When Work from Home Becomes the Norm, BYOD Takes On New Complexity and Risk
Shortfalls in strong policy and information governance isn't exactly a new issue, but the current situation has exacerbated corporate risk exposure significantly. Here's a list of key areas to consider that may help focus efforts.
May 20, 2020 at 07:00 AM
6 minute read
An estimated 58 percent or more of American knowledge workers are now working remotely. This number is up by more than 30 percent from pre COVID-19 averages, and dwarfs previous figures that reported roughly seven percent of the U.S.'s 140 million civilian employees worked from home. To many, this mass exodus from the conventional workplace has been a welcome shift in employer expectations and telework policies. For organizations that don't typically allow remote work, however, enabling it at a moment's notice has raised serious logistical, compliance and security challenges.
Many companies in technology, insurance, professional services and certain other industries already have a large portion of employees who work from home at least some of the time. These were relatively well prepared for the current circumstances. Others have been caught completely off guard, unprepared and without the proper equipment for tens, hundreds or thousands of employees, or infrastructure to enable them to access company systems securely from dispersed locations.
From a governance standpoint, policies that dictate the rules for working from home—including how employees interact with company data, what devices and applications are approved and what additional safety measures they need to take—are also lacking. The result is a significantly increased number in employees using personal devices for work, and the rise of new and unexpected areas of legal, security, compliance and privacy risk.
Shortfalls in strong policy and information governance isn't exactly a new issue. But the current situation has exacerbated corporate risk exposure significantly. For teams in reactive mode, working to put out fires and close the gaps in company exposure, we've compiled a list of key areas to consider that may help focus efforts. These include:
VPN use: An April CNET article reported, "Demand for VPNs increased by 44 percent over the second half of March and remains 22 percent higher than pre-pandemic levels." VPNs help employees securely access systems, but they also come with inherent challenges. For one, employees may not know how to use a VPN, or understand the proper procedures for connecting to it from their personal devices. Increased usage is also straining company VPNs and internet service providers, making it difficult or impossible in some cases for the entire remote workforce to access the network. This may force employees to use their home wi-fi or unsecured hot spots, which can lead to exposure. More, VPNs have a history of being exploited by malicious actors, and some providers have been flagged for weak security. It's critical for organizations to properly vet their VPN providers and get a handle on the scope of issues surrounding VPN use to ensure the most secure connection possible for remote employees.
Information security awareness: Even employees who have been adequately trained on information security best practices may not think of security in the context of working in their homes. More than ever before, sensitive information and communications are dispersed across personal devices and residences. Employees will be taking phone calls and printing confidential documents at home; and saving privileged and private information to their personal computers and mobile devices. Awareness campaigns and best practice refreshers can go a long way in preventing private documents from being disposed of improperly or left out for others to see.
Personal networks and accounts: The merging of work and home environments will inevitably lead to more blending of company information in personal email and messaging accounts, and across smaller, less secure telecom networks. When employees use personal accounts to view and share company documents containing personally identifiable information and IP, tracking and managing that data can become very messy.
Organizations subject to data privacy laws like GDPR and the California Consumer Privacy Act may run into issues with data subject access requests and other privacy compliance matters if sensitive data resides in unknown devices and accounts. When business as usual resumes, legal, compliance and IT teams will need to remediate employee devices, to ensure private information does not remain in unauthorized or unknown locations.
Policy updates: Going forward, organizations need to revisit the BYOD policies they were developing five years ago. It's likely that we'll see a second wave of coronavirus related shutdowns later this year, and organizations need to be better prepared in round two. Ironing out what rights the company has to personal devices used for work, and processes for recalling data stored on those devices will be critical in reducing risk for future privacy, regulatory and e-discovery matters.
Process improvements: In the aftermath of this crisis, organizations can seize an opportunity to examine their weaknesses and bolster processes around them. This may include creating a centralized location to store documents, file sharing systems and policies, tracking mechanisms to monitor where data is being shared or downloaded, usage parameters for collaboration and chat applications and procedures for remediating sensitive data from remote devices.
Educate and train: The best way to ensure private and sensitive information doesn't perpetuate on personal devices is to give employees clear guidance on what they need to do when they return to the workplace. Teach employees how to find and delete sensitive information from their devices, or how to transfer it back to the company. Make sure they are equipped with the knowledge and techniques they need to help reduce risk and work from home in a secure and compliant manner.
Ultimately, companies need to be more proactive about the future of work. We're likely to see a significant increase in the number of people who continue working remotely even after the pandemic is over. Organizations need to be thinking about this shift and begin taking steps to adapt to it. Collaboration across stakeholders in legal, compliance, IT and security will be essential to meet new challenges in remote work situations, and balance employee efficiency with strong data protection.
Deana Uhl is a managing director at FTI Consulting, advising corporate clients, with a focus on designing, implementing and enabling change management for information governance, data privacy, data security and e-discovery programs.
Vanesa Hercules is a director at FTI Consulting where she helps clients operationalize information governance initiatives, streamline litigation hold and eDiscovery processes, remediate legacy data, manage global data privacy risk, and develop cross-functional workflows with sustainable business processes.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 15th Circuit Considers Challenge to Louisiana's Ten Commandments Law
- 2Crocs Accused of Padding Revenue With Channel-Stuffing HEYDUDE Shoes
- 3E-discovery Practitioners Are Racing to Adapt to Social Media’s Evolving Landscape
- 4The Law Firm Disrupted: For Office Policies, Big Law Has Its Ear to the Market, Not to Trump
- 5FTC Finalizes Child Online Privacy Rule Updates, But Ferguson Eyes Further Changes
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250