60% of UK SMEs allow staff to use their own equipment when working from home. Just over half of SME employees have received no cybersecurity training at all. Those two numbers sitting next to each other are the entire BYOD problem in one sentence: businesses adopted personal devices faster than they built the policy to govern them.
The policy gap is not theoretical
Bring-your-own-device access to corporate systems is standard practice now, not an edge case. 80% of senior IT executives believe employees need mobile access to work effectively, and the shift has genuinely paid off in places: businesses can save up to £341 per employee annually by allowing personal devices instead of issuing corporate hardware.
But the same shift created a governance blind spot. 75% of employees use personal mobile phones for work tasks, and only 55% of those offsite personal devices meet corporate security standards. That's not a small compliance gap. It means close to half of the devices touching business data on a personal phone don't meet the bar the business itself has set.
Why "we have a BYOD policy" isn't the same as being covered
Most SMEs that have a written BYOD policy still lack the technical controls to enforce it. A policy document asking staff to use strong passwords and keep software updated is unenforceable without mobile device management (MDM) sitting behind it, remote wipe capability, encryption verification, VPN requirements on public networks. Without MDM, the policy is a request, not a control.
32% of UK SMEs report having no cybersecurity protections in place at all. Layer BYOD on top of that baseline and the personal phone in an employee's pocket becomes the least monitored device with access to the most sensitive systems in the business.
The mobile contract angle nobody connects to security
Business mobile procurement and BYOD security policy are usually handled by different people, one in procurement or ops, one in IT, if there's a dedicated IT function at all. That separation is part of the problem. A business mobile plan decision, data pooling, eSIM rollout, provider choice, is also a security decision, because it determines whether devices sit inside a managed fleet or exist as unmanaged personal hardware with a business SIM dropped in.
Companies that provide devices to more than 20% of staff tend to run more mature mobile strategies overall, not because corporate-owned hardware is inherently more secure, but because centralising the decision forces the security conversation to happen at procurement stage instead of after an incident.
What closing the gap actually requires
Pair every BYOD policy with MDM, not just a signed document. Enterprise MDM is available from around £2 per device per month. That's a small line item next to the cost of a single breach.
Set a minimum device standard, not a request. Encryption, remote wipe, and VPN-on-public-networks should be conditions of access, not recommendations in a PDF nobody re-reads after onboarding.
Fold mobile procurement and security policy into one decision. If the business is renegotiating a mobile contract, that's the moment to also decide whether BYOD, COPE (corporate-owned, personally enabled), or a hybrid fleet model actually fits the business, rather than defaulting to whatever was in place three years ago.
Train quarterly, not annually. Annual e-learning is consistently shown to have limited effect on behaviour. Short, frequent training tied to real scenarios changes habits; a once-a-year module rarely does.
The bottom line
BYOD isn't the risk. An unmanaged BYOD policy is. The businesses getting this right aren't the ones banning personal devices, they're the ones that stopped treating mobile procurement and mobile security as two separate conversations.
Sign in to leave a comment.