Connect with us

Hi, what are you looking for?

HEADLINES

Study: Gen Y shun corporate BYOD and personal cloud policies

There is a growing appetite of Generation Y (the generation born between the late 1970s and the mid 1990s) employees to contravene corporate policies governing the use of own devices, personal cloud storage accounts and new technologies such as smart watches, Google Glass and connected cars.

There is a growing appetite of Generation Y (the generation born between the late 1970s and the mid 1990s) employees to contravene corporate policies governing the use of own devices, personal cloud storage accounts and new technologies such as smart watches, Google Glass and connected cars, according to research released by Fortinet.

Based on findings from an independent 20-country survey of 3,200 (908 of them in Asia) employees aged 21-32 conducted during October 2013, the research showed a 21% increase in the willingness to break usage rules compared to a similar Fortinet survey conducted last year. The new research also describes the extent to which the Gen-Y have been victims of cybercrime on their own devices, their ‘threat literacy’ and their widespread practice for storing corporate assets on personal cloud accounts.

Strong Trend of Contravention
Despite respondents’ positivity about their employers’ provisions for BYOD policy, with 48% agreeing this ‘empowers’ them, in total, 46% stated they would contravene any policy in place banning the use of personal devices at work or for work purposes. This alarming propensity to ignore measures designed to protect employer and employee alike carries through into other areas of personal IT usage. 43% of Asian respondents using their own personal cloud storage (e.g. DropBox) accounts for work purposes said they would break any rules brought in to stop them. On the subject of emerging technologies such as Google Glass and smart watches, more than half (55%) would contravene any policy brought in to curb the use of these at work.

Wearable Technology Set to Enter the Workplace
When asked how long it would take for wearable technologies such as smart watches and Google Glass to become widespread at work or for work purposes, 20% said ‘immediately’ and a further 39% when costs come down. Only 3% of the Asian respondents disagreed that the technologies would become widespread.

Widespread Use of Personal Cloud Accounts for Sensitive Corporate Data
Ninety percent of the sample has a personal account for at least one cloud storage service with DropBox accounting for 32% of the total sample. Seventy-two percent of personal account holders have used their accounts for work purposes.  Fifteen percent of this group admits to storing work passwords using these accounts, 19% financial information, 25% critical private documents like contracts/business plans, while more than a third (39%) store customer data.

Advertisement. Scroll to continue reading.

Almost one third (32%) of the Asian cloud storage users sampled stated they fully trust the cloud for storing their personal data, with only 6% citing aversion through lack of trust.

Threat Literacy Required as Survey Reveals Attacks Really do Happen
When asked about devices ever being compromised and the resulting impact, over 56% of responses indicated an attack on personally owned PCs or laptops, with around half of these impacting on productivity and/or loss of personal and/or corporate data.

Attacks were far less frequent on smartphones (27%), despite the sample reporting a higher level of ownership of smartphones than for laptops and PCs. The same  percentage was observed for tablets (27%), which were less commonly owned than laptops and PCs.

Among one of the worrying findings of the research, 12% of respondents said they would not tell their employer if a personal device they used for work purposes became compromised.

The research exercise examined ‘literacy levels’ for different types of security threat, with the results revealing two opposing extremes of ignorance  and enlightenment (separated by an average of 33% with minimal awareness. Questioned on specific threats like APTs, DDoS, Botnets and Pharming, more than half (61%) appear completely uneducated on these types of threats. This represents an opportunity for IT departments to provide further education around the threat landscape and its impact.

Advertisement. Scroll to continue reading.

The survey also hinted at a direct correlation between BYOD usage and threat literacy, i.e. the more frequent the BYOD habit, the better a respondent’s understanding of threats. This represents a positive finding for organizations when considering if/when to bring policies in alongside training on the risks.

“This year’s research reveals the issues faced by organizations when attempting to enforce policies around BYOD, cloud application usage and soon the adoption of new connected technologies,” said Jeff Castillo, Fortinet’s country manager for the Philippines. “The study highlights the greater challenge IT managers face when it comes to knowing where corporate data resides and how it is being accessed. There is now more than ever a requirement for security intelligence to be implemented at the network level in order to enable control of user activity based on devices, applications being used and locations.”

“It’s worrying to see policy contravention so high and continuing to rise, as well as the high instances of Gen-Y users being victims of cybercrime,” continued Castillo. “On the positive side, however, 88% of the Asian respondents accept that they have an obligation to understand the security risks posed by using their own devices. Educating employees on the threat landscape and its possible impact is another key aspect for ensuring an organization’s IT security.”

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

To help organizations address the challenges they face as a result of the cyber skills gap, the award-winning Fortinet Training Institute provides one of the largest...

HEADLINES

One of Beyond’s commitment in the Philippines is to develop its tech talent. The company announced it has plans to invest in upskilling Filipino...

HEADLINES

By combining Saviynt’s Identity Governance & Administration (IGA), Privileged Access Management (PAM) solutions, and Identity Security Posture Management (ISPM), and Exclusive Networks’ extensive regional footprint, organisations will gain faster access...

HEADLINES

As cyber threats become more sophisticated, cloud and application security can no longer be treated as a compliance exercise. It must be seen as...

HEADLINES

Designed to secure the full AI stack—from data center infrastructure to applications and large language models (LLMs)—the solution delivers advanced AI threat defense with...

HEADLINES

This initiative is particularly critical as organizations in the Philippines face an increasing shortage of skilled cybersecurity professionals.

HEADLINES

The results reveal a threat landscape that is not only evolving in complexity but also shifting toward gaps in visibility, governance, and infrastructure, posing...

HEADLINES

"As digital transformation accelerates, cybersecurity is more critical than ever to safeguarding businesses, the global economy, and society at large,” said Michael Xie, Founder,...

Advertisement