Skip to content
Operations HubIT & Cybersecurity

Personal Devices at Work: Drawing Sensible BYOD Security Lines

Whether or not your business has a BYOD policy, it has BYOD: people are reading work email on personal phones, joining Teams calls from home laptops, saving the.

By Nick Lucock·17 August 2026·4 min read

The short answer

Every business already has BYOD, whether it has a policy or not — people read work email and join calls on personal phones. Draw the line by access, not device: communication tools (email, chat) are reasonable on personal devices with a passcode, current OS and updates; core business systems belong behind controlled browser sessions; and payroll, banking and bulk data should stay on company-managed devices only. Align controls with the ASD Essential Eight.

Whether or not your business has a BYOD policy, it has BYOD: people are reading work email on personal phones, joining Teams calls from home laptops, saving the odd file where it's handy. The choice was never yes-or-no; it's whether this happens inside deliberate lines or inside a blind spot. The good news is that sensible lines are short, mostly free, and don't require treating your team like suspects. Here's where to draw them.

Start with what, not who

Skip the device debate and classify the access. Three tiers cover most SMEs:

  • Tier 1 — communication: email, calendar, chat. Reasonable on personal devices, with conditions (below). Blocking this outright mostly produces workarounds.
  • Tier 2 — business systems: the accounting file, the job system, the CRM, shared documents. Acceptable on personal devices via controlled doors — browser sessions and managed apps, not local copies and syncing folders.
  • Tier 3 — the crown jewels: payroll, banking, bulk customer data, admin consoles. Company-managed devices only. The line that matters most, and the cheapest to enforce because it touches few people.

Written down, this is half your policy: most BYOD trouble comes not from personal phones reading email, but from Tier 3 access quietly happening from an unpatched home PC.

The minimum standards a personal device must meet

If a device touches work systems, it meets the bar — politely non-negotiable: a passcode/biometric lock and auto-lock; the operating system still supported and updates on; MFA on every work account it accesses (the control doing most of the protective work); and work data accessed through the approved apps rather than forwarded into personal email or copied to personal cloud storage. That last one deserves its own sentence in the policy, because the most common SME data leak isn't hacking — it's convenience: the customer list emailed to self "to work on tonight," now living permanently outside every control you have.

For Microsoft 365 (or Google) shops, the practical enforcement tool is the platform's built-in mobile app management: it can require a PIN on work apps, keep work data inside them, and — crucially — wipe the work container only if a device is lost or its owner leaves, without touching personal photos. That selective-wipe capability defuses the privacy objection that sinks most BYOD conversations, and it's typically already in the subscription you pay for.

Decide the exit before anyone exits

The day a team member resigns is the wrong day to discover their personal phone holds two years of work email and a synced documents folder. Bake BYOD into offboarding: accounts disabled on departure (which kills app access), the work profile removed or remotely wiped, and any local copies addressed in the exit conversation. Run the same drill for a lost device — who do they call, how fast, what gets wiped. Write both as five-line procedures; speed is the whole game when a phone goes missing.

Put it in writing people actually read

A one-page BYOD policy beats a ten-page one nobody opens: the three tiers, the device standards, the no-forwarding rule, the lost-device number, what the company can and can't see or wipe (be explicit — transparency here is what makes the whole arrangement feel fair), and who pays for what if you offer an allowance. Have people acknowledge it at onboarding alongside the other policies. Then enforce it the boring way: when the new starter wants the job system on their personal laptop, the answer is whatever tier the policy says — consistently, including for the owner, whose own devices are usually the least compliant in the building.

FAQ

Should we just buy everyone work phones instead?

For roles living in Tier 3 — finance, admin-heavy, the owner — company devices are cleaner and worth the money. For everyone else, managed BYOD with the standards above hits most of the security at none of the hardware cost. Many SMEs land on a hybrid, drawn along the tier lines.

Can we legally wipe someone's personal phone?

You wipe what you manage: with app-level management, the work container only — and your policy should say exactly that, acknowledged in advance. Full-device wipe rights on personal hardware are a fight you don't need and shouldn't ask for.

What about contractors and bookkeepers on their own machines?

Same tiers, same standards, plus contract language: their access runs through your controlled doors, MFA enforced, and offboarding applies the day the engagement ends. External devices are where Tier 3 discipline earns its keep.


Device security is one of the checks in our free Business Health Check — five minutes to find the blind spots before they find you.

About the author

Nick Lucock

Chief Executive Officer, Valont

Nick leads Valont's day-to-day operations across Finance, People, Operations and Growth. He writes about how the work actually gets done — the processes, systems, and tools that keep Australian SMEs compliant and growing.

LinkedIn →

Want to know where your business stands?

Take our free Business Health Check — it takes 5 minutes and gives you a clear picture across finance, people, operations, and growth.