Cyber Security
BYOD security risks: how to let staff use personal devices for work safely
The real risks of staff using personal phones and laptops for work, and how UK small businesses control them with Intune, app protection and a BYOD policy.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
Personal devices used for work create four main risks: no visibility of updates or malware, company data leaking into personal cloud backups and email, no way to wipe data when someone leaves, and UK GDPR exposure if a device is lost. The fix is a written BYOD policy backed by Microsoft Intune app protection, MFA and conditional access.
Somewhere in your business right now, company email is sitting on a phone the company does not own. For a firm of up to 250 people that is normal, and often sensible: nobody wants to carry two phones. The problem is not the practice, it is the practice without controls. This article sets out where the real risks are, what a workable bring-your-own-device (BYOD) arrangement looks like for a UK SME, and what to put in the policy.
Where the risk actually sits
The source of most BYOD trouble is invisibility. On a company laptop, we can see whether it is patched, whether the antivirus is current, whether the disk is encrypted and what happens when it connects to the network. On a personal device we can see none of that unless the business puts management in place.
Updates and malware. Personal devices lag on operating system updates and carry apps nobody vetted. An old Android phone running a version its manufacturer stopped patching years ago is a routine find.
Data leakage. This is the big one. Phones back up to iCloud or Google automatically. Laptops sync Downloads to personal OneDrive or Dropbox. People forward documents to personal Gmail to print at home. Every one of those copies is outside the business's control, cannot be recovered in a dispute and cannot be deleted when the person leaves. Under UK GDPR the business is still the data controller for all of it, and the ICO expects you to know where personal data lives.
Shared and lost devices. Family members know the PIN. Devices get left in taxis. Without encryption and remote wipe, a lost phone containing a mailbox of client correspondence is a potential reportable breach.
No offboarding. When someone leaves, the company laptop comes back. The personal phone with two years of email cached on it does not. Our offboarding checklist covers the wider problem, BYOD is the part most businesses miss.
Weaker network hygiene. Home broadband with a default router password, café Wi-Fi, a teenager's gaming PC on the same network. None of it is catastrophic on its own, but it is more exposure than the office.
Compliance. Cyber Essentials requires that every device accessing organisational data, including personally owned ones used for work email, meets the same controls as company devices. If certification matters to your customers, unmanaged BYOD fails you at the first question.
Two models: manage the device or manage the app
There are two practical ways to control a personal device, and choosing the right one for each group of staff is most of the design work.
| Mobile device management (MDM) | Mobile application management (MAM) | |
|---|---|---|
| What is controlled | The whole device: PIN, encryption, update level, apps, camera, remote wipe | Only the work apps (Outlook, Teams, OneDrive, Edge) and the data inside them |
| Staff perception | Intrusive on a personal phone, the business can see installed apps and can wipe the device | Light-touch, the business sees nothing personal and can only wipe work data |
| Best for | Company-owned devices, or roles handling sensitive data where a personal device is unavoidable | Most BYOD phones used for email, Teams and files |
| Microsoft tool | Intune device enrolment | Intune app protection policies (no enrolment needed) |
For most SMEs the answer is MAM for personal phones and full MDM for company laptops and any device in finance or leadership roles. App protection policies in Intune can require a PIN to open Outlook, block copy-paste from Outlook into WhatsApp, prevent saving attachments to personal storage, encrypt the app data, and wipe it all when the person leaves, without touching a single photo. Intune is included in Microsoft 365 Business Premium, which many businesses already pay for, it is one of the first things we enable in a Microsoft 365 security review.
The controls that make BYOD safe
Whichever model you pick, these six controls do the work.
- MFA on every account. A personal device is more likely to be phished or lost, so the password alone must never be enough. See what MFA is and why your business needs it.
- Conditional access. Require a managed app or a compliant device before Microsoft 365 will release email or files. Unmanaged browsers get read-only access or nothing. This turns the policy into something enforced rather than requested.
- App protection policies as described above, so work data stays in work apps.
- Minimum device standards. A supported OS version, a screen lock, encryption on. Intune can check these and block devices that fail until they are fixed.
- Least privilege. A personal phone does not need access to the finance system or the admin portal. Limit what BYOD accounts can reach.
- A leaver process that includes personal devices. Wiping work data from BYOD phones should be on the same checklist as collecting the laptop. Our client portal has a leaver form precisely so this is never forgotten.
Laptops are a harder case. A personal Windows laptop used for real work is difficult to secure without full management, and few staff will accept that. The honest answer is usually that anyone doing substantial work on a computer should have a company-managed one, and that the cost of a managed laptop is small next to the cost of a breach. The NCSC's device security guidance sets out the same principle for organisations of any size.
What to put in the BYOD policy
A policy is what makes the controls fair and enforceable. Keep it to two pages. It should cover:
- Who may use personal devices, and for what. Email and Teams for everyone, full file access only on managed devices, for example.
- Minimum requirements. Supported OS, automatic updates, screen lock, encryption, no jailbroken or rooted devices.
- What the business will install and what it can see. Be explicit that app protection cannot see personal data, and that full MDM can see installed apps. Trust comes from clarity.
- Data rules. No forwarding to personal email, no personal cloud sync of work files, no work data in personal messaging apps.
- Loss and theft. Report within a set time, the business will wipe work data remotely.
- Leaving. Work data will be removed from the device on the last day, the employee must not retain copies.
- Support boundaries. What IT will and will not help with on a personal device.
- Acknowledgement. Signed, and stored with the new-starter paperwork.
Fold this into your wider security policy rather than leaving it as a standalone document, our article on why you need a cyber security policy shows where it fits.
A worked example
A 25-person estate agency has negotiators out on viewings all day using personal iPhones for email and the property CRM, while the office runs company desktops. The sensible setup: Intune app protection on the negotiators' phones (PIN for Outlook and Teams, no saving to personal storage, wipe on leaving), conditional access that blocks unmanaged devices from SharePoint, MFA everywhere, and full MDM on the two managing partners' phones because they handle vendor and buyer financial details. Total change for staff: one extra PIN. Total change for the business: it can now answer "where is our data?" honestly. We see the same pattern in multi-depot plant hire businesses where depot managers work largely from phones.
What to do next
If you are not sure which personal devices currently hold company email, or whether you could wipe them tomorrow, that is worth finding out before you need to. An IT health check includes a review of device access to Microsoft 365 and a plain-English recommendation on BYOD for each group of staff.

