LegalTXTS – A Luminate Law Blog

Cybersecurity, Privacy & Internet Law

  • Home
  • About
  • Speaking
  • Contact

Recent Posts

  • Aloha, CCPA: What the New California Data Privacy Law Means For Hawaii Businesses
  • Cybersecurity For Small Businesses Tip #5 – Get Physical (Set Physical Controls)
  • Cybersecurity For Small Businesses Tip #4 – Stand Guard (Control Access)
  • Cybersecurity For Small Businesses Tip #3 – Sort It Out (Organize & Centralize)
  • Cybersecurity For Small Businesses Tip #2 – Keep Track (Take Inventory)

Categories

Tags

BYOD CDA CFAA Communications Decency Act Computer Fraud and Abuse Act concerted activity copyright copyright infringement cyber security cybersecurity cybersquatting data breach data collection data privacy data security defamation employee discipline employment employment law Facebook First Amendment FTC HR intellectual property Internet law invasion of privacy labor law misappropriation of information misappropriation of trade secrets National Labor Relations Act National Labor Relations Board NLRA NLRB privacy privacy law protected concerted activity SCA school law Section 230 social media social media firing social media policy Stored Communications Act trade secrets twitter

Archives

  • November 2019
  • October 2019
  • March 2019
  • May 2018
  • February 2018
  • September 2017
  • June 2017
  • April 2017
  • March 2017
  • January 2017
  • October 2016
  • September 2016
  • July 2016
  • May 2016
  • April 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • August 2015
  • June 2015
  • May 2015
  • April 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014
  • October 2014
  • August 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • March 2012
  • November 2011

Tag: BYOC

Cloudy With A Chance of Disaster: Avoiding the Security Risks of BYOC (Bring Your Own Cloud)

November 18, 2013 by Elijah Yip·0 Comments
Photo by Ian Lamont (CC BY 2.0) courtesy of Flickr

Photo by Ian Lamont (CC BY 2.0) via Flickr

You’ve probably heard of BYOD (Bring Your Own Device).  But do you know about BYOC?  It stands for Bring Your Own Cloud, and it’s more prevalent than you might think.

Cloud storage services like DropBox, Google Drive, and SkyDrive sport features that are attractive to an increasingly mobile workforce.  They provide gigabytes of storage for free.  Files in the cloud are accessible anywhere with an internet connection.  Changes to a file in a cloud account are synced across all devices with access to the account.  It’s not difficult to see why cloud services are gaining popularity among individuals and companies alike.

Therein lies the problem.  Because personal cloud accounts are so handy and easy to set up, an employee can create a security risk for a company in a matter of minutes.  An employee can essentially connect the organization to the cloud without the company’s knowledge via a private cloud account.  This enables the transfer of confidential company data to a location outside the company’s reach.

ComRent International, LLC v. Palatini, 2013 WL 5761319 (E.D. Pa. Oct. 24, 2013), involved such a scenario.  ComRent hired Clayton Taylor to serve as a vice president of product development.  Taylor primarily worked on matters related to Experium, a company that he co-founded and of which he was a minority owner.  Taylor set up a Google Drive account to store, access, and edit all of Experium’s intellectual property and confidential commercial information.  Only Taylor knew the username and password necessary for the account.  When ComRent hired an engineering firm to consult on options for the future of Experium, Taylor refused to grant the firm access to any of Experium’s intellectual property, believing that ComRent might appropriate the intellectual property for itself.  As a result, ComRent terminated Taylor and filed a lawsuit seeking access to the Google Drive account containing Experium’s corporate files.

Here are some tips for avoiding problems with unauthorized use of personal cloud storage accounts by employees.

Set a Policy: Remaining silent—and therefore ambiguous—about the organization’s stance on cloud storage can lead employees to believe they may use personal cloud accounts for work purposes without letting management know.  To eliminate such misconceptions, set a policy on whether or not the organization will use cloud storage.  If the decision is yes, then adopt measures to ensure responsible use of cloud storage.  If the decision is no, then clearly communicate to employees that storing work data in a personal cloud account is against company policy.

Maintain Control: If an organization decides to use cloud storage, it should retain control over the information necessary to access the cloud storage account (e.g., login credentials).  It is advisable to create an account under the organization’s name for official work purposes instead of allowing employees to use their personal accounts.

Restrict Unauthorized Cloud Services: Consider restricting access to private cloud storage sites from any device that can also access company data, including mobile devices, through the use of blacklists, proxies, and other network security measures.  This will prevent the transfer of work files to a private cloud account.  Organizations with BYOD programs might find it challenging to eliminate all access to private cloud services, but it is worthwhile consulting with the IT department about the feasibility of implementing such restrictions.

Retain Ownership: Make it clear that company information remains property of the company regardless of where it is stored.  It’s also a good idea to have employees sign written non-disclosure agreements.

Stay safe in the cloud!

 

Related articles
  • Cloud Storage Adoption Rising Among Businesses: TwinStrata
  • Western Digital Has An Unlimited Personal Cloud For All Your Stuff
  • Why BYOC Trend Comes With a Ready-Made New Market
Proudly powered by WordPress. Theme: Flat 1.7.11 by Themeisle.