Did Willy Wonka Write your IT policies?

I’m no IT specialist, but as an exec team and board member I’ve had reason on numerous occasions to think carefully and seek expert advice about IT policy. Benchmarking policies across the higher ed sector I’ve observed widespread adoption of what I can only describe as Willy Wonka Policy. Willy Wonka is the eccentric industrialist/madman at the centre of Roald Dahl’s classic Charlie and the Chocolate Factory. He exists in a fantastical universe in which fizzy drinks can make you fly; he also sometimes punishes children with horrific lifelong consequences for minor breaches of his instructions.

Similarly, Wonka IT policies combine fantastical magical thinking with the occasional streak of sadism.

Willy Wonka with Intune on a laptop

Wonka Policy #1: No personal devices

5E(1)(aa)(iv): No personal electronic devices are to be connected to the Wonka College network or systems under any circumstances.

While it sounds like something from 2009, I’ve seen this in a recently adopted University College policy book. The fact that the vast majority of their teaching staff were adjuncts (who don’t get issued with corporate devices) and almost all the “college systems” were internet-facing web platforms seemed to escape the CTO’s notice. Faculty members who objected that following the policy would make their jobs nearly impossible were referred to their managers for re-education. An exception was made for mobile devices and tablets for reasons that nobody could explain, except that the budget didn’t extend to provisioning of mobile phones.

A sane policy needs to recognise that a highly casualised workforce with adjuncts and part-time teaching staff will need a flexible approach, such as the concentric circles model (more on that below).

Wonka Policy #2: Invasive BYOD requirements

6(vi)(6): Staff and students participating in BYOD must:

(i.) Present personal phones and laptops for inspection and enrolment in MDM and/or Intune

(ii.) Install Microsoft Defender EndPoint on all devices used in connection with the College

(ii.) Install the Wonka College root certificate to enable encrypted traffic to be decrypted and inspected at the gateway.

I guarantee you that nobody who understood what any of this means will have given their informed consent. You can’t control stuff you don’t own. Leaving aside the dubious actual security benefits, there are so many legal, cultural and HR risks here I sometimes wonder if any boards or risk committees actually read these things before adopting them.

Keep in mind that even permanent faculty members rarely have phones provided by their employer, and casual/sessional teaching staff (who make up 60% of teaching staff in some places) almost never get a laptop or a phone. To force people to carry Microsoft Teams around in their pocket so they can be always-contactable is questionable enough. But refusing to buy a device I am expected to have for work, while treating my private property as if the company owns it, is just Willy Wonka level nonsense.

Let me be very clear: hell will freeze over before I give the IT team at some random college where I occasionally adjunct the power to unilaterally administer my personal laptop and phone (“sorry, we accidentally wiped all your family photos and the manuscript for your next book”). In fact, if I’m working for multiple institutions (as is common) it might not even be possible to apply this policy.

I spoke to one experienced academic who agreed to teach a single class at a Melbourne-based uni and was told repeatedly that he could not log into Moodle to input marks until he installed a specific (windows-only) Antivirus program on his (Mac) laptop. Quite understandably, he gave up and hasn’t returned for another semester.

A sane BYOD policy treats private property with respect, and uses reasonable application-based controls to address the actual risks involved in each concentric circle in a reasonable way (more on that below).

Wonka Policy #3: One-size-fits-all data storage and retention rules

7A: All files and data in connection to your employment at Wonka College must only be stored on college systems.

7B: All files and data in connection to your employment at Wonka College must be deleted immediately on termination of your employment.

This is a classic example of a policy that makes total sense for an insurance company or nuclear submarine manufacturer, but shows complete lack of insight into what goes on in a tertiary education context. In Australia, academic staff almost always maintain intellectual property rights over at least some of their work product. Book projects and lecture notes are often developed over decades. Many funded projects involve collaboration with academics all over the world.

It’s true that the education regulatory environment has significant data retention, reporting, privacy and access rules. But you simply cannot work on a one-size-fits-all approach. Under their contracts, faculty are well within their rights to want to keep their lecture notes on a personal laptop, or to take their half-finished journal articles with them when they leave. On the other hand, we obviously need them to keep gradebooks in a place we can access them later for moderation or accreditation audit purposes, and registry staff should not be keeping student medical certificates and credit card numbers stored in the Apple Notes app on their personal iPhone.

A sane data policy will recognise that different types of data need different protections, and provide clear guidance for what is, and what is not, acceptable (more on that below).

Wonka Policy #4: Military-grade Intellectual Property protections

7C: Intellectual Property or data generated in the course of your employment must not be shared outside the organisation.

Clearly someone forgot to share with the CIO that “sharing IP with people outside the organisation” is a pretty good definition of why a university exists!

At one university I’m aware of, this policy was enforced by file sharing controls that in practice made it impossible to give students access to lecture notes, or collaborate with academics from another institution on an edited volume.

You’ll be shocked to learn that teachers being asked to work within this kind of environment inevitably fell back on a shadow IT system (Google Drive) in order to get their jobs done.

IT departments get very grumpy about shadow IT. They get even grumpier when I ask questions like “is the proliferation of shadow IT an indication that you are not providing people the tools they need?” or “if breaking multiple IT policies is an inherent requirement of someone’s job, maybe we need to look at our policies?”.

Again, a sane data policy will distinguish between types of data, taking time to understand what tools and controls are needed to serve the organisation’s actual mission (more on that below).

Wonka Policy #5: Social media gag clauses

8(7)(a): Any social media posts or public comment connected to your employment or Wonka College must be pre-approved by the marketing department

8(7)(b): Any posts on social media, whether of a personal nature or related to your work, must be consistent with the values and ethos of the college

8(7)(c): Employees will only contact current or former students via approved and monitored channels

These policies are so ubiquitous, but so evidently silly, that most organisations have forgotten they even have them. Let’s leave aside the extremely uncomfortable legal issues raised in many jurisdictions with trying to restrict speech based on employment contracts. Are you really expecting an expert on foreign policy to check with marketing before commenting on Twitter about an unfolding situation? Isn’t speaking publicly on issues related to their expertise exactly why you employed them? If you don’t trust them to have a Bluesky account, you probably shouldn’t trust them to teach students either.

As for the strict communications channels, it strikes me as written by people who have forgotten that humans sometimes have multiple relational contexts. Or that graduate students are not primary school children. Some of my former MDiv students are now pastors in the church I attend, and might reasonably send me a text message asking for a book recommendation. If I want to invite some PhD students and their families over for dinner, it might be convenient to organise that over WhatsApp.

A sane communication and social media policy treats your faculty as though they might have some limited powers of judgment (and perhaps even contractual rights to academic freedom!).

Wonka Policy #6: The instant firing squad

9(2)(xci): Breach of these policies will result in disciplinary action including immediate termination

Yeah, nah.

For starters, even Willy Wonka’s most sadistic tendencies is constrained by something called “employment law”. But even as an unenforceable threat, it is still magical and cruel Wonka-policy. Magical, because everyone knows the vice chancellor is never going to lose her job for using Google Docs to draft a conference paper. Cruel, because your receptionist will live in fear of losing his job because he clicked the wrong email – and you can guarantee you won’t hear about the mistake until it’s too late to do anything about it.

A sane policy will enforce policy using conditional access controls, and advise staff that failure to observe these requirements will result in temporary blocking of access.

The concentric circles model

Looking back over these Wonka policies, it's important to note that not all the policies are terrible ideas.

What makes a Wonka-policies is usually lack of alignment with context:

  1. a failure to understand the education sector. Wonka policies all have the same problem – a well-meaning consultant or CTO tries to import policies into the higher education space without understanding what our workers do all day, and those in management or governance roles wave the policy through because they don't see "IT stuff" as their specialty.

  2. a failure to calibrate controls for different types of tasks and users. What is reasonable to ask of a CFO reviewing management accounts is Wonka-thinking for a sessional academic writing a lecture.

The way to avoid Wonka policies is to differentiate between concentric circles. This enables us to distinguish between types of users and devices with appropriate controls at each level.

  • Circle 3 — Browser access. The bulk of the tools that adjuncts (or even full faculty members) need to do their job are accessible through a web browser. Put in place good MFA and conditional access policies, and you don’t have to worry about student data being stored where it shouldn’t be.

  • Circle 2 — Protected applications on BYOD. Need to put Teams on your phone, or OneDrive on your iPad? Sure. We don’t need to own the device, but we can put in place sensible application-level controls to ensure data is not kept on devices.

  • Circle 1 — Trusted devices. Some tasks require more than web or mobile apps. Want to download student enrolment forms or financial data to work on it offline? Cool – you’ll be needing a college owned laptop with appropriate security controls.

Likewise, we need to differentiate between types of data and ensure that some types of data remain on college systems:

  1. Student work, marks, and personal information are not to be copied to personal cloud storage (including personal Dropbox, Google Drive or iCloud accounts) or to personal email.

  2. Lecture notes and academic research can be stored in personal cloud storage.

Trying to fit everyone and every thing into the same access model simply doesn’t work, and you waste an enormous amount of effort and goodwill trying.

But is it just me? What Wonka policies have you come across in your travels?

Next
Next

The Hogwarts guide to securing online exams against AI