Tech Insight : Personal Activities … On Work Laptops (Part 2)

In this second part article, where we review the issues around employees engaging in personal activities on company-issued devices, we look deeper into the legal and compliance implications and provide real-world case studies of security breaches. We also examine how businesses can protect themselves against these growing threats.

Last Week 

In the previous article, with the help of an ESET study, we explored the risks of employees using their work laptops for personal activities and the potential consequences for both the employee and the business. Continuing along those lines, legal and compliance issues are the next area for serious consideration for businesses whose laptops may be used by employees for risky purposes.

Legal and Compliance Implications 

The legal implications of employees engaging in risky behaviour on work laptops can be severe for businesses, particularly in industries where sensitive data is routinely handled. For instance, companies operating in sectors such as finance or healthcare must comply with stringent data protection regulations, such as the UK General Data Protection Regulation (GDPR). Under GDPR, businesses are responsible for protecting personal data, and failure to do so can result in penalties of up to £17.5 million or 4 per cent of global turnover, whichever is higher.

Also, businesses can face legal liability if company devices are used for illegal activities. This includes accessing pirated content, illegal gambling, or visiting the dark web. If such activities are traced back to a business’s network or devices, it could suffer reputational damage or face legal action. This is particularly concerning for companies with distributed or remote workforces, where personal and professional activities on work devices are harder to monitor.

In highly regulated industries, such as finance, companies must also ensure compliance with sector-specific guidelines. For example, the Financial Conduct Authority (FCA) in the UK has strict rules governing data protection, and failure to meet these standards can lead to fines and sanctions. Recent cases have shown that even seemingly innocuous personal activities on work devices can have far-reaching consequences.

Examples of High-Profile Security Breaches Involving Work Laptops 

Several high-profile security breaches in recent years have highlighted the risks associated with employee misuse of work laptops. For example:

– Back in 2016, Tesco Bank faced a £16.4 million fine from the Financial Conduct Authority after cybercriminals exploited weaknesses in the bank’s systems, partly due to poor endpoint security on employee devices. This breach affected thousands of customers and highlighted the importance of robust security protocols on corporate devices.

– In 2018, British Airways suffered a £20 million fine after a data breach exposed the personal data of over 400,000 customers. The attack was traced back to weak endpoint security, underscoring the risks of inadequate protection on work devices.

– In 2020, Travelex, a global currency exchange company, experienced a significant ransomware attack, forcing it offline for several weeks! The attack was caused by an employee’s unsafe behaviour, leading to a ransom demand of £20 million and significant financial losses.

– More recently, in 2021, Colonial Pipeline, the Colonial Pipeline attack in the US disrupted fuel supplies across the eastern states after a single compromised employee password was exploited. This incident demonstrated the catastrophic potential of weak endpoint security on employee devices.

As well as illustrating the devastating consequences of poor endpoint security, these examples may also serve as cautionary tales for businesses, especially as hybrid work and employee mobility continue to grow.

Benefits of Managed Corporate Devices 

Despite the risks, there are clear benefits to allowing employees to use company-provided laptops, particularly in remote and hybrid work settings. Flexible work environments contribute to higher employee morale and productivity. However, businesses must ensure that security is not compromised in pursuit of these benefits.

Mobile Device Management

Many companies have successfully implemented Mobile Device Management (MDM) systems, which allow IT departments to manage, monitor, and secure corporate devices remotely. These systems enable businesses to enforce security policies, such as encryption and regular software updates, while providing IT teams with visibility over potential threats. Companies like IBM and Google, for example, have adopted stringent MDM solutions, ensuring that employees can work flexibly without putting the business at risk.

What Does This Mean for Your Business? 

The growing risks associated with employees using work laptops for personal activities demand that businesses take a more proactive approach to cybersecurity. The rise of hybrid and remote work appears to have blurred the lines between personal and professional device use, creating new vulnerabilities that need to be addressed.

To mitigate these risks, businesses need to establish clear guidelines for acceptable use of work devices. This includes not only educating employees about the dangers of risky behaviour but also ensuring they understand the legal and compliance implications of their actions. Regular cybersecurity training, particularly on topics like phishing, malware, and safe browsing practices, could, therefore, be crucial.

In addition to clear policies, businesses may also benefit from investing in robust endpoint security solutions that can detect and block threats in real-time. Popular solutions, such as Microsoft Defender for Endpoint (there are, of course, many others), can provide the necessary protection while allowing IT teams to monitor threats without invading employees’ privacy.

Ultimately, businesses that implement a comprehensive cybersecurity strategy, invest in cutting-edge security solutions, and foster a culture of awareness and responsibility among their employees will be better positioned to thrive in today’s increasingly flexible work environment. Ensuring that company devices are secure and that employees are well-informed about their responsibilities is not just a technical issue but is critical for long-term business success.

Tech Insight : Personal Activities … On Work Laptops (Part 1)

Following a new ESET study which highlighted how workers using company-provided laptops for personal activities could be putting work hardware at risk, we’ll explore the issues surrounding this practice and the potential consequences for businesses and employees, in two parts.

90% Using Work Laptops For Home Usage … But What About Risky Behaviour? 

The recent study by cybersecurity company ESET revealed that employees are regularly engaging in risky activities on their work laptops. For example, the study shows that nine out of ten surveyed admitted to using their work devices for personal activities, including illegal streaming, gambling, and viewing adult content! Alarmingly, 20 per cent of respondents who view adult content say they do so daily, while the same proportion engages in online gambling daily using their work devices.

Work From Anywhere and Employee Mobility 

The shift towards remote and hybrid work environments is one reason employees may be blurring the lines between professional and personal use of their work laptops. With the flexibility to work from anywhere, such as a home-office or while travelling, these devices often become a primary computing tool for both work and personal activities. While this convenience enhances productivity and work-life balance, it also introduces significant risks to businesses.

Accessing the Dark Web with Their Work Laptop! 

The ESET study also highlighted some very concerning behaviour, with 17 per cent of respondents admitting to accessing the dark web using their work laptops, with some doing so daily.

Accessing the dark web exposes businesses to severe risks, including malware or ransomware attacks, data breaches, legal consequences, and reputational damage.

Consequences of Risky Behaviour 

The consequences of employees engaging in risky online behaviour using work devices can be severe for both the business and the individual. Businesses may face data breaches, financial losses, and regulatory penalties, while employees could be subject to disciplinary action, legal ramifications, or even job termination if their actions cause significant harm to the organisation. The ESET study revealed that 18 per cent of respondents felt their job would be at risk if their risky behaviour were discovered.

Employee Awareness Important 

In the report of the study, Jake Moore, Global Cybersecurity Advisor at ESET, stresses the importance of employee awareness, saying: “We often hear ’employees are the weakest security link,’ and endpoint security may not be the first thought on people’s minds. Businesses need to ensure that employees understand cybersecurity risks and their role in mitigating them, which includes avoiding risky behaviour or accessing illegal websites on their work laptops.” 

Many Have No Cybersecurity On Work Laptop 

Despite the clear risks, the study also revealed a worrying lack of security measures, with one in five (18 per cent) of respondents saying they had no cybersecurity software installed on their work laptop. A further 7 per cent were unsure if their devices were adequately protected, highlighting a critical gap in corporate security management.

What Does This Mean For Your Business? 

The findings of the ESET study highlight the critical need for businesses to take a proactive role in ensuring the security of work laptops and corporate devices. With so many employees engaging in what appears to be some extremely risky online behaviour (e.g. going on the dark web daily), the potential for significant data breaches and financial loss is high. The key for businesses is really to ensure that robust security measures are implemented across all work devices, particularly in hybrid work settings where employees use these devices both for work and personal tasks.

Implementing effective cybersecurity policies is essential. Employees should really be educated about the dangers of risky online behaviour, and must be helped to clearly understand their responsibilities in safeguarding corporate assets. Training and awareness programmes that help employees recognise the threats of malware, ransomware, and phishing attacks should ideally be mandatory, particularly as personal, and professional device use becomes more intertwined. Also, companies should ensure that all devices have up-to-date cybersecurity software, such as endpoint protection, that can detect and block potential threats in real-time.

As highlighted in the ESET study, for businesses to effectively manage employee behaviour without invading privacy, IT departments should try to adopt tools and solutions that focus on detecting risk patterns rather than overseeing every detail of employees’ digital activity. Striking this balance could help maintain trust within the organisation while ensuring that cybersecurity remains a priority.

Next week, in Part 2 of this series, we will delve into the legal and compliance implications of risky employee behaviour on work laptops, explore real-world case studies of high-profile breaches, and provide further insights into how businesses can mitigate these risks effectively.