was the iPad which took the fancy of every CXO and techno-affiliate with its cool factor. It did not matter that the tablet was another appendage to do everything that the earlier devices did well enough while ensuring that the information assets of the company stayed protected from nefarious elements. Said the tablet toting executive “I want it; security is for you to go figure”.

The starting point though was the iPhone, which was contained to some extent; the tablet was something different, a wave that swept away all opposition. Developers mushroomed all over creating applications to do everything that mattered and some that did not; IT had no clue what kind of vulnerabilities these created or introduced on the device. Faith in mankind was one of the strategies promoted by many to allow the devices to connect.

In another part of the world, employees went up in arms against the corporate issue compute devices, laptops, desktops, citing their home computers superiority over the standardized and locked devices. Thus the trend started that is now gaining momentum of BYOD, or Bring Your Own Device. It frees up financial resources, support too if the employee fends for herself, no hassles of managing refresh. But what about information on the device ? Confidentiality or sensitivity of information especially when the employee leaves ?

Now extend the same to the mobile, which is lot more like a consumable and gets changed on an average every year, in some cases earlier too. With the space evolving and a multi-polar world of IOS, Android, Symbian, Blackberry and Windows, that too with many versions, the challenges are unique and getting out of hand. In a world where every corporate employee expects all kinds of information on their fingertips (read mobile device), the security framework looks worse than a coarse sieve.

Mobile device security is an evolving subject; vulnerabilities on the mobile are being discovered every day and they are attaining critical proportions with multiple applications vying for attention. In a 24X7 world, the definition of acceptable risk has changed. CIOs are expected to create visibility of the potential compromises and keep the critical information assets secure at all times. The change in the security stance thus creates new challenges and opportunities requiring higher agility to respond. Abstraction of applications and information layers from the device is one of the strategies that helps and many frameworks are emerging in this space. Keep abreast of these developments and experiment before business forces change.

In another couple of years the expectation is that the dependence on the big computer (including laptops) will reduce dramatically; the CXO will carry a few devices (personal, corporate, function specific devices) and all will require management and access to corporate information assets. Start preparing now !

Monday, May 02, 2011

Work in Life in Work

A CEO in a heated debate asks a question to one of the CXOs; the poor phone tapping guy has no clue what the discussion was all about. Confused in his reality, he blurts the words that were top of the mind recall, the interaction he was having with his girlfriend. Everyone on the table smirks, but the CEO accepts whatever nonsense comes out. “Go ahead, mix your worlds” proudly says an advertisement for a mobile service justifying the jumbling up of internet social media world and the workplace.

Ever since the time of portable computers to the current paradigm of everything on the handheld device, be it mobile, tablet or the laptop, work transgressed the boundaries of what was earlier a 9X5 or whatever hours people worked, and the dividing line between what was referred to as work and life has disappeared. It is normal to expect a response to a mail 24X7 and many obliged. In an interconnected world with business being conducted across timezones, this became a way of life. Umpteen cases have reflected the damage this phenomena causes to friends, family and the individual.

As we grew up through school, there was a sense of relief that there will be no homework when we start attending a job in an enterprise. The irony of the situation is that work has expanded to fill all the time beyond the cubicle or cabin reaching the bedroom permeating every nook and corner of life, threatening to follow like the shadow.

So a debate on work life balance is an exercise in intellectual stimulation; reality for most executives is that balance is a utopian state never to be reached with the swing all the way towards work. So if work activities are standard fare, why not allow the life to creep into the workplace ? Why do organizations abhor the thought of employees occasionally checking personal email or posting a few updates on social or micro-blog sites but expect them to work on the presentation or spread sheet while traveling or in their homes ? Security is one of the justifications and then corporate data travels all over the world. Consultants will tout productivity loss due to distractions not recognizing the gains in after office hours.

This is more so now with the IT function with networks, ERP systems, messaging and collaboration, you name it is buzzing with activity through the day and night. Downtime ? What’s that ? And scheduled downtime shifts again and again until the breakpoint is imminent. CIOs struggle to retain teams engaged in keeping these running. Weekends, holidays, vacations belong to an era gone by; the executive is now chained on a WIFI, GPRS or 3G network which cannot be unshackled.

IT and work policies straightjacket the behaviour on premise and often off premises too when using corporate assets like the laptop, smartphone or others. We all accept these as a way of life. Progressive organizations have taken a lenient view of some digression, as of date they are the exception. I believe that productivity will be higher when knowledge workers have the flexibility to escape a few times. Unfortunately there are no empirical data or solutions to validate this. Contradictory claims make such decisions difficult while burnouts continue. Incidences of fatality are getting younger with stress induced by work pressures and lifestyles that may get promotions, but what is a promotion worth when you are dead ?

I don’t know what can help alleviate the issue; unless life is allowed to creep into the work hours.

P.S. I wrote this past the midnight hour on Saturday