BYOD Security Policy: Protecting Personal Devices at Work
Bring Your Own Device (BYOD) policies allow staff to use personal smartphones and laptops for work — but without proper controls, they introduce significant security and compliance risks. This guide explains what a BYOD security policy should cover and how UK businesses can implement one effectively.
BYOD Security: The Core Challenge
43% of UK businesses experienced a cyber breach in 2025 (DSIT). Personal devices accessing company data without policy controls or MDM enrolment are a significant and growing attack surface. A proper BYOD policy combines written rules with technical enforcement — including work profile separation and remote wipe capability — to protect company data whilst respecting employee privacy.
Explore business mobile securityWhat does BYOD security actually cover?
BYOD security covers every control that keeps corporate data safe when staff use personal devices for work. That means a written policy defining acceptable use, plus technical enforcement — encryption, screen locks, separated work data and the ability to remove company information without touching personal content.
Most UK firms adopted BYOD informally: staff simply connected personal phones to company email with no policy and no controls. The risk is straightforward — corporate data sits on a device the business does not own. If that handset is lost, stolen, or the employee leaves on bad terms, there is no reliable way to remove company data. Roughly 87% of organisations allow BYOD in some form, yet far fewer enforce it technically. Effective BYOD security closes that gap with mobile device management (MDM) and a clear policy.
How does BYOD security work?
BYOD security works by combining a written policy with technical enforcement — neither is enough alone. A policy without controls is unenforceable; controls without a policy confuse staff and erode trust. Together they let the business protect its data while respecting the employee's right to privacy on their own device.
The written element sets out which apps may touch company data, the minimum security settings required (PIN, encryption, current operating system), and exactly what the employer can and cannot see. Transparency drives cooperation — staff enrol willingly when they know personal content stays private. The policy should also cover data ownership, lost-device reporting, and what happens to company data when someone leaves.
The technical element uses Microsoft Intune for mobile devices to create a managed work profile — a separate container for company apps and data. The employer pushes security settings to that profile and can selectively wipe only the work container, leaving personal photos, messages and apps untouched. Microsoft documents this work-profile and app-protection model in its Intune deployment guidance. For a lighter touch, Mobile Application Management (MAM) applies policy to specific apps — stopping data copying from Outlook into a personal notes app, for example — without enrolling the whole device.
MDM vs MAM: which approach fits your business?
The choice between MDM and MAM depends on data sensitivity and how much control the business needs. Full MDM gives the strongest enforcement; MAM is lighter and suits staff who resist enrolling personal devices. Many UK SMEs run a mix, matching the control level to the data each role handles.
| Approach | Control level | Best for | Wipe scope |
|---|---|---|---|
| Full MDM (work profile) | Highest — enforce encryption, PIN, OS minimums | Sensitive or regulated client data | Selective wipe of work container |
| MAM (app-level policy) | App data only — no device-level control | Email and Teams, lower sensitivity | Wipes managed app data only |
| Containerisation | Strong data separation, no full device management | Mixed BYOD estates | Wipes the secure container only |
AMVIA advises clients on the right balance based on the data their staff access and the risk the business will accept — then implements and manages it as part of a wider managed cybersecurity service.
Why do UK SMEs need BYOD security?
UK SMEs need BYOD security because personal devices are a common, poorly defended attack vector. A lost phone with access to company email or cloud files can expose client data and trigger a reportable breach. Remote and hybrid working has pushed far more company data onto devices the business does not directly control.
According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach in the past year — and mobile devices without enforced encryption or PIN locks are a frequent entry point. With around 28% of UK employees now working in a hybrid pattern, staff check email on personal phones and access Teams on personal tablets daily, each interaction a potential exposure point. Mobile malware attacks have also risen sharply year on year, and personal devices are hit hardest because they rarely carry enterprise-grade protection. The NCSC's device security guidance sets out the baseline controls every BYOD programme should enforce.
How does BYOD security support UK GDPR compliance?
BYOD security supports UK GDPR compliance because the business remains the data controller regardless of who owns the device. Under UK GDPR the organisation is responsible for personal data processed on staff handsets, and unmanaged access without controls is unlikely to meet the law's "appropriate technical measures" test.
Several GDPR duties map directly onto BYOD controls:
- Data protection by design and default (Article 25): controls must be built in, not bolted on — unmanaged access fails this test.
- Security of processing (Article 32): encryption, access controls and the ability to remove data remotely are all relevant measures.
- Breach notification (Articles 33–34): a lost device holding unencrypted personal data may be reportable to the ICO within 72 hours.
- Employee privacy: selective wipe — never full-device wipe — must be used on personal devices, and the policy must state plainly what the employer can see.
A documented BYOD policy plus MDM or MAM enrolment records forms the accountability evidence the ICO expects in an investigation.
What should a BYOD security policy include?
A BYOD security policy should pair clear written rules with enforced technical controls and a defined leavers process. It must specify acceptable use, minimum device standards, data separation, and exactly what the employer can and cannot access. Staff should sign an informed acknowledgement before any device is enrolled.
- Acceptable use: which apps, systems and data staff may reach from personal devices.
- Device security baseline: PIN or biometric lock, OS updates, encryption and screen timeout.
- MDM or MAM enrolment: managed work profile or app-level policy enforcing the baseline.
- Data separation: work and personal data kept apart — personal content invisible to the employer.
- Remote wipe scope: selective wipe of the work profile only, tested before rollout.
- Leavers process: access revoked and the work profile wiped on the day of departure, tied to HR offboarding.
- Laptops too: personal laptops covered via conditional access policies in Microsoft Entra ID before they reach Microsoft 365.
- Annual review: revisit policy and controls each year as threats and devices change.
How much does BYOD security cost?
BYOD security cost depends on how you license the management layer and how many devices you enrol. Most UK SMEs already own the tooling: Microsoft Intune is included in Microsoft 365 Business Premium, so the device-management capability often costs nothing extra beyond a plan upgrade.
Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual commitment) and bundles Intune MDM/MAM alongside Defender for Business — confirmed on Microsoft's UK pricing pages. Standard sits at £9.60 and Basic at £4.60, but neither includes Intune. The remaining cost is implementation and ongoing management — policy design, enrolment, baseline configuration and leavers handling — which AMVIA delivers as a managed Microsoft 365 security service so your internal team carries none of the admin.
Key Elements of a BYOD Security Policy
What your BYOD policy and technical controls need to address.
Acceptable Use Rules
Clear rules on which apps, systems, and data employees can access from personal devices.
Device Security Requirements
PIN or biometric lock, OS update requirements, encryption, and screen timeout settings.
MDM Enrolment
Mobile Device Management allows IT to enforce policy, deliver apps, and wipe company data remotely.
Data Separation
Work and personal data kept in separate containers — personal content invisible to the employer.
BYOD Policy Checklist
Essential elements your BYOD policy and technical controls should cover.
Written BYOD policy in place
Employees have read, understood, and signed the policy before their device accesses company data.
MDM work profile deployed
Microsoft Intune or equivalent creates a separate managed container for company apps and data.
Remote wipe of work profile tested
Selective wipe removes only company data, leaving personal content intact — tested before deployment.
Minimum device requirements defined
Policy specifies OS version, encryption, PIN/biometric lock, and screen timeout requirements.
Leavers process documented
Access revoked and work profile wiped immediately on the day of departure.
GDPR data separation confirmed
Employer cannot access personal apps, photos, or messages on enrolled devices.
BYOD Security Policy FAQs
No. When MDM uses a work profile — as with Microsoft Intune on Android or Apple Business Manager on iOS — the employer manages only the work container. Personal apps, photos, messages and contacts stay private and invisible. This separation is a core GDPR requirement and should be stated plainly in your BYOD policy.
Under a properly configured BYOD policy, IT remotely wipes the work profile when employment ends. That removes company email, apps and files from the managed container while leaving personal content untouched. Without MDM there is no reliable way to do this — which is exactly why a written policy backed by technical controls matters.
Yes, provided the controls are strong enough — mandatory MDM enrolment, data separation, tested remote wipe and a clear written policy. For the most sensitive data, some firms restrict access to company-owned devices instead. AMVIA advises on the right approach based on the data your staff actually process.
Yes. Personal laptops that reach company systems need the same discipline. The controls differ — typically conditional access policies in Microsoft Entra ID that require a device to meet compliance rules before it can open Microsoft 365. AMVIA configures these as part of a complete BYOD implementation.
MDM manages the device and can enforce encryption, PIN and OS minimums through a work profile. MAM manages only specific apps and the data inside them, without controlling the device itself. MDM gives stronger protection for sensitive data; MAM suits staff who only access email and Teams and resist full enrolment.
Implement a Proper BYOD Policy
AMVIA can assess your current BYOD exposure and implement Microsoft Intune-based device management with work profile separation, remote wipe, and a written policy your team can follow.
Related Resources
Business Mobile Security
How to secure company-owned phones and the data they access.
Remote Wipe and Device Security
What remote wipe is and why every business needs it configured before a device is lost.
The Complete Guide to Cybersecurity for UK SMEs
How mobile device security fits into a broader layered security strategy.
Microsoft 365 Security
How Intune and Entra ID enforce device compliance and conditional access.
Mobile Device Security for UK Businesses
Mobile device security is the practice of protecting the smartphones and tablets that access your business email, Teams and files using policy.
Consolidate your mobile fleet → Get a Mobiles Quote