We had a client last year - a real estate agency in Draper with about 40 agents - who discovered that one of their agents had been accessing the company CRM, email, and shared drives from a personal laptop that was also used by their teenager for gaming. That laptop had no antivirus, no encryption, no screen lock policy, and three browser extensions that were flagged as spyware. Every client record, transaction document, and internal communication that agent had accessed was potentially exposed.
The agency's official IT policy? "We don't allow personal devices for work." The reality? Every single agent was using a personal phone for email. Most were using personal laptops. The policy existed on paper and nowhere else.
BYOD Is Already Happening
Bring Your Own Device isn't something you decide to implement. It's something that's already happening in your organization whether you've sanctioned it or not. Employees check work email on personal phones. They download files to personal laptops. They access cloud applications from tablets at home. Sales teams use their personal phones for client calls and texts. The question isn't whether BYOD is happening - it's whether you have any visibility into it or control over it.
A 2024 study by Zippia found that 82% of organizations allow some form of BYOD, but only 39% have a formal policy governing it. That 43% gap represents businesses where personal devices are touching corporate data with zero oversight. No encryption requirements. No remote wipe capability. No application management. No idea what's actually on those devices.
What You're Actually Risking
Personal devices without management create several categories of risk that compound each other:
- Data leakage. When an employee leaves - voluntarily or otherwise - every piece of company data on their personal device leaves with them. Without mobile device management, you have no ability to selectively remove business data while leaving personal data intact. You're relying entirely on trust and good faith.
- Unpatched vulnerabilities. Corporate-managed devices get patches pushed automatically. Personal devices get patched when the owner feels like it - which for many people means never. An unpatched phone or laptop connecting to your cloud services is a vulnerability you can't see and can't fix.
- Malware crossover. A personal device used for work is also used for everything else. Personal email, social media, gaming, downloads from questionable sources. Malware that lands on a personal device through personal use can pivot to corporate data through saved credentials, synced files, or active sessions.
- Lost and stolen devices. People lose phones. They leave laptops in cars, at coffee shops, in airport security bins. Without device encryption and remote wipe capabilities, a lost phone with your company email configured is a data breach waiting to be discovered - or not discovered, which is worse.
- Compliance exposure. If your business handles data subject to HIPAA, PCI-DSS, CMMC, or state privacy regulations, unmanaged personal devices accessing that data is a compliance violation. Full stop. The regulations require that you maintain control over devices that process protected data.
MDM: What It Actually Does
Mobile Device Management - or more accurately these days, Unified Endpoint Management - is the technology layer that makes BYOD manageable. It doesn't mean taking over someone's personal phone. Modern MDM solutions create a separation between personal and business data on the same device.
When we deploy MDM for our managed IT clients, the setup creates a managed container on the employee's device. Inside that container: company email, company apps, company files. Outside the container: everything personal. The business can manage, monitor, and if necessary wipe the business container without touching personal photos, messages, or apps. The employee gets to use one device for everything. The business gets the security controls it needs.
What MDM gives you in practice:
- Conditional access enforcement. Devices that don't meet your security requirements - no passcode, outdated OS, jailbroken - are blocked from accessing company resources. The user sees a message explaining what they need to fix. Once they comply, access is restored automatically.
- Remote selective wipe. When an employee leaves or a device is lost, you wipe the business container. Company email, apps, and files are removed. Personal data stays untouched. This is the single most important capability for BYOD - the ability to reclaim your data without a confrontation about someone's personal property.
- App management. You control which apps can access company data. You can prevent company files from being opened in unmanaged apps, block copy-paste from business apps to personal apps, and require managed browsers for company web resources.
- Encryption verification. MDM confirms that device encryption is enabled before allowing access. On modern phones this is usually on by default, but on laptops - especially personal Windows machines - it's not guaranteed.
- Compliance reporting. You get a dashboard showing which devices are accessing your environment, their security posture, and their compliance status. For the first time, you actually know what's connecting to your data.
The Policy Side
Technology without policy is just software. A BYOD program needs both. The policy doesn't have to be a 40-page document - in fact, the shorter and clearer it is, the more likely people will actually read it. At minimum, your BYOD policy should address:
- Which devices and operating systems are permitted (we generally require devices running an OS version that's still receiving security updates)
- Minimum security requirements - passcode, encryption, OS version
- What happens to company data when an employee leaves
- Who pays for the device and the data plan (this matters more than you think for legal reasons)
- What the company can and cannot see on personal devices (transparency builds trust)
- Acceptable use boundaries - what's allowed and what isn't
- Employee acknowledgment and consent
We've helped dozens of Utah businesses put together BYOD policies that balance security with employee privacy. The key is being upfront: tell employees exactly what the MDM software can see (app inventory, security posture, location if enabled) and what it can't see (personal messages, photos, browsing history, personal app data). When people understand the boundaries, adoption isn't a fight.
What This Looks Like in Practice
One of our clients - a property management company in Salt Lake with 60 employees across three offices - rolled out MDM as part of their managed IT engagement with us. Before MDM, they had 60+ personal phones accessing company email with no visibility. After deployment, they discovered that 14 devices were running iOS versions with known critical vulnerabilities, 8 had no passcode set, and 2 were jailbroken. All of those devices had full access to company email, SharePoint, and their property management platform containing tenant PII.
Within two weeks of deployment, every device was compliant. The employees whose devices didn't meet requirements either updated their devices or were issued company phones. The total cost of the MDM deployment was less than what a single data breach notification to affected tenants would have cost.
If your team is using personal devices for work - and they are - the question is whether you'll manage that reality proactively or discover it during an incident. We'd rather help you with the first one. Reach out and we'll walk you through what a BYOD program looks like for your specific situation.
