Back to glossary

BYOD (bring your own device)

4 min read

BYOD is the practice of letting employees use their own phones, tablets and laptops for work and to reach corporate resources.

July 30, 2026
Compartir:

BYOD, for bring your own device, is the practice of letting employees use their own phones, tablets and laptops for work and to reach corporate resources.

It is popular because it is convenient for the person and cheap for the company. It is difficult because the organisation now depends on the security of devices it does not own, cannot standardise and cannot always inspect.

The whole discipline comes down to one tension: protecting company data on a device whose owner is entitled to use it however they like.

What makes it hard

Every device is different. Different operating systems, different versions, different levels of hardening. A policy that can be enforced uniformly on a managed fleet becomes a set of exceptions here.

Loss and theft are ordinary events. Personal devices travel everywhere. A phone left in a taxi is not an incident on a corporate fleet, where it can be wiped remotely; on an unmanaged one it can be a disclosure.

Untrusted networks. The same device joins the office network, a home network shared with everything else in the house, and public wireless in a station.

Personal and corporate data live in the same place. Separating them is the central control, and it is also the one that raises the hardest questions: what the employer may see, what it may erase, and what happens on the day the person leaves.

What it is good for

Flexibility. People work from where they are, on hardware they already know, which is why the practice spread in the first place.

Cost. The organisation is not buying and refreshing a device for every role.

Newer hardware. Personal phones are usually replaced faster than corporate ones, so the estate is not stuck on a model chosen four years ago.

The controls that actually carry the weight

A written policy that says what is allowed. Which data may reach a personal device, what the device has to have (screen lock, encryption, a supported operating system version), and what the company will do if it is lost.

Management of the work half, not the whole device. Mobile device management, or the lighter application-level variant of it, lets corporate data be contained and erased without touching the owner’s photos. That distinction is what makes the policy acceptable to the person signing it.

Access decided per request, not per network. Whether a device gets to the data should depend on its state at that moment: patch level, whether it is jailbroken, whether the user passed a second factor. That is conditional access, and it is what replaces the assumption that being inside the office means being trusted.

Somewhere for it to land that is not everything. Personal devices reaching a flat internal network is the failure that turns one compromised phone into a foothold. See network segmentation.

Telling people why. The rules only hold if the person understands what they are protecting, because on their own device they can always work around them.

A worked example

A company lets staff read corporate mail and open documents on their own phones.

An employee joins an open wireless network in a public place. Somebody on the same network is capturing traffic.

Whether that costs the company anything depends entirely on decisions made earlier: whether the connection to the mail service is properly protected, whether the document could be opened at all on a device in that state, and whether the session could be used from somewhere else afterwards.

That is the honest summary of BYOD security. The incident happens on a device you do not control, so the only defences that count are the ones that were already in place before it happened.

Where this shows up in an audit

The common finding is not a badly configured phone. It is that nobody knows how many personal devices hold company data, or which ones. Once the answer to that is a list rather than an estimate, most of the rest is tractable; until then, every control is being applied to a population of unknown size, which is the same problem shadow IT describes in a different corner of the estate.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.