Assessing BYOD Security Maturity: A Survey of Australian Hospitals
摘要
The adoption of Bring Your Own Device (BYOD) in healthcare enhances productivity and mobility, however, it may introduce unique cybersecurity and privacy challenges. This study investigates BYOD security maturity of Australian hospitals from a socio-technical perspective, focusing on the integration of technical, organizational, and human factors. A survey of 19 IT and security executives, covering over 75 hospitals, assessed BYOD practices across four lifecycle stages: planning, asset protection, detection, and monitoring. While technical measures like network security (mean rating 3.79) and identity management (3.42) were relatively strong, areas such as BYOD security management automation (2.68), clinical communication (2.68), and BYOD policy (2.89) scored lower, reflecting gaps in BYOD related automation processes and alignment with clinical workflows. The study also highlights significant deficiencies in the “people” dimension, with low ratings for user training and awareness (2.58), stakeholder engagement (2.95), and management support (2.84), underscoring limited efforts to foster a security-conscious culture. Policies and processes, including vendor monitoring (2.53) and accountability (2.58), were often underdeveloped, with many hospitals lacking comprehensive BYOD frameworks tailored to healthcare’s operational and regulatory needs. The findings emphasize the need for hospitals to adopt a holistic socio-technical approach, prioritizing stakeholder collaboration, security automation, and targeted education programs to enhance their BYOD security posture, along with technological improvements. This approach allows strengthening of cybersecurity resilience, while also aligning security practices with the unique demands of healthcare environments, offering a foundation for further research into tailored, healthcare-specific solutions.