SCCyberworld

Friday, July 6, 2012

Fortinet Pan-Asia Survey Reveals ‘First Generation’ BYOD Workers Pose Serious Security Challenges to Corporate IT Systems

Almost half of the Asian respondents would contravene company policy banning the use of personal devices at work or for work purposes

MALAYSIA, July 5, 2012 – Fortinet − a world leader in high-performance network security – has conducted a global survey that reveals the extent of the challenge posed to corporate IT systems by first generation Bring Your Own Device (BYOD) users; people entering the workplace with an expectation to use their own mobile devices. The survey describes the degree to which security is widely given low consideration by Gen-Y employees using their own devices, including the disturbing fact that almost one in two Asian employees would contravene a company’s security policy that forbids them to use their personal devices at work or for work purposes. Overall, the findings underscore the urgency with which enterprises should develop security strategies to successfully secure and manage BYOD activity.

The global survey, conducted in 15 territories* during May/June 2012, asked over 3,800 active employees aged 21 to 31 about their perspectives on BYOD, its impact on their work environment and their approach to personal and corporate IT security. One thousand four hundred and forty-three Asian employees were surveyed.

Strong Dependence on Personal Communications Means BYOD is Here to Stay

Within the demographic of the survey, which represents tomorrow’s management and decision makers, BYOD is confirmed as a mainstream activity. More than three quarters (85%) of Asian respondents already regularly engage in the practice. More importantly, more than half (55%) of the Asian respondents viewed using their device at work as a ‘right’ rather than a ‘privilege’.

From a user perspective, the primary driver of the BYOD practice is that individuals can constantly access their preferred applications, especially social media and private communications. The dependence on personal communications is strong with 59% of Asian respondents admitting they could not go a day without accessing social networks, and 67% unable to last a day without SMS. In fact, Asians' affinity for their mobile devices is significantly higher than the global averages of 35% and 47% for social networks and SMS, respectively.

Lax Consideration of Business Risks Means Workers Contravene Corporate Policy

The first generation of BYOD workers understands the risks posed by BYOD to their organization. Forty-two percent of the Asian survey sampled actually believes potential data loss and exposure to malicious IT threats to be the dominant risk. Yet, worryingly for IT departments, this risk awareness does not prevent those workers from bypassing corporate policies. In fact, close to half of the Asian respondents (47%) admitted they have or would contravene a corporate policy banning the use of personally-owned devices for work purposes.

When asked about policies banning the use of non-approved applications, the figure remains about the same, with 39% of Asian respondents admitting they have or would contravene policy. The risk to organizations from non-approved applications looks set to grow. Indeed, more than three quarters (81%) of Asian respondents confirmed they are interested in Bring Your Own Application (BYOA) − where users create and use their own custom applications at work.

The survey results also hinted at the resistance organizations might face with regards to implementing security on an employee’s device. The majority (54%) of the Asian respondents consider themselves – not the company – to be responsible for the security of the personal devices they use for work purposes. This is substantially more than the number who believes responsibility ultimately rests with their employer (35%).

“The survey clearly reveals the great challenge faced by organizations to reconcile security and BYOD,” said Patrice Perche, senior vice president of International Sales & Support for Fortinet. “While users want and expect to use their own devices for work, mostly for personal convenience, they do not want to hand over responsibility for security on their own devices to the organization. Within such an environment, organizations must regain control of their IT infrastructure by strongly securing both inbound and outbound access to the corporate network and not just implement mobile device management or “MDM”. Organizations cannot rely on a single technology to address the security challenges of BYOD. The most effective network security strategy requires granular control over users and applications, not just devices.”

Fortinet最新亚太区BYOD调查显示,员工自带设备上班为企业IT系统带来严重的安全挑战


近半数受访者表示会违反公司禁止在工作场所使用个人设备或将其用于工作用途的政策

马来西亚, 2012年7月5日 – Fortinet - 一个全球高效能网路安全的领导者– 进行了一项针对新世代 BYOD (自带设备办公)用户的调查。该调查透露新世代 BYOD 用户带给企业IT系统挑战的严重程度;人们在踏入职场时都期待能够使用自己的移动设备。该调查说明了风险意识已被使用个人设备的Y世代员工大幅度地降低;包括每两位亚洲员工里就有一位表示,他们可能或曾经违反公司禁止在工作场所使用个人设备或将其用于工作用途的政策这种不安的事实。总结来说,该研究结果显示企业必须拥有更周全的策略来因应BYOD的趋势。

这项调查于五、六月期间进行,共计访问来自15个地区超过3,800位员工,年龄介于21至31 岁。调查内容包含他们对BYOD的看法,自带设备对工作环境的影响,及他们对个人和企业IT安全的态度等等。其中,亚太区受访者为1,443位。

高度依赖个人通讯奠定BYOD趋势

这些受访对象,代表着未来的管理与决策者,因此BYOD已确定是主流的使用行为。亚太区有超过四分之三(85%)的受访者,已定期在工作中使用个人的科技设备。更重要的是,亚太区超过半数(55%)的受访者认为自带设备上班是他们的权利,而不是特权。

从使用者的角度来看,BYOD主要的驱动力来自于:任何人都可以随时使用他们喜欢的应用程式,特别是社交网站和私人通讯。对这些个人通讯的依赖度,反映不能一天没有社交网站的情况,亚太区受访者高达59%(整体受访者仅35%);不能没有简讯的则更高达67% (整体受访者为47%)。

企业风险欠缺考量 员工可能违反企业政策

新世代的BYOD工作者明白自带设备上班对所属企业可能带来的危害。整体受访者有42%认为有资料遗失的潜在风险,同时可能暴露于恶意软体的威胁。然而,IT部门担心的是,对风险的认知并未让这些工作这正视企业的规定。事实上,亚太区仍有近半数(47%)的受访者承认他们可能或曾经违反公司禁止使用个人设备的规定。

当被问及是否会违反企业规定使用未经允许的应用程式,所得的数据仍然相同。亚太区有39%的受访者表示他们可能或曾经违反规定,而且风险似乎更逐渐升高。事实上,亚太区超过四分之三(81%)的受访者确定他们对自带应用程序办公 (Bring Your Own Application, BYOA) 很感兴趣 – 使用者在上班时可以创造及使用自己专属的应用程序。

这项调查的结果,同时也显示企业在对员工设备进行使用规范与限制时,可能会面临抵抗。大多数的受访者(54%)认为,他们会为自己设备的安全问题负责(而非公司)。认为雇主需要负责的,则仅有35%。

Fortinet国际销售暨支援资深副总裁Patrick Perche指出, “这项调查显示企业在兼顾安全与BYOD趋势时,所需面对的严峻挑战。使用者想要并期待能在工作中使用自己的设备,大多是出于个人便利,他们不希望将自己设备的安全责任交给公司手上。因此企业组织只能从IT构架着手,严峻管控进出企业网路的存取,而非仅是订定行动设备的管理规范(Mobile Device Management, MDM)。BYOD的安全问题,不能只靠单一的技术来解决,最有效率的网路安全策略是精确管理使用者和应用程序,而非只管控设备。”

附注:
此调查报告Fortinet Internet Security Census 2012,有独立公司Vision Critical代表Fortinet,于2012年五、六月间进行。总计访问3,872位大专毕业,年龄介于21至31岁的全职雇员,他们拥有自己的智慧型手机、平板或笔记型电脑。

*参与调查的15个地区,包括卖国、英国、法国、德国、意大利、西班牙、阿联酋、台湾、香港、印度、韩国、中国、新加坡和日本。

No comments: