Most teams already use personal phones for work. Someone answers email on their own iPhone at the weekend, someone else opens a client document on a home laptop. The question isn’t whether it happens. It’s whether anyone has written down what’s allowed.
A BYOD policy sets out which personal devices can touch work data, what they can do with it, and what the business controls in return. It should cover the tasks people may do, minimum device standards, access rules including MFA, what happens when someone leaves, and how work data is removed.
A BYOD policy is the written agreement between an organisation and its staff about personal devices at work. It names what people may do, what they may not, and which controls the business will enforce. The NCSC treats the written policy and the technical controls as one job.
What Is a BYOD Policy?
A BYOD policy, or bring your own device policy in full, is the document that says which personally owned phones, laptops and tablets may be used for work, what they may reach, and what security the business asks for in exchange. The NCSC’s definition is blunt: with BYOD the organisation owns the data, the employee owns the device.
That split is the whole problem. You can’t image a device you don’t own, and you can’t tell someone to stop letting their family use their own tablet. So the policy has to do two things at once: describe the work you’re happy to see done on personal kit, and describe the control you need over the work data on it.
Most UK organisations don’t start from a strong position here. The government’s 2025/26 breaches survey found that 36% of businesses have any formal policy covering cyber security risks, falling to 31% of micro businesses and rising to 89% of large ones. Personal devices are usually the gap inside that gap.
Is BYOD a Security Risk?
Yes, and the size of the risk depends on how much of the device you can see. The ICO’s guidance says the fully unmanaged version, personal devices with no company software at all, should be avoided by everyone except the smallest organisations with no other way to work remotely. Its reasoning is practical.
- Shared devices. Family members use the same tablet and may see data they shouldn’t.
- Old software. Personal phones run unpatched operating systems for months.
- Unencrypted data. Work files sit on a device that may never have been encrypted.
- Weak access control. A short laptop password is all that stands between a thief and the data.
- Data drifting sideways. Personal USB sticks, personal email, personal cloud storage.
None of that means BYOD is off the table. It means the BYOD security risks are the reason the policy exists. Transputec’s guide to mobile device security covers the device-level side in more detail.
Staff Using Their Own Phones for Work?
Transputec's Modern Workplace services configure Entra ID, Intune and Defender to zero-trust baselines, which is where access rules, app protection and device compliance are actually enforced. Talk to our team about the security work behind your BYOD policy.
Get a Strategic ConsultationWhat Should a BYOD Policy Include?
Start with what people may do, not with the tools. The NCSC splits the job into two halves: the goals, which say what staff can and cannot do from a personal device, and the controls that enforce them. Write the first half before you shop for the second.
Work through these questions, and write the answer to each one into the policy:
- Which tasks are allowed, and which are not. Submitting expenses is not the same as approving payments. The NCSC is explicit that anyone with privileged or administrative access should not hold that access from a personal device.
- Which services and which data. You might allow the expenses system but not the file store, or the file store but not the sensitive folders inside it.
- How much control the business needs, and how much staff will accept. People object to an employer who can wipe their whole phone, and that objection decides which approach is realistic.
- How enforceable the rules are. If a rule depends entirely on people following instructions, decide now what happens when they don’t.
- Which kinds of access are permitted. Native apps, a container app, or just the browser.
- Minimum versions. Name the operating system versions you will support, and say that unsupported ones lose access.
- Device-level or app-level rules. Passcode length, blocking copy and paste between work and personal apps, and where each rule applies.
- Joiners, movers and leavers. How access and work data come off a device when someone changes role, changes phone or leaves.
- Access conditions. Compliance checks before a device connects, with MFA as the floor. The NCSC calls multi-factor authentication a minimum requirement for BYOD.
Do Personal Devices Count for Cyber Essentials?
Yes. Requirements for IT Infrastructure v3.3, in force since April 2026, puts user-owned devices in scope when they access organisational data or services. The exceptions are narrow: devices used only for native voice calls, only for native text messages, or only for multi-factor authentication apps.
So a personal phone with work email on it is in scope, and every one of the five controls applies to it. A personal phone that only receives your MFA prompts is not. That single distinction decides how much work your certification takes, which is why the scoping conversation belongs in the BYOD policy rather than in the assessment.
The requirements also warn that BYOD makes consistent control harder, because people customise their own devices. Our explainer on the 5 Cyber Essentials controls sets out what each control asks for.
How Do You Enforce a BYOD Policy Without Taking Over Someone's Phone?
You enforce it at the app layer. Microsoft’s app protection policies work with or without enrolling the device, so you can require a PIN on work apps, stop copy and paste into personal apps, and remove company data from those apps later without touching personal photos. Conditional Access is what makes the rules stick.
That combination is what most UK teams end up with, because it gives the business control of work data and leaves the rest of the phone alone. Enrolment through mobile device management goes further, and suits company-issued kit or staff who accept full management. Our guides to Conditional Access in Microsoft 365 and to Intune deployments cover both routes.
Two things are worth writing down while you choose. Test the setup before you roll it out to everyone, and tell people why the rules exist. The NCSC asks for both, and adds one more: staff should know not to use jailbroken or rooted devices, and to keep their phones, apps and browsers current.
Which BYOD Approach Should You Choose?
Pick the least access that does the job. The ICO sets out three broad options and Transputec sees all three in UK tenants, usually side by side. The table below is the short version, and the right answer often differs by team rather than by company.
| Approach | What the business controls | Main weakness | Suits |
|---|---|---|---|
| Company-issued device | Everything: updates, configuration, remote support, data loss prevention | Cost, and someone has to manage the fleet | Admins, regulated data, anyone handling sensitive records |
| Personal device, work apps managed | The work apps and the work data inside them | The device underneath may still be unpatched | Most office and field teams |
| Personal device, browser only | The session, and little else | Data cached locally, no assurance about the device | Light, occasional access |
| Personal device, no controls | Nothing | Shared devices, unencrypted files, personal storage | The ICO says avoid this one |
Cost cuts both ways. Company devices cost money up front; unmanaged personal devices cost more when something goes wrong.
What Happens When Someone Leaves?
Decide it before it happens, and write it into the policy. The NCSC lists device changes, role changes and leavers as policy questions rather than IT afterthoughts. With app-level control you remove the work account and its data and the personal photos stay. Without it, you’re asking for the phone back.
Three practical rules keep this clean:
- Removal is part of leaving. Put work data removal on the offboarding checklist next to the laptop and the door pass.
- Tell people the scope. Say in writing what a wipe removes and what it leaves, before anyone enrols. It prevents the argument later.
- Cover the lost phone. Staff need one obvious way to report a lost device fast, and the ICO expects them to know how to report a suspected personal data breach internally.
Reporting is a training job as much as a policy one, which is where security awareness training earns its place.
Your BYOD Policy Checklist
Use this to check whether the document on your intranet is doing its job.
- Name the tasks staff may do from a personal device, and the tasks they may not.
- Say which services and which data personal devices can reach.
- Rule out privileged and administrative access from personal devices.
- Set minimum operating system versions, and say what happens to devices that fall behind.
- Require MFA for every service a personal device touches.
- State whether rules apply at device level, app level, or both.
- Decide how work data is separated from personal data on the device.
- Write the joiner, mover and leaver steps, including what a wipe removes.
- Give staff one route to report a lost device or a suspected breach.
- Review the document each year, and whenever the platforms change.
Conclusion
Personal devices are already inside most UK organisations. The written rules usually arrive later, after a lost phone or a failed assessment, and by then the argument is about someone’s own handset rather than about work data.
Two decisions do most of the work. Decide what people may do from a personal device, and decide how work data is kept separate from everything else on it. The controls follow from those answers: app protection for the phone you don’t own, enrolment for the one you do, MFA either way, and a leaver process that removes the account rather than the holiday photos.
Transputec runs that day to day for UK teams through Modern Workplace and cyber security services, and personal devices are in scope for Cyber Essentials whether or not anyone has written them down. If staff are already using their own phones for work, talk to us about the security work behind your BYOD policy.
FAQs
Do Personal Phones Need to Be in Cyber Essentials Scope?
Yes, if they access organisational data or services. Requirements for IT Infrastructure v3.3 puts user-owned devices in scope alongside company ones. A phone used only for native voice calls, native text messages or MFA prompts stays out of scope, so a device that opens work email counts and a device that only approves sign-ins does not.
Can We Wipe an Employee's Personal Phone?
Only what the policy and the tooling allow, and you should say which in writing before anyone enrols. App-level controls remove company data from work apps and leave personal content alone. Full device wipe is a much bigger ask, and the NCSC notes that staff often refuse a level of control that reaches their whole device.
Do We Need Mobile Device Management for BYOD?
Not always. Microsoft’s app protection policies work with or without enrolling a device, so you can require a PIN for work apps and block data moving into personal apps without managing the phone itself. Enrolment gives more control and suits company-owned devices. Transputec’s Intune guide covers both.
What Does the ICO Say About Personal Devices at Work?
It ranks the options. Company-issued devices are the most secure and the most expensive. Personal devices running company software are the middle ground, provided the organisation’s data stays separate from the owner’s. Fully unmanaged personal devices carry the most risk and the ICO advises avoiding them except in the smallest organisations with no alternative.
Is a BYOD Policy Template Enough?
A template gets you the headings, not the decisions. The answers that matter are yours: which tasks are allowed, which services personal devices can reach, what a wipe removes, and which platforms you support. A BYOD policy that nobody has mapped to real controls is a document, not a control.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



