{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T19:22:24Z","timestamp":1778613744332,"version":"3.51.4"},"reference-count":62,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2022,2,23]],"date-time":"2022-02-23T00:00:00Z","timestamp":1645574400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Informatics"],"abstract":"<jats:p>The prevalence and maturity of Bring Your Own Device (BYOD) security along with subsequent frameworks and security mechanisms in Australian organisations is a growing phenomenon somewhat similar to other developed nations. During the COVID-19 pandemic, even organisations that were previously reluctant to embrace BYOD have been forced to accept it to facilitate remote work. The aim of this paper is to discover, through a study conducted using a survey questionnaire instrument, how employees practice and perceive the BYOD security mechanisms deployed by Australian businesses which can help guide the development of future BYOD security frameworks. Three research questions are answered by this study: What levels of awareness do Australian businesses have for BYOD security aspects? How are employees currently responding to the security mechanisms applied by their organisations for mobile devices? What are the potential weaknesses in businesses\u2019 IT networks that have a direct effect on BYOD security? Overall, the aim of this research is to illuminate the findings of these research objectives so that they can be used as a basis for building new and strengthening existing BYOD security frameworks in order to enhance their effectiveness against an ever-growing list of attacks and threats targeting mobile devices in a virtually driven work force.<\/jats:p>","DOI":"10.3390\/informatics9010016","type":"journal-article","created":{"date-parts":[[2022,2,23]],"date-time":"2022-02-23T22:54:02Z","timestamp":1645656842000},"page":"16","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["BYOD Security: A Study of Human Dimensions"],"prefix":"10.3390","volume":"9","author":[{"given":"Kathleen","family":"Downer","sequence":"first","affiliation":[{"name":"School of Computing, Mathematics & Engineering, Charles Sturt University, Albury 2640, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5276-1421","authenticated-orcid":false,"given":"Maumita","family":"Bhattacharya","sequence":"additional","affiliation":[{"name":"School of Computing, Mathematics & Engineering, Charles Sturt University, Albury 2640, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,23]]},"reference":[{"key":"ref_1","unstructured":"Geoff, E. (2020, August 20). Bring Your Own Device-the New Normal: The NCSC View on BYOD and the Rise in Home Working, Available online: https:\/\/www.ncsc.gov.uk\/blog-post\/bring-your-own-device-the-new-normal."},{"key":"ref_2","unstructured":"Ratchford, M., El-Gayar, O., Noteboom, C., and Wang, Y. (2021). BYOD security issues: A systematic literature review. Inf. Secur. J. Glob. Perspect., 1\u201321."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1016\/S1361-3723(14)70007-7","article-title":"Best practices for BYOD security","volume":"2014","author":"Romer","year":"2014","journal-title":"Comput. Fraud Secur."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/S1353-4858(12)70111-3","article-title":"BYOD security challenges: Control and protect your most sensitive data","volume":"2012","author":"Morrow","year":"2012","journal-title":"Netw. Secur."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1016\/j.procs.2016.02.030","article-title":"Legal Issues in Secure Implementation of Bring Your Own Device (BYOD)","volume":"78","author":"Dhingra","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_6","unstructured":"Brodin, M. (2015, January 14\u201316). Combining ISMS with strategic management: The case of BYOD. Proceedings of the 8th IADIS International Conference Information Systems, Madeira, Portugal."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"101998","DOI":"10.1016\/j.cose.2020.101998","article-title":"Compliance with Bring Your Own Device security policies in organizations: A systematic literature review","volume":"98","author":"Palanisamy","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_8","unstructured":"Bullock, L. (2019). The Future of BYOD: Statistics, Predictions and Best Practices to Prep for the Future, Forbes. Available online: https:\/\/www.forbes.com\/sites\/lilachbullock\/2019\/01\/21\/the-future-of-byod-statistics-predictions-and-best-practices-to-prep-for-the-future\/#1c6a1fa91f30."},{"key":"ref_9","unstructured":"Barker, J. (2014). Kensington Survey: Majority of Organizations Report BYOD Creates Greater Security Risks, Close-Up Media Inc."},{"key":"ref_10","unstructured":"Malloy, M. (2014). Webroot Rolls out New BYOD Security Report. Wireless News, Close-Up Media Inc."},{"key":"ref_11","unstructured":"Johnson, K., and DeLaGrange, T. (2012). SANS Survey on Mobility\/BYOD Security Policies and Practices. Whitepaper, SANS Institute."},{"key":"ref_12","first-page":"1135","article-title":"BYOD Security Strategy (Aspects of a Managerial Decision)","volume":"9","author":"Michelberger","year":"2020","journal-title":"J. Secur. Sustain. Issues"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Weidman, J., and Grossklags, J. (2017, January 4\u20138). I like it, but I hate it: Employee perceptions towards an institutional transition to BYOD second-factor authentication. Proceedings of the 33rd Annual Computer Security Applications Conference, Orlando, FL, USA.","DOI":"10.1145\/3134600.3134629"},{"key":"ref_14","first-page":"1","article-title":"Factors Affecting Information Security and the Widest Implementations of Bring Your Own Device (BYOD) Programs","volume":"14","author":"Mensch","year":"2020","journal-title":"ACET J. Comp. Edu. Res."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1016\/j.chb.2018.07.045","article-title":"An examination of the gender gap in smartphone adoption and use in Arab countries: A cross-national study","volume":"89","author":"Ameen","year":"2018","journal-title":"Comp. Hum. Behav."},{"key":"ref_16","first-page":"61","article-title":"BYOD Policy Compliance: Risks and Strategies in Organizations","volume":"62","author":"Palanisamy","year":"2020","journal-title":"J. Comput. Inf. Syst."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/S1353-4858(12)70013-2","article-title":"BYOD: Enabling the chaos","volume":"2012","author":"Thomson","year":"2012","journal-title":"Netw. Secur."},{"key":"ref_18","first-page":"1","article-title":"Factors driving employee participation in corporate BYOD programs: A cross-national comparison from the perspective of future employees","volume":"21","author":"Wang","year":"2017","journal-title":"Australas. J. Inf. Syst."},{"key":"ref_19","unstructured":"Chigada, J., and Kyobe, M.E. (2018, January 4\u20136). Evaluating factors contributing to misalignment of the South African National Cybersecurity Policy Framework. In Proceedings of the 2018 International Conference on Information Resources Management (CONF-IRM 2018). Ningbo, China."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Alotaibi, B., and Almagwashi, H. (2018, January 4\u20136). A Review of BYOD Security Challenges, Solutions and Policy Best Practices. Proceedings of the 2018 1st International Conference on Computer Applications & Information Security (ICCAIS), Riyadh, Saudi Arabia.","DOI":"10.1109\/CAIS.2018.8441967"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Ward, J., Dogan, H., Apeh, E.T., Mylonas, A., and Katos, V. (2017, January 8\u201314). Using human factor approaches to an organisation\u2019s Bring Your Own Device scheme. In Proceedings of the 5th International Conference on Human Aspects of Information Security, Privacy and Trust. Vancouver, BC, Canada.","DOI":"10.1007\/978-3-319-58460-7_28"},{"key":"ref_22","unstructured":"French, A., Guo, C., Schmidt, M., and Shim, J. (2015, January 13\u201315). An exploratory study on BYOD in class: Opportunities and concerns. Proceedings of the Twenty-first Americas Conference on Information Systems, Fajardo, Puerto Rico."},{"key":"ref_23","first-page":"237","article-title":"Bring your own device to work: Benefits, security risks, and governance issues","volume":"16","author":"Pinchot","year":"2015","journal-title":"Issues Inf. Syst."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Hallett, J., and Aspinall, D. (2017, January 29\u201331). Capturing Policies for BYOD. Proceedings of the 32nd International Conference on ICT Systems Security and Privacy Protection\u2014IFIP SEC 2017, Rome, Italy.","DOI":"10.1007\/978-3-319-58469-0_21"},{"key":"ref_25","first-page":"1279","article-title":"Bring Your Own Device Organisational Information Security and Privacy","volume":"10","author":"Garba","year":"2015","journal-title":"ARPN J. Engg. Appl. Sci."},{"key":"ref_26","unstructured":"Wang, W., Wei, J., and Vangury, K. (2014, January 10\u201313). Bring Your Own Device Security Issues and Challenges. Proceedings of the 11th Annual IEEE CCNC-Mobile Device, Platform and Communication, Las Vegas, NV, USA."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"475","DOI":"10.1108\/ICS-03-2016-0025","article-title":"A systematic approach to investigating how information security and privacy can be achieved in BYOD environments","volume":"25","author":"Bello","year":"2017","journal-title":"Inf. Comp. Security"},{"key":"ref_28","first-page":"11","article-title":"Complying with BYOD security policies: A moderation model based on protection motivation theory","volume":"1","author":"Tu","year":"2019","journal-title":"J. Midwest Assoc. Inf. Syst."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1108\/ICS-05-2020-0069","article-title":"Users\u2019 attitude on perceived security of enterprise systems mobility: An empirical study","volume":"29","author":"Palanisamy","year":"2021","journal-title":"Inf. Comp. Security."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Wani, T.A., Mendoza, A., and Gray, K. (2019, January 29\u201331). BYOD in hospitals-Security issues and mitigation strategies. Proceedings of the Australasian Computer Science Week Multiconference Proceedings (ACSW\u201919), Sydney, Australia.","DOI":"10.1145\/3290688.3290729"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"274","DOI":"10.1080\/10919392.2019.1639913","article-title":"Security Policy Opt-in Decisions in Bring-Your-Own-Device (BYOD)\u2013A Persuasion and Cognitive Elaboration Perspective","volume":"29","author":"Yang","year":"2019","journal-title":"J. Organ. Comput. Electron. Commer."},{"key":"ref_32","first-page":"247","article-title":"Motivation and opportunity based model to reduce information security insider threats in organisations","volume":"40","author":"Safa","year":"2018","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"106184","DOI":"10.1016\/j.chb.2019.106184","article-title":"Employees\u2019 behavioural intention to smartphone security: A gender-based, cross-national study","volume":"104","author":"Ameen","year":"2020","journal-title":"Comp. Hum. Behav."},{"key":"ref_34","first-page":"115","article-title":"Exploring information systems security implications posed by BYOD for a financial services firm","volume":"38","author":"Chigada","year":"2021","journal-title":"Bus. Inf. Rev."},{"key":"ref_35","first-page":"56","article-title":"Security issues with mobile IT: A narrative review of Bring Your Own Device (BYOD)","volume":"8","author":"Aguboshim","year":"2019","journal-title":"J. Inf. Eng. Appl."},{"key":"ref_36","unstructured":"Downer, K., and Bhattacharya, M. (2016, January 19\u201321). BYOD Security: A New Business Challenge. Proceedings of the Proceedings of the 5th International Symposium on Cloud and Service Computing, Chengdu, China."},{"key":"ref_37","unstructured":"Agudelo-Serna, C.A., Ahmad, A., Bosua, R., and Maynard, S.B. (2017, January 10\u201313). Strategies to mitigate knowledge leakage risk caused by the use of mobile devices: A preliminary study. Proceedings of the 38th International Conference on Information Systems (ICIS 2017), Seoul, Korea."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"659","DOI":"10.1080\/17517575.2017.1404132","article-title":"A study of BYOD adoption from the lens of threat and coping appraisal of its security policy","volume":"12","author":"Cho","year":"2018","journal-title":"Enterp. Inf. Syst."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1287\/isre.2019.0846","article-title":"Why would I use location-protective settings on my smartphone? Motivating protective behaviors and the existence of the privacy knowledge\u2013belief gap","volume":"30","author":"Crossler","year":"2019","journal-title":"Inf. Syst. Res."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"770","DOI":"10.1108\/JEIM-10-2019-0318","article-title":"Understanding employees\u2019 adoption of the Bring-Your-Own-Device (BYOD): The roles of information security-related conflict and fatigue","volume":"34","author":"Chen","year":"2020","journal-title":"J. Enterp. Inf. Manag."},{"key":"ref_41","unstructured":"Bradford Networks (2012). Ten Steps to Secure BYOD. Whitepaper, Bradford Networks."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Eslahi, M., Naseri, M., Hashim, H., Tahir, N.M., and Mat Saad, E. (2013). BYOD: Current State and Security Challenges, Universitii Teknologi MARA.","DOI":"10.1109\/ISCAIE.2014.7010235"},{"key":"ref_43","first-page":"62","article-title":"Bring Your Own Device (BYOD): Security risks and mitigating strategies","volume":"4","author":"Gajar","year":"2013","journal-title":"J. Glob. Res. Comp. Sci."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Leavitt, N. (2013). Today\u2019s Mobile Security Requires a New Approach. Technology News, Computer, IEEE Computer Society.","DOI":"10.1109\/MC.2013.400"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Scarfo, A. (2012, January 12\u201314). New Security perspectives around BYOD. Proceedings of the 2012 Seventh International Conference on Broadband, Wireless computing, Communication and Applications, Victoria, BC, Canada.","DOI":"10.1109\/BWCCA.2012.79"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1016\/S1353-4858(13)70050-3","article-title":"The security implications of BYOD","volume":"4","author":"Tokuyoshi","year":"2013","journal-title":"Network Sec."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1016\/j.protcy.2013.12.005","article-title":"BYOD Bring Your Own Device","volume":"9","author":"Disterer","year":"2013","journal-title":"Procedia Technol."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"247","DOI":"10.1016\/j.ijcip.2014.10.002","article-title":"Security considerations related to the use of mobile devices in the operation of critical infrastructures","volume":"7","author":"Armando","year":"2014","journal-title":"Int. J. Crit. Infras. Protectn."},{"key":"ref_49","first-page":"281","article-title":"Comparing intention to avoid malware across contexts in a BYOD-enabled Australian university: A Protection Motivation Theory approach","volume":"48","author":"Pittayachawan","year":"2014","journal-title":"Comp. Secur."},{"key":"ref_50","first-page":"95","article-title":"BYOD: Implementing the right policy","volume":"Volume 1","author":"Pell","year":"2013","journal-title":"IT Practices for SME Success Series: Book 1: The Role of IS Assurance & Security Management"},{"key":"ref_51","first-page":"36","article-title":"Countering Mobile Device Threats: A mobile device security model","volume":"8","author":"Kearns","year":"2016","journal-title":"J. Forensic Investig. Account."},{"key":"ref_52","unstructured":"Cisco\u20132014 (2014). Device Freedom without Compromising the IT Network, Whitepape."},{"key":"ref_53","unstructured":"Vignesh, U., and Asha, S. (2017, January 29\u201339). Modifying security policies towards BYOD. Proceedings of the 2nd International Symposium on Big Data and Cloud Computing, Tetouan, Morocco."},{"key":"ref_54","unstructured":"Australian Government, Department of Defence: Intelligence and Security (2014). Bring Your Own Device (BYOD) For Executives. Paper Explaining Guidelines for Corporate BYOD Policies, Australian Cyber Security Centre."},{"key":"ref_55","first-page":"12","article-title":"Bring Your own Device (BYOD): An evaluation of associated risks to corporate information security","volume":"4","author":"Boaten","year":"2016","journal-title":"Int. J. IT Eng."},{"key":"ref_56","unstructured":"Oracle Corporation-2014 (2014). The Oracle Mobile Security Suite: Secure Adoption of BYOD. Whitepaper, Oracle Corporation."},{"key":"ref_57","unstructured":"King, J. (2015). Identifying Best Practices for a BYOD Policy, University of Oregon."},{"key":"ref_58","unstructured":"Agudelo, C., Bosua, R., Ahmad, A., and Maynard, S. (December, January 30). Understanding knowledge leakage & BYOD (Bring Your Own device): A mobile worker perspective. Proceedings of the Australasian Conference on Information Systems, Adelaide, Australia."},{"key":"ref_59","unstructured":"CISCO\u20132008 (2008). Data Leakage Worldwide: The High Cost of Insider Threats. White Paper, CISCO."},{"key":"ref_60","unstructured":"Koh, E., Oh, J., and Im, C. (2014, January 12\u201314). A study on security threats and dynamic access control technology for BYOD, Smart-work Environment. Proceedings of the International Conference of Engineers and Computer Scientists, Hong Kong."},{"key":"ref_61","unstructured":"Reinfelder, L., and Weishaupl, E. (2015). A Literature Review on Smartphone Security in Organisations Using a New Theoretical Model-The Dynamic Security Success Model, University Erlangen-Nurnberg."},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"418","DOI":"10.1016\/j.procs.2016.08.064","article-title":"Data management in mobile enterprise applications","volume":"94","author":"Hemdi","year":"2016","journal-title":"Procedia Comput. Sci."}],"container-title":["Informatics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2227-9709\/9\/1\/16\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:26:11Z","timestamp":1760135171000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2227-9709\/9\/1\/16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,23]]},"references-count":62,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2022,3]]}},"alternative-id":["informatics9010016"],"URL":"https:\/\/doi.org\/10.3390\/informatics9010016","relation":{},"ISSN":["2227-9709"],"issn-type":[{"value":"2227-9709","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,23]]}}}