An article in NB Online presents the view of David Smith, a fellow at Gartner in the United States, that an “employee-owned PC” approach is effective for companies.

This is a quintessential analyst’s argument. It sounds good and appears novel at first glance, so it will attract attention, but it is not grounded in reality.

When considering security, it has been said for 10 years that rather than prohibiting behavior, one should identify why employees engage in behavior one wants to prohibit and remove those causes. There is no doubt that this is correct, although security personnel seem not to understand it very well.

However, one must say that there is a considerable gap between that idea and the claim that companies should have employees bring their personal PCs rather than buying PCs for them.

Companies have presumably provided PCs because they considered both compliance and individual incentives.

Business use requires securing logs for compliance and various similar measures. To achieve this on a personal PC, software such as Hibun would have to be installed on it. That is certainly possible, but the result would be that the “personal PC” had no privacy at all and could not use external devices. Would an individual want to buy such an “unusable and frightening” PC with their own money? Probably not. A company might nevertheless be able to compel them, but forcing someone to purchase something they do not want infringes individual property rights and is an unfair act. Ultimately, the company would provide the PC, whose use would primarily be for work. An employment contract could make purchasing a PC a condition, but in that case it would be reasonable to regard its cost as included in salary. The company would presumably also need to bear the resulting increase in income and local taxes.

Taken to its conclusion, this “work on a personal PC” argument looks like nothing more than shifting company expenses onto individuals. If so, the question ultimately becomes which has the lower TCO: the company’s management costs, or the company buying an “individual asset” for the employee and shifting maintenance responsibility to that person.

I do not know how much each company pays in management costs, but centralized management is not necessarily more expensive, is it?

Of course, possible solutions are visible. One is to use a completely thin-client model. In that case, however, issues would remain, such as the maturity of server-side virtualization. Inability to work offline would also be a problem. It will still take considerable time to create an environment where high-speed network access is available anytime and anywhere.

If PCs themselves are left unrestricted while data and information remain safely usable offline, DRM-like functionality is essential. Yet no sufficiently general-purpose, easy-to-use DRM framework has currently been announced.

Only after these issues are resolved will “personal-PC adoption” cease to be pie in the sky and become something that can actually be tasted.