Bring Your Own Device (BYOD) can be convenient for employees and businesses. Checking email on your phone, joining a Teams meeting from a laptop at home, or opening a company document on a tablet has become completely normal.
But convenience can come with a cost.
When an employee uses a personal device for work, your business is relying on a device that it may not own, manage or fully control. That can make it much harder to protect company information, enforce security standards and remove business data when circumstances change.
This guide explains the key risks of BYOD and the controls businesses should consider before allowing personal devices to access company information.
What does BYOD actually include?
BYOD simply means an employee uses a personally owned phone, tablet or computer for work.
That could include:
- Adding a work email account to a personal phone
- Signing into Microsoft 365 or Google Workspace
- Joining online meetings
- Opening customer or company files
- Using a business messaging application
- Accessing accounting, CRM or project management software
- Downloading documents to a personal computer
It is important to remember that business information does not necessarily stay in the cloud.
Depending on the application and how it is configured, information can be stored on the device as downloaded files, attachments, cached data, messages, browser data or application content.
That means a seemingly harmless activity, such as opening an email attachment on a personal laptop, can create a copy of company information outside your normal IT controls.
The problem: you don’t fully control a personal device
On a company-owned computer, your IT provider can generally control the operating system, security software, updates, applications and configuration.
With a personal device, the situation is different.
The employee decides which applications to install, when to update the device, who else uses it and where their personal files are backed up.
Management software can provide additional controls, but what can actually be controlled depends on the device, operating system, application and management method.
Other people may use the device
A personal laptop or tablet may also be used by a partner, child or another member of the household.
Separate user accounts can reduce the risk, but many personal devices are still used through a shared account.
The UK’s National Cyber Security Centre (NCSC) specifically highlights this as a BYOD consideration, stating that access should not be permitted where an employee cannot follow the required security rules — including where work information cannot be kept separate from other family users.
Security updates may be missing
Your IT provider may not be able to confirm whether a personal device is running a supported operating system or has the latest security updates installed.
Employees may delay updates because their device is low on storage, an older application could stop working, or the device simply isn’t restarted regularly.
On a company-owned device, these issues can be monitored and managed centrally. On a personal device, they can be much harder to enforce.
Business files can end up in personal storage
Consider what happens when an employee downloads a document from work email or cloud storage.
The file could remain in:
- The Downloads folder
- A personal Documents folder
- A locally installed application
- A personal cloud storage account
- A device backup
Opening the document in another application can potentially create yet another unmanaged copy.
The result is that one company document could end up in several places that your business does not control.
Personal applications may have access to business information
Personal devices contain applications selected by the employee.
Depending on the permissions granted, applications may be able to access files, contacts, clipboard contents, browser information or other data stored on the device.
Your business may have little visibility of which applications are installed or what access they have.
Repairs can expose company information
A broken personal phone or laptop may be taken to a repair shop chosen by the employee.
If the device contains business email, saved sessions or downloaded company files, that information could potentially be accessible during the repair process.
Your BYOD policy should clearly explain who employees must contact before having a device repaired and what they should do if the device cannot be accessed.
Company data can remain after someone leaves
Disabling an employee’s Microsoft 365 or other business account will stop future access to many cloud services.
It won’t necessarily remove copies of company information that have already been downloaded to a personal device.
Files may remain in personal folders, unmanaged applications, downloads or personal cloud backups.
Managed applications and work profiles can make removing business information easier, but they can only remove data that they actually control.
Decide what work can be done on personal devices
Not all work carries the same level of risk.
Rather than simply deciding that BYOD is either “allowed” or “not allowed”, businesses should consider what information employees need to access and what they need to do with it.
For example, you might allow an employee to read work email through an approved mobile application while requiring a company-owned computer for:
- Customer database exports
- Financial information
- Legal documents
- Large volumes of customer data
- Administrative tasks
- Security configuration
- Backup management
- User account administration
Administrative and privileged work should be performed from a managed device wherever possible.
The same principles should apply to contractors. Their access should be limited to the applications and information they actually need to perform their role.
Minimum security requirements for BYOD
If you do allow personal devices to access company information, they should meet clearly defined security requirements.
Use a supported operating system
The device should run an operating system that is still receiving security updates.
Devices that can no longer receive current security updates should not be permitted to access company information.
Install security updates
Operating system and application updates should be installed automatically wherever possible.
Employees should also restart their devices when required to complete an update.
Require a screen lock
Every device accessing company information should be protected by a PIN, password, fingerprint or facial recognition.
Automatic screen locking should also be enabled when the device is not being used.
Enable encryption
Encryption helps protect information stored on a device if it is lost or stolen.
The Australian Cyber Security Centre recommends full-device encryption where personal devices may store business information.
Australian Cyber Security Centre – BYOD guidance
Encryption needs to be enabled before a device is lost or stolen, and it should be protected by a strong password or PIN.
Require Multi-Factor Authentication
MFA should be required for work email, cloud storage and other important business systems.
The NCSC recommends MFA as a minimum security control for BYOD access.
However, MFA is only one part of the solution. It protects access to an account; it does not protect a downloaded file sitting on an unencrypted personal laptop.
Block rooted or jailbroken devices
Rooting or jailbreaking removes some of the security restrictions built into modern operating systems.
Devices that have been rooted or jailbroken should not be permitted to access company data.
Detection isn’t perfect, so this should be treated as one control within a wider security strategy.
Control the applications used for work
Employees should know which applications are approved for:
- Messaging
- File access
- Document editing
- Remote access
- Other business activities
Where your management platform supports it, controls can also prevent company information being copied into unmanaged applications or saved to personal storage.
Keep shared computers separate
If a personal computer is permitted for work, the employee should have a dedicated user account.
Other household users should have their own accounts and should not know the employee’s password.
If business information cannot be kept separate from other users, BYOD access should not be permitted.
Make reporting problems easy
Employees need to know exactly who to contact if a personal device is:
- Lost
- Stolen
- Repaired
- Replaced
- Infected with malware
- Suspected of being compromised
The sooner the business knows about a problem, the more opportunity it has to disable access, investigate account activity and remove managed company data.
Use managed applications and work profiles
Technology such as Mobile Device Management (MDM) and Mobile Application Management (MAM) can help businesses separate work information from personal information.
MDM can apply security settings to an enrolled device and report whether it meets the organisation’s requirements.
MAM takes a more application-focused approach. Depending on the platform, it can restrict copying and pasting, prevent saving information to personal storage, require an additional PIN or remove company information from managed applications.
For example, Microsoft Intune can remove company data from protected applications when a device is lost or an employee leaves.
Microsoft Intune – Remove company data from protected applications
The employee’s personal information can remain on the device.
However, there is an important limitation:
Selective removal only works for information that the management system controls.
If an employee has copied a file into an unmanaged application, personal cloud storage or another unsupported location, the management platform may not be able to remove it.
A full factory reset is a different matter. It can remove both business and personal information, which is why businesses need to be particularly careful when applying full device management to employee-owned devices.
Microsoft provides further guidance on planning Intune deployments here:
Microsoft Intune planning guide
Employees should be told clearly what their employer and IT provider can see, control, lock or remove before they enrol a personal device.
Your BYOD policy should answer these questions
A BYOD policy shouldn’t simply say “employees can use their own devices”.
It should clearly define what is permitted and what is expected.
Your policy should cover:
- Which employees and contractors may use personal devices?
- Which types of devices are permitted?
- What work can be performed on them?
- Which applications must be used?
- Can company files be downloaded?
- Can the device be shared with other people?
- Which security settings are required?
- What information can the business or IT provider see?
- What settings can the business control?
- Can company information be removed remotely?
- What happens if the device is lost or stolen?
- What must happen before the device is repaired or sold?
- What happens when the employee leaves?
- Who pays for mobile data, repairs or replacement?
Privacy, employment and data protection requirements can vary between countries, so businesses operating across multiple locations should have their policy reviewed appropriately.
Employees should read and accept the policy before company access is added to their personal devices.
What happens if a personal device is lost or stolen?
The most important thing is to report it immediately.
Your response may include:
- Disabling access if the device cannot be accounted for
- Revoking active sign-in sessions
- Removing company data from managed applications
- Removing the device from approved-device lists
- Checking account activity for unexpected sign-ins
- Resetting credentials if they may have been exposed
- Establishing which company information may have been stored on the device
Remote locking and data removal aren’t magic solutions.
The device needs to connect to the management service before it can receive the command. If it remains switched off or offline, the command may never reach it.
That’s why encryption, MFA and other preventative controls remain important.
What happens when an employee leaves?
A BYOD process should also form part of your employee offboarding procedure.
At the agreed time, you should:
- Disable the employee’s account.
- Revoke active sessions.
- Remove company data from managed applications and work profiles.
- Check whether business files were downloaded to the device.
- Confirm how those files will be returned or deleted.
- Remove the device from approved-device records.
- Remove business applications, certificates, email profiles and VPN settings where supported.
The key point is that turning off an account isn’t necessarily the same as removing company data.
When shouldn’t you allow BYOD?
There are situations where providing a company-owned device is likely to be more appropriate.
Consider using a company-owned device when:
- The employee handles sensitive information
- The role requires administrator or privileged access
- Large amounts of company data need to be stored locally
- The device is shared with other people
- The operating system is no longer supported
- Encryption cannot be enabled
- The business cannot separate or remove its data
- The employee does not accept the required security controls
- The device has been rooted or jailbroken
Company-owned devices are generally easier for an IT provider to support because the hardware, configuration, software and security settings are known and can be managed.
Frequently Asked Questions
Can employees use a web browser without enrolling their personal device?
Potentially, yes.
However, browser-based access does not mean that no information is stored on the device.
Information can remain in browser caches, Downloads folders, saved passwords, screenshots or active sessions.
Access policies can restrict which devices and browsers are permitted, but sensitive work may still require a managed device.
Is MFA enough to secure a personal device?
No.
MFA helps protect the employee’s account, but it does not protect company files already stored on the device.
A proper BYOD approach should combine MFA with security updates, screen locks, encryption, approved applications and a process for dealing with lost or compromised devices.
Can the business see an employee’s personal information?
That depends on how the device is managed.
Application management generally focuses on business applications and their associated data. Full device enrolment can provide broader visibility and control.
Employees should receive a clear explanation of what their IT provider can see, change, lock or remove before enrolling their device.
Can the business erase an employee’s personal phone?
Some management methods support a complete factory reset, while application-only management does not.
A factory reset removes personal information as well as company data.
For employee-owned devices, selective removal of company information should be used where available.
Is BYOD cheaper than providing company devices?
Not necessarily.
BYOD can reduce the number of devices a business needs to purchase, but it can also introduce additional costs for management, support, security and administration.
Whether BYOD actually saves money depends on the devices, applications and type of work involved.
BYOD is a business decision, not just an IT decision
Allowing employees to use personal devices can provide flexibility and convenience, but it also changes how your business needs to approach security and data protection.
The key question isn’t simply:
“Can our employees use their own devices?”
It is:
“Can we protect our company information when they do?”
If employees are already using personal devices for work, your IT provider should be able to establish what information is being accessed, what controls are currently in place and where the gaps may be.
And if you don’t have an IT provider, Netserve can help you understand your current risks and put the right controls in place.
Get in touch with the Netserve team to discuss your BYOD setup and find out what you should be doing to protect your business.
Sources and further reading
- NCSC: Bring Your Own Device guidance
- NCSC: BYOD costs and security requirements
- Australian Cyber Security Centre: Risk management of enterprise mobility and BYOD
- Australian Cyber Security Centre: Securing customer personal data
- Microsoft Learn: Protect data and devices with Intune
- Microsoft Learn: Remove company data from protected applications
- Microsoft Learn: Intune planning guide




