Skip to content

Home / The bargain

The Arrangement You Already Have

Before writing a policy, find out what is actually happening. The discovery is usually uncomfortable and it takes about a week.

The bargain · Procedure

Writing a BYOD policy for a situation you have not measured produces a document describing an organisation you do not run. The first task is finding out the shape of the thing.

The practical lesson in “The Arrangement You Already Have” is to connect every record to a named decision. Organisations exploring the provider's guide for employee time tracking can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.

What to find out

How many people access company systems from a device the organisation does not own. Which systems. What kind of device. Whether any agreement exists with any of them. And what data is actually resting on those devices rather than merely passing through.

For an independent reference relevant to “The Arrangement You Already Have”, consult the Microsoft BYOD planning guidance; compare its principles with the proposed ownership model, access rules and real support process.

That last distinction matters more than the others. A person reading email in a browser leaves little behind; a person with files synchronised to a personal laptop is holding your data at home.

Where to look

Identity and access logs show which devices connect, and most current systems record device type and operating system. That alone usually produces the headline number, and it is usually higher than the estimate anybody would have given.

Email and file platforms show which clients are connected, including the personal phone somebody configured three years ago and forgot.

Expense claims are an underused source: people claiming phone bills or accessories are telling you they are using personal equipment for work.

And asking is legitimate. A short, non-punitive survey — what do you use, for what — gets honest answers if it is clearly not an audit, and it finds the arrangements that leave no technical trace.

What the discovery usually shows

More devices than expected, by a wide margin.

A long tail of old phones still holding mail from a person who changed devices and never removed the account.

Several former employees whose access was revoked but whose devices still hold synchronised files, because nobody checked.

And at least one arrangement nobody knew about: a department that bought its own tooling, a contractor group working entirely on personal machines, a shared device in a back office used by whoever is on shift.

What to do with it first

Not a policy. Two immediate things: remove the access of people who have left, and remove the stale device registrations of people who are still there.

Both are reversible, both reduce exposure that day, and neither requires an agreement or a decision about the future arrangement.

Then the policy conversation can happen against a known population rather than an imagined one, which is the difference between a document that fits and one that describes somebody else's organisation.

What to do with an uncomfortable number

The first honest count usually exceeds whatever anybody expected, and the instinct is to treat it as a failure requiring a response. It is better treated as a baseline. Nothing got worse on the day you counted. The exposure existed before and is now visible, which is the only state from which it can be reduced, and reporting it that way protects whoever did the counting.

Keeping the count current

A one-off audit decays within months as people join, leave and change devices. The useful version is a standing report from the access system, produced monthly, showing device count by type and the oldest versions connecting. Ten minutes to set up and it converts an exercise into a measure, which is what makes the annual review in the later note possible.

Who should run the count

Somebody with access to the identity systems and no stake in the answer. Where the arrangement's owner runs their own audit the findings are reliably smaller, not through dishonesty but because people search less hard for things that reflect on them.

Starting with the leavers

Of everything a first audit uncovers, former employees with live data are the item to act on immediately. It is bounded, it is entirely within the organisation's control, and it reduces real exposure in the same week. The rest of the findings can wait for the policy work; this one should not.

An audit that finds nothing surprising was not looking hard enough. In this subject the first honest count is always larger than the estimate.

Whose Device, Whose Data