The bossware debate

Issue 6 2023 Information Security


Carey van Vlaanderen.

Employee monitoring, also called ‘bossware’ or ‘tattleware’, is more popular than ever. Bossware is used to describe various tracking tools to monitor employee activity. It is mostly used to track productivity and mitigate risk by monitoring email content, browser history, location, app usage and phone use through software, webcams, CCTV, GPS, fitness devices, and access control hardware.

Increased remote working, driven by the pandemic, has seen around 60% of companies with remote workers implement some form of bossware. Over half (53%) of those companies have found that workers are spending three or more hours per day on non-work activities.

Additional studies conducted support these findings. One study reported that up to 40% of employee internet usage was not work-related, while global analytics firm, Gallup, estimates that disengaged employees cost the world $8,8 trillion in lost productivity annually.

Bossware can help employers spot productivity issues and is often also used to monitor security. Between 88-95% of data breaches are caused by employee errors such as recycling passwords, clicking on links in phishing emails, or failing to update security patches. Humans are indeed the biggest threat in the cybersecurity space, and bossware can shine a light on areas where security training and awareness may be lacking.

“While bossware could be one way to boost productivity and examine security issues, it requires some forethought,” says Carey van Vlaanderen, CEO of ESET Southern Africa. “If implemented properly, bossware can help to protect your company against security and legal risks, but it should never be considered a replacement for robust security software and practices. Employers should, nonetheless, still respect the privacy of employees and be wary of potential privacy concerns that could demotivate employees and damage your relationship with them.”

There are several benefits to bossware, including:

• Discovering workplace practices that hinder productivity.

• Identifying tasks that could be automated.

• Building a fairer workplace by ensuring equal duties.

• Mitigating security risks.

• Monitoring employee stress levels.

There are also some potential cons, such as:

• Limited insight into time spent problem solving and on non-digital tasks.

• Increased performance pressure on employees.

• Privacy and legal concerns.

• Low employee morale due to feeling mistrusted or undervalued.

Legal and ethical implications

In South Africa, employee monitoring is mostly legal as long as the employer complies with certain aspects of the law. The two applicable laws are the Protection of Personal Information Act (POPIA), which requires that an employee must be informed if they are being monitored, and the Regulation of Interception of Communications and Provision of Communication-related Information Act (RICA), whereby a business may only intercept communications as it relates to the business and during the carrying on of business.

So, employers may not access or seek access to employees’ private email or social media accounts, for example, or monitor them after hours. Typically, employers also stipulate any monitoring terms in the employment contract so that it is agreed upon by both parties in writing before any work commences.

Just because something is legal, however, does not mean it is always ethical. Van Vlaanderen says that employers should take care to ensure monitoring is proportionate and does not unnecessarily intrude on the lives of employees. “Take time to outline a framework that stipulates the extent of the monitoring and the reasons for tracking those activities. Ensure employees are aware of any monitoring and how it may be used and encourage them not to conduct personal affairs on work devices.”

“Good policies,” she says, “will strike a balance between business demands and privacy concerns. Most importantly, transparency and dialogue will be key in maintaining trust between employers and employees, as is ensuring that any collected data is safe and only available to authorised users. Remember that monitoring on its own is also not enough – whether your concerns are security or productivity. Regular training, clear guidelines, and a robust software framework should always be the priority.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...