Mobile Device Security for Business: Protecting Work Phones
Business mobile devices carry email, contacts, authentication apps and corporate data. Effective mobile security requires MDM policies, encryption, application controls and a clear BYOD policy — treating phones as managed business assets, not personal accessories.
Nathan Hill-Haimes
Technical Director
Why is mobile security so often overlooked?
Laptops and desktops get the attention — endpoint protection, patch management, encryption. Phones get far less, yet a modern smartphone holds the employee's email, authenticator apps, corporate contacts, document access, and often direct lines into finance and CRM systems. It is frequently a more sensitive device than the laptop, and far more likely to be lost or stolen.
Lost and stolen devices remain one of the most common causes of personal data breaches, a risk the National Cyber Security Centre flags repeatedly in its device guidance. A phone with no PIN, no encryption, and no remote-wipe capability is a direct liability for any UK business subject to UK GDPR. The fix is not exotic; it is management.
If your team carries company handsets, start by reading our business mobile services overview, which sets out how procurement, management and support fit together.
What threats do business mobiles actually face?
Mobile devices face a distinct threat set that desktop controls do not cover. The five that matter most for UK SMEs are physical loss, malicious apps, SMS and messaging phishing, unsecured Wi-Fi, and SIM swap fraud. Each has a practical, proportionate control — none require enterprise budgets.
- Physical loss and theft — the most common mobile incident. A handset left in a taxi or lifted from a café table is a direct data exposure unless it is encrypted and remotely wipeable.
- Malicious applications — apps sideloaded outside official stores, or legitimate-looking apps with embedded malware, can exfiltrate data, log keystrokes, or grant remote access.
- Smishing (SMS and messaging phishing) — credential-theft links delivered by text bypass email security controls entirely. Pair device controls with phishing protection across the business.
- Unsecured Wi-Fi — public networks expose any traffic not encrypted at the application layer. HTTPS covers most web traffic; poorly built apps remain the gap.
- SIM swap attacks — criminals convince a network operator to port a target's number to a SIM they control, intercepting SMS codes and defeating SMS-based MFA.
What is Mobile Device Management (MDM) and do I need it?
MDM is the foundation of a managed mobile programme. It is software that lets administrators enforce security policy across every enrolled phone and tablet — centrally, remotely, and verifiably. Any business whose staff reach corporate email or data from a phone needs some form of MDM. Without it, you cannot prove a lost device was secure.
A capable MDM platform — Microsoft Intune, Jamf, or VMware Workspace ONE — lets your IT team:
- Enforce PIN, passcode or biometric authentication
- Enable and verify full-device encryption
- Configure managed email, calendar and app access
- Apply application allow and block policies
- Remotely lock or wipe a lost, stolen, or ex-employee device
- Report on every device that drifts out of policy
Microsoft Intune is included in Microsoft 365 Business Premium — £16.90 per user per month (ex VAT, annual) — and manages both iOS and Android. For any organisation already inside Microsoft 365, Intune is usually the most cost-effective choice. See our mobile device management breakdown for how AMVIA configures it.
Corporate-owned or BYOD — which should you choose?
The choice between issuing company handsets and allowing Bring Your Own Device is part security, part culture. Corporate-owned devices can be fully managed with no compromise. BYOD cuts hardware cost but creates a hybrid device holding both personal and corporate data, which complicates security and raises legitimate privacy questions for staff.
Intune supports a middle path: a separate managed work profile on personal Android handsets, or supervised mode on corporate iOS. The work profile applies corporate policy and lets IT wipe only the corporate partition — never personal photos or messages. That respects privacy while protecting company data. Our BYOD security guide covers the policy side in detail.
| Factor | Corporate-owned | BYOD (work profile) |
|---|---|---|
| Hardware cost | Higher — business buys devices | Lower — staff use own devices |
| Management control | Full device | Corporate container only |
| Employee privacy | Limited personal use | Personal data ring-fenced |
| Selective wipe | Full wipe available | Wipes corporate data only |
| Best for | Regulated, high-sensitivity roles | Cost-conscious, mixed-use teams |
How should mobile authentication be secured?
SMS codes texted to a phone beat no MFA, but they are vulnerable to SIM swap and interception. For business use, authenticator apps or hardware tokens give stronger MFA that does not depend on the phone number. Phishing-resistant MFA — FIDO2 passkeys or certificate-based auth — is the strongest option and is increasingly built into mobile operating systems.
For most UK SMEs, moving from SMS codes to Microsoft Authenticator with enforced MFA is a proportionate and significant upgrade. Deploy the same authenticator estate-wide through Microsoft Intune mobile so policy is consistent across every device, not left to individual users.
| MFA method | Strength | SIM-swap resistant |
|---|---|---|
| SMS code | Basic | No |
| Authenticator app | Strong | Yes |
| FIDO2 passkey / certificate | Strongest | Yes |
What belongs in a mobile device policy?
Technical controls work best behind a clear written policy. A good mobile policy covers acceptable use of corporate devices, the requirements for personal devices used for work, how to report a lost or stolen handset, and the basis on which IT may access or wipe a device. Staff should read and sign it before reaching corporate resources from a phone.
Policy and technology have to move together. A remote-wipe capability is only useful if employees know to report losses fast — pair the policy with a tested remote wipe and device security process so the response is immediate, not improvised.
Are Your Business Mobiles Properly Secured?
Most businesses have no visibility into the security configuration of employee mobile devices. AMVIA can deploy MDM, enforce encryption and establish the policies that turn phones from liabilities into managed assets.
Frequently Asked Questions
Because of what they hold and where they go. A work phone carries email, authenticator apps, contacts and often direct access to finance and CRM systems — yet it leaves the building every night and is far more likely to be lost or stolen than a laptop. Treating phones as second-class endpoints inverts the actual risk.
If work email or company data touches phones — yes. MDM is what lets you enforce encryption and screen locks, separate work data from personal, and wipe a lost device remotely. Without it, your data protection on mobiles is whatever each employee personally chose, which is no policy at all.
Either can be safe with the right controls; unmanaged personal phones with full access are the dangerous middle ground. BYOD works when MDM separates and protects the work container. Corporate-owned devices give more control at more cost. Choose deliberately per role rather than drifting into de facto BYOD.
Which devices may access company data and under what enrolment, the required protections (encryption, PIN, updates), what happens on loss or departure — including remote wipe — and the boundary between personal and work use. Write it down and enrol devices against it; an unwritten policy can't be enforced.
Related Reading
Keeping Remote Workers Secure
How mobile device security fits into the wider picture of securing remote and hybrid workers.
Password Protection & Authentication
Moving beyond SMS codes to authenticator apps and phishing-resistant MFA.
Endpoint Security for Business
How endpoint protection extends from laptops to mobile devices in a managed security programme.
Consolidate your mobile fleet → Get a Mobiles Quote