Allowing employees to use their own phones, tablets or laptops for work can seem convenient. Staff can work from almost anywhere, businesses may spend less on equipment, and employees get to use technology they already understand.
However, when personal devices are used without clear rules or security controls, that convenience can introduce risks that are easy to overlook.
Customer information, company emails, passwords and internal documents may end up stored on devices the business does not fully manage. The Australian Cyber Security Centre warns that businesses using Bring Your Own Device arrangements need appropriate protections to avoid increasing the risk of customer data breaches.
What does Bring Your Own Device mean?
Bring Your Own Device, often shortened to BYOD, is an arrangement that allows employees to use personally owned devices for work.
This may include:
- Reading company emails on a personal phone
- Accessing Microsoft 365 from a home computer
- Saving work documents to a personal laptop
- Using personal messaging applications for business conversations
- Accessing company systems while working remotely
In many businesses, these activities happen informally. An employee signs into their work email on their phone or quickly downloads a document to their home computer without anyone considering where that information will be stored.
The device may be personal, but the business information on it still needs to be protected.
Business information can leave your controlled environment
Company-owned computers can be configured with security software, automatic updates, access restrictions and monitoring.
A personal device may not have the same protections.
For example, an employee could download a customer spreadsheet to their home computer. That document may then be automatically copied into a personal cloud storage account or included in a personal device backup.
The business may not know that another copy exists—or have any way to remove it later.
Australian privacy guidance recommends that organisations have clear policies governing staff-owned devices and procedures for employees taking work away from the office.
Lost and shared devices create another risk
Personal devices are regularly taken into cafés, airports, vehicles and other public places. They may also be shared with partners, children or other family members.
A lost phone might provide access to:
- Company email
- Microsoft Teams conversations
- Customer contact details
- Saved passwords
- Cloud storage
- Authentication applications
- Internal business documents
Even when the device is not lost, allowing other people to use it could accidentally expose or delete business information. The Australian Cyber Security Centre recommends locking devices whenever they are left unattended and avoiding sharing devices with other people.
Strong passcodes, automatic screen locking and multi-factor authentication can reduce the risk, but they need to be required rather than left to individual preference.
Removing access becomes more difficult
When an employee leaves the business, their company account can be disabled. However, that does not automatically remove every document, email attachment or screenshot previously downloaded to a personal device.
The former employee may still have:
- Files stored in a downloads folder
- Emails saved within an application
- Synced contact information
- Documents copied to personal cloud storage
- Screenshots containing sensitive information
- Business conversations in personal messaging applications
This does not necessarily mean the employee has acted maliciously. They may simply forget that the information is still there.
Without a defined process, the business may have no reliable way to confirm that its data has been removed.
Personal devices can make IT support more complicated
When employees use a mixture of personal laptops and phones, every device may have different software, security settings and operating systems.
One employee may use an updated Windows laptop. Another may use an older computer that no longer receives security updates. Someone else may have a phone with very little storage or an operating system that does not support required applications.
This can make troubleshooting slower and create an inconsistent experience for employees.
It can also be difficult to determine whether an IT problem is caused by the business system, the employee’s device, their home internet connection or another personal application.
As the number of personal devices grows, so does the time required to support them.
Privacy needs to be considered too
Managing personal devices is not as simple as installing software that gives the business complete control.
A personal phone may contain private photos, messages, applications and location information. Employees need to understand what the business can—and cannot—see or manage.
Clear communication is important. Employees should know:
- What security controls are required
- What information the business can access
- Whether the business can remotely remove work data
- Which applications are approved
- What happens when employment ends
- Who is responsible if the device is lost or damaged
The goal should be to protect business information without unnecessarily accessing an employee’s private information.
Does this mean personal devices should be banned?
Not necessarily.
A well-managed BYOD arrangement can support flexible work and allow employees to access business systems safely. The problem is not always the personal device itself—it is the absence of clear boundaries and security controls.
Businesses should decide which systems and information can be accessed from personal devices.
For example, employees may be permitted to access email and Teams from a secured phone while being prevented from downloading sensitive financial or customer information to an unmanaged laptop.
Access should reflect the employee’s role, the sensitivity of the information and the security of the device.
What should a personal device policy include?
A practical BYOD policy should explain:
- Which types of personal devices are allowed
- Which company systems employees can access
- What security software and updates are required
- Whether devices must use a passcode or biometric lock
- Whether multi-factor authentication is mandatory
- Where company files may be stored
- Which applications are approved for work
- How lost or stolen devices must be reported
- How business information will be removed when an employee leaves
The policy should be easy to understand and supported by technical controls. A written rule alone will not prevent someone from downloading information to an unsecured device.
Start by finding out what is already happening
Before creating a new policy, businesses should understand how employees currently work.
Ask questions such as:
- Which staff members use personal devices for work?
- What company information can those devices access?
- Are business files being downloaded or stored locally?
- Are employees using personal email or messaging applications?
- Can company data be removed without affecting personal information?
- What happens when a device is lost or an employee leaves?
You may discover that personal device use is more widespread than expected.
Convenience should not come at the cost of control
Personal devices can make work easier, particularly for remote and flexible teams. However, businesses still need to know where their information is stored, who can access it and how that access will be removed.
The solution is not necessarily to ban personal devices. It is to manage them properly.
Clear policies, multi-factor authentication, appropriate access controls and secure device management can allow employees to work flexibly while keeping business information protected.
The earlier these expectations are established, the easier it becomes to prevent personal technology from turning into a business security problem.

