CIO Dashboard

BYOD and Your CEO

by Chris Curran on May 10, 2012 [email] [twitter]

Post image for BYOD and Your CEO

What’s small, shiny and keeps CIOs up at night? The CEO’s personal devices.

CEOs are like every other employee. They love tablets, smart phones and apps. The glaring difference is that the CEO’s personal devices put the company at much greater risk than the gadgets of virtually all other employees combined. CIOs must  include chief executives in conversations as they grapple with putting BYOD security policies and procedures in place.

Many CEOs criss-cross the globe carrying the company’s most sensitive information—trade secrets, delicate details about employees, financial projections, etc—in the palms of their hands. At any given moment, the CEO could lose her data-laden device on a plane or in a coffee shop. Or possibly, a hacker on a mission to harm the company intentionally swipes the device’s information when the CEO isn’t looking.

If those risks weren’t enough, there’s also the potential for the CEO to lose her precious personal files by forgetting a password or unintentionally mishandling information.

Take what happened to the CEO of an email management provider recently. He was vacationing with his family when his five-year-old tried unsuccessfully to access Dad’s smartphone five times. The firm’s Mobile Device Management (MDM) system kicked in and wiped the CEO’s vacation pictures. Luckily for the CIO the CEO couldn’t blame anyone but himself since he was instrumental in setting the company’s BYOD usage policy.

In this instance, the CEO-sanctioned system erased pictures in the event the device was compromised because employees often take pictures of their whiteboard brainstorms. This is an example of where a business decision to guard trade secrets had a personal impact on the CEO that he probably didn’t anticipate.

These devices are extremely risky to the company and personal to employees. So it’s crucial that CIOs have meaningful conversations with employees, including the CEO, about the responsibilities of managing their own personal devices and the ramifications of BYOD usage and security policies and procedures. (see Building a BYOD Ready Infrastructure) CEOs often get special privileges, but CEOs certainly shouldn’t be allowed to muscle exceptions to BYOD rules or miss the opportunity to have a say in shaping the company’s security strategy.

Scenario planning using real-life possibilities and demos helps IT paint a vivid picture for senior leadership and employees about the risks of BYOD. My colleague, Jim Guinn, stresses the importance of employee education to protect the business and the personal interests of employees in his new cyber security video.

You have to educate people on what they are doing and what their exposures are. Not only to the corporation: You have to teach them what the risks are to them personally. It’s all about training and education and tying them to real-world issues and incidents.

Mike Phillips, CISO, CenterPoint Energy, agrees: “People get very upset if you change the functionality of their device. And the reality of it is if you are going to put something on it like a secure container or encrypt the email you might have to change the email client and the minute they connect with you you’ve changed it.”

You can view the entire conversation between Jim and Mike here.

The last thing a CIO wants is to upset or frustrate the CEO. Or worse, fail to protect the organization from the obvious risks of BYOD. Make sure the CEO understands exactly when IT will be accessing his device, for what purpose, and what could happen as a result. Make sure she is backing up her files and knows what will transpire if the device is lost or stolen. Giving the CEO a heads up and ongoing guidance will avoid heartbreak and headache.

Have you had the “BYOD talk” with your CEO? Share your best practices and concerns below.

Image shared by allensima

Be the first to comment

Is Social Media Leadership Critical for a CIO?

May 3, 2012
Thumbnail image for Is Social Media Leadership Critical for a CIO?

Do CIOs need to engage and evangelize public social media networks to effectively lead their organizations in social media initiatives? Or is facilitating connection and collaboration among employees and clients enough? Who is most responsible for cultivating a social corporate culture? These are the questions I asked myself after reading the news that only about 10 percent of CIOs in the Fortune 250 are using public social networks. According to harmon.ie’s research, a paltry 4% ...

13 comments Read more →

The Value of Visualization

April 24, 2012
Thumbnail image for The Value of Visualization

Recently I was discussing a history project with my son.  He was writing a paper about the inconsistencies in access to clean water in all parts of the world and their causes.  In researching the history of urban water access, he came across the story of the outbreak of cholera in the mid-1800′s in London and the impact it had on modern medicine. A young doctor, John Snow, proposed that cholera was carried in contaminated food ...

1 comment Read more →

Social Collaboration vs. Quiet Contemplation

April 12, 2012
Thumbnail image for Social Collaboration vs. Quiet Contemplation

Roughly 20-30% of the population is acknowledged introverts and it’s no secret that IT has its fair share. One of the more famous is Steve Wozniak who dreamt up the first Apple computer in solitude. It’s highly unlikely that this quantum leap of imagination that changed the world would have bubbled to the surface in a boisterous brainstorming session. That’s because introverts like Wozniak excel in low-key environments and crave quiet to create, as Susan ...

1 comment Read more →

Whiteboard Culture: An Organizational Competitive Advantage?

April 3, 2012
Thumbnail image for Whiteboard Culture: An Organizational Competitive Advantage?

Guest post by Sachal Lakhavani Does your organization have a whiteboard culture?  When faced with complex problems or collaborating with people with different perspectives, do the people in your organization draw to communicate in a dynamic and visual way, or do they rely solely on verbal explanations and static Powerpoint slides? I recently attended a panel at SXSW that was instructively entitled “Shut up and Draw.” The panelists, Dan Roam, Sunni Brown and Jessica Hagy, ...

5 comments Read more →

Building a BYOD Ready Infrastructure

March 20, 2012
Thumbnail image for Building a BYOD Ready Infrastructure

What can the process of protecting a prized baseball card collection teach us about BYOD security? Let me explain. A few years ago, my sons and I got hooked regularly visiting a sports collectables store. These days, collecting sports cards is not just about completing team sets or collecting your favorite players.  Now, its about trying to find the rarest cards in perfect condition – sometimes these cards even have a piece of a jersey ...

0 comments Read more →

How the CIO Can Establish a BYOD Usage Policy

March 8, 2012
Thumbnail image for How the CIO Can Establish a BYOD Usage Policy

If you’re grappling with putting policies and procedures in place to manage the consumer-driven transition to a bring-your-own-device workplace (BYOD), don’t worry. You’re not alone. Only 43 percent of respondents to PwC’s 2012 Global Information Security Survey said that their organization has implemented a security strategy for use of employee-owned devices. It’s not surprising that companies are struggling. Developing a BYOD strategy can stir up a hornet’s nest of issues for the CIO at the nexus ...

2 comments Read more →

Digital Razorblades: CIO Insight from App Stores

March 6, 2012
Thumbnail image for Digital Razorblades: CIO Insight from App Stores

  Razorblades. This was the thought I had while browsing the “top grossing” apps in the Apple AppStore today.  The top 10 grossing apps are “free” and the same is true in the Android store. How could this be?  Well, it turns out that these apps ARE free, but make their revenue by selling add-ons, upgrades, tokens, in-game currency, game equipment, etc.  This is like the razor vs blades business model, in which the razor ...

0 comments Read more →

We Need More Demos

March 1, 2012
Thumbnail image for We Need More Demos

TED is an unbelievable place to step back from the day-to-day and dream big.  As I described in my first TED 2012 post this week, this place puts me in a great frame of mind to find meaning in just about any subject or point of view.  Speakers all throughout the week have helped me to crystalize one thing in my mind that we as IT leaders in our organizations can and should do better.  ...

1 comment Read more →

3 CIO Questions from TED 2012

February 29, 2012
Thumbnail image for 3 CIO Questions from TED 2012

Where do you get inspiration from?  How do you challenge yourself, your ideas, perspectives and plans?  An old friend and mentor used to tell me that it’s crucial to commit to learn about a few disciplines that are seemingly unrelated to your own.  The TED experience is one way to immerse yourself in many worlds – some somewhat comfortable and others wholly new.  I’ve been fortunate to attend TED for the last 2 years and ...

2 comments Read more →