BYOD (Bring Your Own Device): Risks and How to Manage It

BYOD (Bring Your Own Device)

BYOD (Bring Your Own Device) means employees use their personal phones, laptops or tablets for work. If that's happening in your business without a formal policy, it's likely a security and compliance gap nobody has looked at yet.

Most small and midsize businesses answer the BYOD question by accident rather than by design. Someone starts checking work email on their personal phone. Then a second person does. Before long it's simply how things work. That's BYOD in practice, and it comes with real risk that is very manageable once you plan for it.

What BYOD means

BYOD: Bring Your Own Device. Any arrangement where employees reach company systems, data or communications using hardware they own personally rather than equipment the company issued.

Why BYOD happens

It's usually the path of least resistance, not a deliberate decision. Company devices for every employee cost money. Staff already have capable phones and laptops. Connecting a personal phone to company email takes a minute. So it spreads quietly, until someone asks what the business is actually allowing onto its systems and what's on those devices.

The risks of unmanaged BYOD

The core problem: the business has no visibility into or control over the device, but the device has access to business data.

  • Data on personal devices isn't controlled. If client records, patient data or financial information sit on an employee's phone, you can't enforce encryption, control who else uses the device or wipe the data if the phone is lost or stolen.
  • Personal devices are often less protected. No endpoint protection, out-of-date operating systems, apps from unknown sources, devices shared with family. The risk is very different from a managed company device.
  • Departing employees take devices with them. A company laptop comes back when someone leaves. A personal phone walks out the door with whatever company data is on it, which is why offboarding needs a plan for BYOD too. Our offboarding checklist covers removing company data when someone leaves.
  • Compliance obligations follow the data. Under HIPAA, electronic protected health information on any device, personal or company-owned, must be covered by your risk analysis and safeguards such as access controls. Encryption is currently an "addressable" specification, meaning you must use it or document why an equivalent measure is reasonable; a proposed 2025 update to the Security Rule would make it mandatory. "It's their own phone" is not an exemption.

Managing BYOD properly

Banning personal devices is often impractical and unpopular. The better answer is a written BYOD policy backed by mobile device management (MDM), which gives IT control over business data on personal devices without touching personal content.

A managed BYOD program typically includes:

  • Device enrollment or app protection. The device or the work apps on it register with a management platform. IT can require encryption and a PIN or biometric lock, and can remove company data if the device is lost or the employee leaves, without wiping personal photos, apps or contacts.
  • Conditional access. A device must meet minimum requirements (supported operating system, screen lock on, no known compromise) before it can reach company resources. Devices that don't meet them are blocked automatically.
  • Separating work data. Company data lives in protected work apps, isolated from personal apps and content. In Microsoft 365, Microsoft Intune app protection policies (included in some Microsoft 365 business plans) do this for email and documents. Our Microsoft 365 support team can tell you whether your licenses include it.
  • A written policy employees acknowledge. What's allowed, what IT can and can't see, what happens when someone leaves, and what happens if the policy isn't followed.

BYOD in regulated industries

Financial services and healthcare firms need extra care. A financial advisory firm where advisers open client portfolios on personal tablets, or a medical practice where staff check appointment details on personal phones, has BYOD exposure whether or not anyone calls it that. Safeguards such as encryption, access controls, logging and remote removal of company data apply regardless of who owns the device. Advisers also need to think about recordkeeping: business communications sent from personal devices, including texts, are subject to the same retention rules as everything else, and regulators have taken enforcement action over off-channel communications. Our page on IT for investment advisers and financial firms covers how we approach this.

NerdSquad handles BYOD as part of the broader security setup for clients in these industries, usually through MDM, conditional access, multi-factor authentication (MFA) and Zero Trust identity controls. NerdSquad is not a law firm; confirm your obligations with your compliance counsel.

How NerdSquad handles BYOD for clients

As a Managed Service Provider (MSP), we review existing BYOD exposure during onboarding, set up device management for personal devices that reach company data, configure conditional access and help clients write a BYOD policy that documents their controls clearly for auditors and examiners. It's one of the most common gaps we find, and one of the more straightforward to close.

If you're not sure whether BYOD is happening in your business, it probably is. The question is whether it's managed. Related reading: remote work security and the new employee IT security checklist.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services