top of page

What happens when staff access company data from personal devices?

  • Aug 5
  • 4 min read

Checking a work email from a personal phone has become completely normal.

So has opening a document from a home laptop, joining a Teams call while travelling or responding to a client message outside the office.


For many businesses, personal devices help employees work flexibly and respond quickly.


The problem is not simply that a device is personally owned.


The problem is whether the organisation knows how that device is accessing business information and whether the right controls are in place.


Convenience can reduce visibility



A company-owned laptop can normally be configured, monitored and maintained according to the organisation’s security requirements.


A personal device is different.


The business may have less control over:


  • Which operating system it uses

  • Whether updates are installed

  • Which applications are present

  • Whether the device is shared

  • How it is backed up

  • Where downloaded files are stored

  • Whether work data is copied into personal applications

  • What happens when the device is replaced


The National Cyber Security Centre notes that organisations generally have less control and visibility over personal devices than corporate devices, which means BYOD requires a deliberate balance between flexible access and appropriate security controls.


Allowing personal devices without understanding these risks can leave the business dependent on assumptions about how employees manage their own phones and laptops.


What happens when a device is lost or stolen?


A missing phone is inconvenient for its owner.


It may also become a business issue if that phone contains or can access:


  • Work email

  • Microsoft Teams

  • Client documents

  • Shared folders

  • Contact information

  • Authenticator applications

  • Saved passwords

  • Downloaded attachments


The organisation should know whether access can be blocked quickly and whether company information can be removed without deleting the employee’s personal data.


This becomes much more difficult when work information is spread across unmanaged applications or saved directly onto the device.


The aim is not to monitor everything an employee does on a personal phone.


It is to protect company information while respecting the separation between business and personal use.


Personal and business data can become mixed


An employee may download an email attachment and open it in a personal application.


A client document may be saved to a personal cloud-storage account.


A screenshot may enter the employee’s photo library and be included in their personal backup.


Contact details may synchronise with a personal account.


None of these actions necessarily begins with bad intent. They often happen because the easiest option on the device is also the least controlled.


NCSC guidance recommends limiting BYOD users to the minimum services and data they require, applying strong authentication and considering controls that separate work applications and information from personal data. The business needs to decide what information can be accessed from personal devices and how that access should work.


Unmanaged applications create additional routes


Employees may use applications that are convenient but have not been reviewed or approved by the organisation.


This could include:


  • Personal email

  • Consumer file-sharing services

  • Messaging applications

  • Note-taking tools

  • Document scanners

  • Personal cloud backups


Once information leaves a managed company application, it may become harder to control, trace or remove.


A sensible personal-device approach should therefore focus not only on the device but also on the applications being used to access and store company information.


What happens when somebody leaves?


Personal-device access also needs to form part of the joiner, mover and leaver process.


When an employee leaves or changes role, the organisation should be able to:


  • Disable their account

  • Revoke active sessions

  • Remove access to company applications

  • Protect or remove company information where appropriate

  • Confirm that unnecessary permissions have been removed


Changing a password alone may not address every active session, downloaded file or connected application.


A clear process helps the business respond consistently instead of trying to work out what was connected after the person has already left.



A BYOD policy needs to reflect reality


A written policy is only useful if it matches how people actually work.


If employees regularly use personal devices but the official policy says they do not, the business does not have control. It has a gap between policy and practice.


NCSC guidance recommends that a BYOD policy clearly communicates the responsibilities of both the organisation and its employees, alongside the controls used to manage the identified risks.


A practical policy should make clear:


  • Which devices are allowed

  • Which business services can be accessed

  • What security settings are required

  • Whether the device must be updated

  • Which applications can be used

  • What happens if the device is lost

  • What the business can and cannot manage

  • How access is removed when employment ends

  • What support the company will provide


Employees should understand the arrangement before being asked to install management or security tools on a personal device.


Questions every business should be able to answer


Leadership does not need to understand every technical detail, but it should be able to answer:


  • Are personal devices accessing business data?

  • Which users and devices are involved?

  • What information can they reach?

  • Is multi-factor authentication applied?

  • Can access be revoked remotely?

  • Is business data separated from personal applications?

  • Are devices expected to meet minimum security standards?

  • Does the BYOD policy match actual working practices?

  • Who is responsible for reviewing the controls?


If the answer to several of these questions is unclear, the business may have more exposure than it realises.


Personal devices are not automatically the problem


Banning personal devices is not necessarily practical or proportionate.


The stronger approach is to understand how they are being used and apply sensible controls based on the information being accessed.


The ISUMO Security Exposure Review can examine:


  • Personal-device and remote access

  • Microsoft 365 permissions

  • Multi-factor authentication

  • BYOD policies

  • Administrator permissions

  • SharePoint and document-library access

  • Patch and update processes

  • Wider security vulnerabilities


The client receives clear findings, immediate quick wins, prioritised recommendations and a 30, 60 and 90-day improvement plan.


The aim is to give the business greater visibility and control without making flexible working unnecessarily difficult.


If you are unsure how personal phones and laptops are accessing your company data, speak to ISUMO about a Security Exposure Review.



 
 
 

Comments


© 2026 ISUMO. All rights reserved 

Abstract technology background used in ISUMO page layout
27001 Accreditation Logo

Contact

20 – 22 Wenlock Road,
London, N1 7GU

We work with you to improve reliability, strengthen security and boost scalability. Your business gains better performance, lower costs and real peace of mind.
ISUMO LOGO White
phone icon
Pin Icon
Mail Icon
LinkedIn Icon

Join our mailing list

bottom of page