What happens when staff access company data from personal devices?
- Aug 5
- 4 min read

Checking a work email from a personal phone has become completely normal.
So has opening a document from a home laptop, joining a Teams call while travelling or responding to a client message outside the office.
For many businesses, personal devices help employees work flexibly and respond quickly.
The problem is not simply that a device is personally owned.
The problem is whether the organisation knows how that device is accessing business information and whether the right controls are in place.
Convenience can reduce visibility

A company-owned laptop can normally be configured, monitored and maintained according to the organisation’s security requirements.
A personal device is different.
The business may have less control over:
Which operating system it uses
Whether updates are installed
Which applications are present
Whether the device is shared
How it is backed up
Where downloaded files are stored
Whether work data is copied into personal applications
What happens when the device is replaced
The National Cyber Security Centre notes that organisations generally have less control and visibility over personal devices than corporate devices, which means BYOD requires a deliberate balance between flexible access and appropriate security controls.
Allowing personal devices without understanding these risks can leave the business dependent on assumptions about how employees manage their own phones and laptops.
What happens when a device is lost or stolen?
A missing phone is inconvenient for its owner.
It may also become a business issue if that phone contains or can access:
Work email
Microsoft Teams
Client documents
Shared folders
Contact information
Authenticator applications
Saved passwords
Downloaded attachments
The organisation should know whether access can be blocked quickly and whether company information can be removed without deleting the employee’s personal data.
This becomes much more difficult when work information is spread across unmanaged applications or saved directly onto the device.
The aim is not to monitor everything an employee does on a personal phone.
It is to protect company information while respecting the separation between business and personal use.
Personal and business data can become mixed
An employee may download an email attachment and open it in a personal application.
A client document may be saved to a personal cloud-storage account.
A screenshot may enter the employee’s photo library and be included in their personal backup.
Contact details may synchronise with a personal account.
None of these actions necessarily begins with bad intent. They often happen because the easiest option on the device is also the least controlled.
NCSC guidance recommends limiting BYOD users to the minimum services and data they require, applying strong authentication and considering controls that separate work applications and information from personal data. The business needs to decide what information can be accessed from personal devices and how that access should work.
Unmanaged applications create additional routes
Employees may use applications that are convenient but have not been reviewed or approved by the organisation.
This could include:
Personal email
Consumer file-sharing services
Messaging applications
Note-taking tools
Document scanners
Personal cloud backups
Once information leaves a managed company application, it may become harder to control, trace or remove.
A sensible personal-device approach should therefore focus not only on the device but also on the applications being used to access and store company information.
What happens when somebody leaves?
Personal-device access also needs to form part of the joiner, mover and leaver process.
When an employee leaves or changes role, the organisation should be able to:
Disable their account
Revoke active sessions
Remove access to company applications
Protect or remove company information where appropriate
Confirm that unnecessary permissions have been removed
Changing a password alone may not address every active session, downloaded file or connected application.
A clear process helps the business respond consistently instead of trying to work out what was connected after the person has already left.

A BYOD policy needs to reflect reality
A written policy is only useful if it matches how people actually work.
If employees regularly use personal devices but the official policy says they do not, the business does not have control. It has a gap between policy and practice.
NCSC guidance recommends that a BYOD policy clearly communicates the responsibilities of both the organisation and its employees, alongside the controls used to manage the identified risks.
A practical policy should make clear:
Which devices are allowed
Which business services can be accessed
What security settings are required
Whether the device must be updated
Which applications can be used
What happens if the device is lost
What the business can and cannot manage
How access is removed when employment ends
What support the company will provide
Employees should understand the arrangement before being asked to install management or security tools on a personal device.
Questions every business should be able to answer
Leadership does not need to understand every technical detail, but it should be able to answer:
Are personal devices accessing business data?
Which users and devices are involved?
What information can they reach?
Is multi-factor authentication applied?
Can access be revoked remotely?
Is business data separated from personal applications?
Are devices expected to meet minimum security standards?
Does the BYOD policy match actual working practices?
Who is responsible for reviewing the controls?
If the answer to several of these questions is unclear, the business may have more exposure than it realises.
Personal devices are not automatically the problem
Banning personal devices is not necessarily practical or proportionate.
The stronger approach is to understand how they are being used and apply sensible controls based on the information being accessed.
The ISUMO Security Exposure Review can examine:
Personal-device and remote access
Microsoft 365 permissions
Multi-factor authentication
BYOD policies
Administrator permissions
SharePoint and document-library access
Patch and update processes
Wider security vulnerabilities
The client receives clear findings, immediate quick wins, prioritised recommendations and a 30, 60 and 90-day improvement plan.
The aim is to give the business greater visibility and control without making flexible working unnecessarily difficult.
If you are unsure how personal phones and laptops are accessing your company data, speak to ISUMO about a Security Exposure Review.



Comments