CyberElements
Back

How to Secure the BYOPC?

CyberElements,

Share via

Having been widely democratised over the past three years due to the unexpected and massive lockdown caused by the first wave of the Covid-19 epidemic, the BYOPC (Bring Your Own PC) concept is now becoming a real issue for the IT departments of organisations. For them, this practice provides as many organisational solutions as it generates security issues for the information system. While it is generally not recommended to let employees use their personal computers to access their organisation’s applications and resources, there are today certain solutions that make BYOPC and BYOD security achievable.

What is BYOPC?

BYOPC is a subset of the BYOD (Bring Your Own Device) concept that focuses on personal computers, including Windows PCs and Macs. It means employees can use their personal computer to access their organisation’s information system from the company’s premises, from home, or in a mobile situation — either regularly or exceptionally, in addition to using a professional computer.

In the Hype Cycle for Endpoint Security report for 2022, Gartner predicted that BYOPC security would peak in two to five years. According to Gartner’s senior research director, Rob Smith, the “urgent need” to let employees work from home and the absence of hardware bolstered BYOPC adoption globally.

What are the challenges for IT systems security?

In a BYOPC situation, the IT department of the organisation neither controls nor manages the employee’s workstation. Without a solution appropriate to this specific situation, the IT department cannot guarantee the integrity of that workstation. If malware is present on the employee’s personal computer, it can easily spread throughout the entire information system as soon as the user connects to the organisation’s resources.

This was particularly true during the lockdown period, when the number of teleworkers more than doubled in just a few days. A large number of these employees were forced to use their personal computers, given the lack of availability of professional laptops controlled by the IT department. During the lockdown period in 2020, the number of cyberattacks exploded, largely due to teleworking and the porosity between personal and professional use of the same computer. The lockdown also allowed hackers to install themselves permanently and discreetly in organisations’ information systems, in order to attack and ransom them several weeks or even months after entering.

Securing access to the IT system from a personal device

BYOD security is nevertheless possible, particularly by using a ZTNA (Zero Trust Network Access) solution, which is much better suited to BYOPC than a VPN. While a VPN gives access to a network, ZTNA gives access to an application or resource, depending on the user’s access context — which allows granular access and better partitioning of the organisation’s information system. Applying this principle of least privilege is an essential pillar of Zero Trust. Applicable to all users, internal or external to the organisation and on a managed device or not, ZTNA becomes essential when it comes to BYOPC.

CyberElements, as a Zero Trust SaaS platform, secures BYOPC and turns untrust into trust. A device posture check can be enabled in order to validate, for example, the presence of an antivirus, a firewall or updates, to ensure the proper management of a user endpoint device the IT department does not manage. Access policies can be set according to the trust one can place in the endpoint’s security context: an employee teleworking might get fewer rights than at the office when it comes to accessing critical assets.

Zero Trust goes beyond access policy management

When we think of Zero Trust, the first thing that comes to mind is the policies that must be enforced: least privilege, JIT privilege, zero standing privilege. But reaching a full Zero Trust level also takes intrinsic characteristics of the access infrastructure: using dynamic, random and disposable network ports to protect against brute-force attacks; hiding web applications and resources from the internet by rewriting all their URLs, so that the URLs exposed in the end user’s browser cannot be used outside the access platform itself; creating the connection tunnel to the resource only at the time of, and for the duration of, the use of that application or resource. So beyond access policy management, you need to enforce least connection, JIT connection and zero standing connection to reach the utmost level of Zero Trust.

Tags

  • Articles
  • ZTNA
  • Defence & Critical Infrastructure
  • Healthcare
  • Industrial & Manufacturing
  • MSPs
  • Public Sector
  • Financial Services
  • Secure Remote Access
  • Third-Party & Vendor Access
  • OT & Industrial Security
  • Audit & Compliance

Let’s secure your access together