{"id":2380,"date":"2014-11-19T13:29:24","date_gmt":"2014-11-19T13:29:24","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=2380"},"modified":"2019-03-08T19:52:26","modified_gmt":"2019-03-09T00:52:26","slug":"blog-personal-data-security-and-the-byod-problem-who-is-truly-at-risk","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2014\/11\/19\/blog-personal-data-security-and-the-byod-problem-who-is-truly-at-risk\/","title":{"rendered":"Blog: Personal Data Security and the \u201cBYOD\u201d Problem: Who is Truly at Risk?"},"content":{"rendered":"<p>By: Jill Smaniotto, Associate Manuscripts Editor<\/p>\n<p>\u201cBring your own device\u201d policies are undeniably on the rise in the realm of business IT. \u00a0According a recent survey, roughly two-fifths of U.S. consumers working for large enterprises use their personally-owned devices\u2014i.e. smartphones, tablets, or desktops\u2014for at least some aspect of their work.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a>\u00a0 Generally, concern surrounding the practice of BYOD has been in regard to the risk to misappropriation of corporate data (i.e., that of the employer\u2019s customers). \u00a0However, a recent case has shed light on another area for concern: the risk to employee data when the employer\/employee relationship sours.<\/p>\n<p>\u201cBring your own device\u201d or \u201cBYOD\u201d is a phrase that has become widely adopted to refer to the practice of employees bringing their own personal computing devices to the workplace for use on the corporate network.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a>\u00a0 In recent years, a shift in IT culture has taken place: the consumerization of IT.<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a>\u00a0 Essentially, there has been a shift from a IT-department-driven culture to one in which consumers are getting the newest, latest technologies ahead of their corporate counterparts.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a>\u00a0 In turn, these consumers are finding their own personal devices are better suited for their work than those provided by employers.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a><\/p>\n<p>This use of personal devices to handle corporate data on secure corporate networks is occurring regardless of whether employees have employer consent to do so.<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a>\u00a0 In fact, a survey conducted by ZDNet indicated that only one-quarter of all enterprise employees surveyed are required by employers to bring their own device, suggesting that the remaining three-quarters were doing so without their employer\u2019s consent.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a>\u00a0 This raises several concerns for data security, as corporate entities are generally not in control of the data accessed via personal devices where employees are using personal devices without the consent of the employer.<\/p>\n<p>Similarly, small and midsized business are embracing the use of BYOD policies at a rapid pace, while failing to address security risks at the same pace.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a>\u00a0 The cost-saving benefits of operating under BYOD policies is also to blame for the lack of security solutions in place in small, low-capital companies.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a><\/p>\n<p>Despite the risks, software companies are beginning to encourage the adoption of BYOD policies by offering services to put in place security solutions.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a>\u00a0 By employing one of these \u201csolutions,\u201d companies can set safeguards for their customers\u2019 data, while allowing the company and the employees to reap the benefits of BYOD. \u00a0For example, IBM emphasizes that BYOD increases employee productivity and satisfaction as employees are more comfortable with their own devices.<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a>\u00a0 Additionally, BYOD programs may result in minimal savings for the company, as it shifts the cost to the employee\/user.<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a><\/p>\n<p>While the focus is primarily on the risk to company\/consumer data, there has been little addressing the risk BYOD poses for the employee\/user\u2019s data. \u00a0Last week, the U.S. District Court for the Southern District of Texas decided a case addressing that very risk.<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a>\u00a0 In <em>Rajaee v. Design Tech Homes, Ltd.<\/em>, plaintiff Saman Rajaee asserted a claim for loss under Computer Fraud and Abuse Act (\u201cCFAA\u201d), 18 U.S.C. \u00a7 1030.<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a>\u00a0 Rajaee was formerly employed by the defendant, Design Tech Homes, in a position that required he have constant access to email in order to address customer questions and concerns.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a>\u00a0 Design Tech did not provide Rajaee with a cell phone or smart device.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a>\u00a0 Instead, Rajaee used his own personal iPhone to conduct his work for Design Tech via a remote access connection to Design Tech\u2019s Microsoft Exchange Server.<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a>\u00a0 Roughly one year after he began working for Design Tech, Rajaee notified Design Tech that he would be resigning in two weeks, and Design Tech immediately terminated Rajaee\u2019s employment. \u00a0Shortly thereafter, Design Tech\u2019s network administrator remotely wiped Rajaee\u2019s iPhone, deleting all work-related and personal data.<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a><\/p>\n<p>Rajaee filed suit against Design Tech under the CFAA, alleging that company\u2019s indiscriminate wiping of his iPhone caused him to lose \u201cmore than 600 business contacts collected during the course of his career, family contacts (many of which were overseas and some related to family business), family photos, business records, irreplaceable business and personal photos and videos and numerous passwords.\u201d<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a><\/p>\n<p>Under the CFAA, \u201closs\u201d is defined as \u201cany reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential damages incurred because of interruption of service.\u201d<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a><\/p>\n<p>Here, the Court held that while Rajaee did assert losses as a result of the defendant\u2019s actions, he did not assert cognizable loss under the CFAA. The Court notes that Rajaee\u2019s assertions of monetary values corresponding to his \u201closses\u201d are not supported by any evidence, and he failed to produce any evidence relating to his response to the data\u2019s deletion or damages suffered as the result of an \u201cinterruption of service.\u201d<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a>\u00a0 Accordingly, the Court granted Design Tech\u2019s motion for summary judgment and dismissed Rajaee\u2019s claim under the CFAA.<a href=\"#_ftn22\" name=\"_ftnref22\">[22]<\/a><\/p>\n<p>The Court\u2019s ruling in <em>Rajaee<\/em> is troubling in that at this stage, it appears as though there is little recourse for employees who suffer due to their employers\u2019 choices to implement BYOD policies. \u00a0Where individuals run the risk of losing personal photographs, messages, and contact information, that risk is further exacerbated by the very nature of such personal data, making it nearly impossible to quantify loss. \u00a0It seems as though participation in BYOD programs by employers is on a track to become relatively low-risk, while all of the risk rests with the employee\/user, who may be completely beholden to the whims of the employer.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> Zack Whittaker, <em>Bring-Your-Own-Device Gains Traction in the U.S. \u2013 Even if Enterprises Aren\u2019t Ready Yet<\/em>, ZDNet (Oct. 21, 2014), http:\/\/www.zdnet.com\/bring-your-own-device-gains-traction-in-the-u-s-even-if-enterprises-arent-ready-yet-7000034925\/.<\/span><\/p>\n<p><span style=\"color: #000000\">[2] Vangie Beal, <em>What is Bring Your Own Device (BYOD)?<\/em>, Webopedia (last visited Nov. 16, 2014), http:\/\/www.webopedia.com\/TERM\/B\/BYOD.html.<\/span><\/p>\n<p><span style=\"color: #000000\">[3] Tony Bradley, <em>Pros and Cons of Bringing Your Own Device to Work<\/em>, PCWorld (Dec. 20, 2011, 10:42 PM), http:\/\/www.pcworld.com\/article\/246760\/pros_and_cons_of_byod_bring_your_own_device_.html.<\/span><\/p>\n<p><span style=\"color: #000000\">\u00a0<a style=\"color: #000000\" href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>Id<\/em>.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>See<\/em> Whittaker, <em>supra<\/em> note 1.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref6\" name=\"\n_ftn6\">[6]<\/a> <em>Id<\/em>.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> <em>Id<\/em>.\u00a0<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> Pedro Hernandez, <em>Small Biz Mobile Security Lags Behind BYOD Adoption<\/em>, SmallBusinessComputing.com (Nov. 13, 2014), http:\/\/www.smallbusinesscomputing.com\/News\/Security\/small-biz-mobile-security-lags-behind-byod-adoption.html.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>Id<\/em>.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>See<\/em> <em>BYOD: Bring Your Own Device: Why and How You Should Adopt BYOD<\/em>, IBM (last visited Nov. 16, 2014), http:\/\/www.ibm.com\/mobilefirst\/us\/en\/bring-your-own-device\/byod.html; <em>BYOD \u2013 Bring Your Own Device<\/em>, MobileIron (last visited Nov. 16, 2014), https:\/\/www.mobileiron.com\/en\/solutions\/byod; <em>BYOD Smart Solution<\/em>, Cisco (last visited Nov. 16, 2014), http:\/\/www.cisco.com\/web\/solutions\/trends\/byod_smart_solution\/index.html.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> IBM, <em>supra<\/em> note 10.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>Id<\/em>.<em>\u00a0<\/em><\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>BYOD-Covered Employee Cannot Prove CFAA Loss After Company Remotely Wiped Phone<\/em>, 19 Electronic Com. &amp; L. Rep. Online (BNA) (Nov. 13, 2014).<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> Rajaee v. Design Tech Homes, Ltd., No. H-13-2517, 2014 U.S. Dist. LEXIS 159180, at *3 (S.D. Tex. Nov. 11, 2014).<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>Id<\/em>. at *1.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>Id<\/em>. at * 1-2.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> <em>Id<\/em>. at *2.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> <em>Id<\/em>. at *3.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>Rajaee<\/em>, 2014 U.S. Dist. LEXIS 159180, at *3.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> <em>Id<\/em>. at *8-9 (citing 18 U.S.C. \u00a7 1030(e)(11)).<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> <em>Id<\/em>. at *9-10.<\/span><\/p>\n<p><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> <em>Id<\/em>. at *11-12.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By: Jill Smaniotto, Associate Manuscripts Editor \u201cBring your own device\u201d policies are undeniably on the rise in the realm of business IT. \u00a0According a recent survey, roughly two-fifths of U.S. consumers working for large enterprises use their personally-owned devices\u2014i.e. smartphones, tablets, or desktops\u2014for at least some aspect of their work.[1]\u00a0 Generally, concern surrounding the practice [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-2380","post","type-post","status-publish","format-standard","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-Co","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2380","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=2380"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2380\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=2380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=2380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=2380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}