Whether or not your business has a BYOD policy, it has BYOD: people are reading work email on personal phones, joining Teams calls from home laptops, saving the odd file where it's handy. The choice was never yes-or-no; it's whether this happens inside deliberate lines or inside a blind spot. The good news is that sensible lines are short, mostly free, and don't require treating your team like suspects. Here's where to draw them.
Start with what, not who
Skip the device debate and classify the access. Three tiers cover most SMEs:
- Tier 1 — communication: email, calendar, chat. Reasonable on personal devices, with conditions (below). Blocking this outright mostly produces workarounds.
- Tier 2 — business systems: the accounting file, the job system, the CRM, shared documents. Acceptable on personal devices via controlled doors — browser sessions and managed apps, not local copies and syncing folders.
- Tier 3 — the crown jewels: payroll, banking, bulk customer data, admin consoles. Company-managed devices only. The line that matters most, and the cheapest to enforce because it touches few people.
Written down, this is half your policy: most BYOD trouble comes not from personal phones reading email, but from Tier 3 access quietly happening from an unpatched home PC.
The minimum standards a personal device must meet
If a device touches work systems, it meets the bar — politely non-negotiable: a passcode/biometric lock and auto-lock; the operating system still supported and updates on; MFA on every work account it accesses (the control doing most of the protective work); and work data accessed through the approved apps rather than forwarded into personal email or copied to personal cloud storage. That last one deserves its own sentence in the policy, because the most common SME data leak isn't hacking — it's convenience: the customer list emailed to self "to work on tonight," now living permanently outside every control you have.
For Microsoft 365 (or Google) shops, the practical enforcement tool is the platform's built-in mobile app management: it can require a PIN on work apps, keep work data inside them, and — crucially — wipe the work container only if a device is lost or its owner leaves, without touching personal photos. That selective-wipe capability defuses the privacy objection that sinks most BYOD conversations, and it's typically already in the subscription you pay for.
Decide the exit before anyone exits
The day a team member resigns is the wrong day to discover their personal phone holds two years of work email and a synced documents folder. Bake BYOD into offboarding: accounts disabled on departure (which kills app access), the work profile removed or remotely wiped, and any local copies addressed in the exit conversation. Run the same drill for a lost device — who do they call, how fast, what gets wiped. Write both as five-line procedures; speed is the whole game when a phone goes missing.
Put it in writing people actually read
A one-page BYOD policy beats a ten-page one nobody opens: the three tiers, the device standards, the no-forwarding rule, the lost-device number, what the company can and can't see or wipe (be explicit — transparency here is what makes the whole arrangement feel fair), and who pays for what if you offer an allowance. Have people acknowledge it at onboarding alongside the other policies. Then enforce it the boring way: when the new starter wants the job system on their personal laptop, the answer is whatever tier the policy says — consistently, including for the owner, whose own devices are usually the least compliant in the building.
FAQ
Should we just buy everyone work phones instead?
For roles living in Tier 3 — finance, admin-heavy, the owner — company devices are cleaner and worth the money. For everyone else, managed BYOD with the standards above hits most of the security at none of the hardware cost. Many SMEs land on a hybrid, drawn along the tier lines.
Can we legally wipe someone's personal phone?
You wipe what you manage: with app-level management, the work container only — and your policy should say exactly that, acknowledged in advance. Full-device wipe rights on personal hardware are a fight you don't need and shouldn't ask for.
What about contractors and bookkeepers on their own machines?
Same tiers, same standards, plus contract language: their access runs through your controlled doors, MFA enforced, and offboarding applies the day the engagement ends. External devices are where Tier 3 discipline earns its keep.
Device security is one of the checks in our free Business Health Check — five minutes to find the blind spots before they find you.
About the author
Nick Lucock
Chief Executive Officer, Valont
Nick leads Valont's day-to-day operations across Finance, People, Operations and Growth. He writes about how the work actually gets done — the processes, systems, and tools that keep Australian SMEs compliant and growing.
LinkedIn →