Business Mobiles

BYOD Security Policy: Protecting Personal Devices at Work

Bring Your Own Device (BYOD) policies allow staff to use personal smartphones and laptops for work — but without proper controls, they introduce significant security and compliance risks. This guide explains what a BYOD security policy should cover and how UK businesses can implement one effectively.

BYOD Security: The Core Challenge

43% of UK businesses experienced a cyber breach in 2025 (DSIT). Personal devices accessing company data without policy controls or MDM enrolment are a significant and growing attack surface. A proper BYOD policy combines written rules with technical enforcement — including work profile separation and remote wipe capability — to protect company data whilst respecting employee privacy.

Explore business mobile security

What does BYOD security actually cover?

BYOD security covers every control that keeps corporate data safe when staff use personal devices for work. That means a written policy defining acceptable use, plus technical enforcement — encryption, screen locks, separated work data and the ability to remove company information without touching personal content.

Most UK firms adopted BYOD informally: staff simply connected personal phones to company email with no policy and no controls. The risk is straightforward — corporate data sits on a device the business does not own. If that handset is lost, stolen, or the employee leaves on bad terms, there is no reliable way to remove company data. Roughly 87% of organisations allow BYOD in some form, yet far fewer enforce it technically. Effective BYOD security closes that gap with mobile device management (MDM) and a clear policy.

How does BYOD security work?

BYOD security works by combining a written policy with technical enforcement — neither is enough alone. A policy without controls is unenforceable; controls without a policy confuse staff and erode trust. Together they let the business protect its data while respecting the employee's right to privacy on their own device.

The written element sets out which apps may touch company data, the minimum security settings required (PIN, encryption, current operating system), and exactly what the employer can and cannot see. Transparency drives cooperation — staff enrol willingly when they know personal content stays private. The policy should also cover data ownership, lost-device reporting, and what happens to company data when someone leaves.

The technical element uses Microsoft Intune for mobile devices to create a managed work profile — a separate container for company apps and data. The employer pushes security settings to that profile and can selectively wipe only the work container, leaving personal photos, messages and apps untouched. Microsoft documents this work-profile and app-protection model in its Intune deployment guidance. For a lighter touch, Mobile Application Management (MAM) applies policy to specific apps — stopping data copying from Outlook into a personal notes app, for example — without enrolling the whole device.

MDM vs MAM: which approach fits your business?

The choice between MDM and MAM depends on data sensitivity and how much control the business needs. Full MDM gives the strongest enforcement; MAM is lighter and suits staff who resist enrolling personal devices. Many UK SMEs run a mix, matching the control level to the data each role handles.

ApproachControl levelBest forWipe scope
Full MDM (work profile)Highest — enforce encryption, PIN, OS minimumsSensitive or regulated client dataSelective wipe of work container
MAM (app-level policy)App data only — no device-level controlEmail and Teams, lower sensitivityWipes managed app data only
ContainerisationStrong data separation, no full device managementMixed BYOD estatesWipes the secure container only

AMVIA advises clients on the right balance based on the data their staff access and the risk the business will accept — then implements and manages it as part of a wider managed cybersecurity service.

Why do UK SMEs need BYOD security?

UK SMEs need BYOD security because personal devices are a common, poorly defended attack vector. A lost phone with access to company email or cloud files can expose client data and trigger a reportable breach. Remote and hybrid working has pushed far more company data onto devices the business does not directly control.

According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach in the past year — and mobile devices without enforced encryption or PIN locks are a frequent entry point. With around 28% of UK employees now working in a hybrid pattern, staff check email on personal phones and access Teams on personal tablets daily, each interaction a potential exposure point. Mobile malware attacks have also risen sharply year on year, and personal devices are hit hardest because they rarely carry enterprise-grade protection. The NCSC's device security guidance sets out the baseline controls every BYOD programme should enforce.

How does BYOD security support UK GDPR compliance?

BYOD security supports UK GDPR compliance because the business remains the data controller regardless of who owns the device. Under UK GDPR the organisation is responsible for personal data processed on staff handsets, and unmanaged access without controls is unlikely to meet the law's "appropriate technical measures" test.

Several GDPR duties map directly onto BYOD controls:

  • Data protection by design and default (Article 25): controls must be built in, not bolted on — unmanaged access fails this test.
  • Security of processing (Article 32): encryption, access controls and the ability to remove data remotely are all relevant measures.
  • Breach notification (Articles 33–34): a lost device holding unencrypted personal data may be reportable to the ICO within 72 hours.
  • Employee privacy: selective wipe — never full-device wipe — must be used on personal devices, and the policy must state plainly what the employer can see.

A documented BYOD policy plus MDM or MAM enrolment records forms the accountability evidence the ICO expects in an investigation.

What should a BYOD security policy include?

A BYOD security policy should pair clear written rules with enforced technical controls and a defined leavers process. It must specify acceptable use, minimum device standards, data separation, and exactly what the employer can and cannot access. Staff should sign an informed acknowledgement before any device is enrolled.

  • Acceptable use: which apps, systems and data staff may reach from personal devices.
  • Device security baseline: PIN or biometric lock, OS updates, encryption and screen timeout.
  • MDM or MAM enrolment: managed work profile or app-level policy enforcing the baseline.
  • Data separation: work and personal data kept apart — personal content invisible to the employer.
  • Remote wipe scope: selective wipe of the work profile only, tested before rollout.
  • Leavers process: access revoked and the work profile wiped on the day of departure, tied to HR offboarding.
  • Laptops too: personal laptops covered via conditional access policies in Microsoft Entra ID before they reach Microsoft 365.
  • Annual review: revisit policy and controls each year as threats and devices change.

How much does BYOD security cost?

BYOD security cost depends on how you license the management layer and how many devices you enrol. Most UK SMEs already own the tooling: Microsoft Intune is included in Microsoft 365 Business Premium, so the device-management capability often costs nothing extra beyond a plan upgrade.

Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual commitment) and bundles Intune MDM/MAM alongside Defender for Business — confirmed on Microsoft's UK pricing pages. Standard sits at £9.60 and Basic at £4.60, but neither includes Intune. The remaining cost is implementation and ongoing management — policy design, enrolment, baseline configuration and leavers handling — which AMVIA delivers as a managed Microsoft 365 security service so your internal team carries none of the admin.

Key Elements of a BYOD Security Policy

What your BYOD policy and technical controls need to address.

Acceptable Use Rules

Clear rules on which apps, systems, and data employees can access from personal devices.

Device Security Requirements

PIN or biometric lock, OS update requirements, encryption, and screen timeout settings.

MDM Enrolment

Mobile Device Management allows IT to enforce policy, deliver apps, and wipe company data remotely.

Data Separation

Work and personal data kept in separate containers — personal content invisible to the employer.

BYOD Policy Checklist

Essential elements your BYOD policy and technical controls should cover.

Written BYOD policy in place

Employees have read, understood, and signed the policy before their device accesses company data.

MDM work profile deployed

Microsoft Intune or equivalent creates a separate managed container for company apps and data.

Remote wipe of work profile tested

Selective wipe removes only company data, leaving personal content intact — tested before deployment.

Minimum device requirements defined

Policy specifies OS version, encryption, PIN/biometric lock, and screen timeout requirements.

Leavers process documented

Access revoked and work profile wiped immediately on the day of departure.

GDPR data separation confirmed

Employer cannot access personal apps, photos, or messages on enrolled devices.

BYOD Security Policy FAQs

Implement a Proper BYOD Policy

AMVIA can assess your current BYOD exposure and implement Microsoft Intune-based device management with work profile separation, remote wipe, and a written policy your team can follow.