A recent survey shows that employees who use personal devices for work are not as careful as they should be with data or even the devices themselves. Security firm Kaspersky said that once sensitive information is out of the hands of an organization, it’s important to keep contingencies in place.

According to the survey, 73 percent of all Internet users age 16 and above use a personal device for work, with 63 percent of that portion using a tablet and 58 percent using a smartphone. However, despite the convenience provided by mobile devices, only 10 percent of workers are “seriously concerned about keeping work information safe should cybercriminals gain access to their device,” according to Kaspersky.

The survey was conducted by Kaspersky Lab in conjunction with B2B International and collected information online from 12,355 people in 26 countries. (Some of the data from China was excluded “due to its high overall weighting and marked difference in attitude and behavior compared to most of the other geographies surveyed.”)

Considering the kind of work information that employees keep on their personal devices, 36 percent keep work files on personal devices, 34 percent have work emails, 18 percent store passwords for work email accounts and 11 percent keep passwords for work VPN and/or intranet access, according to the survey, malicious access to a device could spell disaster for an organization.

But Kaspersky said a bring-your-own-device (BYOD) program still provides value for both workers and organizations, even those that put a premium on confidentiality.

“For example, easy access to corporate communications and applications alongside personal data and activities means that employees can see and manage tasks faster and more effectively,” according to Kaspersky. “However, to keep the business and any proprietary data secure, the integration of BYOD into the IT infrastructure must be implemented responsibly by employers.”

To that end, the security firm provided a list of tenets that companies can follow to make sure their BYOD efforts remain secure. They include looking at BYOD execution as its own special project; the institution of a broad solution that sees to the security of all devices, not just mobile; keeping specialists on staff who understand mobile security, not just run-of-the-mill systems administration; and, most importantly to Kaspersky, “the business needs to develop robust scenarios for how to remove personal devices from the corporate network if they are lost or stolen, or if an employee leaves the company.”

Via: FierceMobile IT