Cybersecurity

Company Devices or BYOD? Choosing a Mobile Device Strategy

Updated June 17, 2015By the CalliArc team

Key takeaway

Company-owned devices give you full control and cost more; personal devices cost less and limit what you can enforce. Either way, manage the applications and data rather than the whole device where personal devices are involved — attempting full control of an employee's phone creates privacy problems and quiet non-compliance.

Work happens on phones whether or not there's a policy. The choice is between managing that deliberately and discovering later that company data is spread across devices nobody has an inventory of.

The options

  • Company-owned, business-only — full control, clean separation, highest cost, and employees carrying two phones will use the other one.
  • Company-owned, personal use permitted — good control with a clear policy on monitoring and acceptable use.
  • Bring your own device — lowest hardware cost, highest complexity, and the approach most people will default to anyway.
  • A mixed policy by role is common and sensible: managed devices for those handling sensitive data, personal devices for everyone else with tighter application controls.

Manage the data, not the person's phone

  • On personal devices, use application-level management: company data lives in managed apps that can be wiped independently.
  • Require a device passcode, current operating system, and disk encryption as conditions of access rather than taking control of the device.
  • Avoid location tracking and personal data visibility on employee-owned devices — it's usually unlawful, always resented, and rarely necessary.
  • Make the leaving process clean: remove company data without touching personal photographs, and say so in the policy up front.

Write the policy people can follow

  • State which data may be accessed on personal devices and which may not.
  • Explain exactly what the organisation can and cannot see. Ambiguity here produces workarounds.
  • Cover lost and stolen devices: who to tell, how fast, and what happens next.
  • Address the cost question — a contribution towards the phone bill, or none, stated clearly rather than assumed.
  • Cover what happens when someone leaves, including access revocation on the same day.

The practical minimum

Even with no formal programme, three controls cover most of the risk: multi-factor authentication on email and business applications, the ability to revoke access centrally when a device is lost, and a requirement that company documents stay in managed cloud storage rather than being downloaded locally. Those are achievable in a week and matter more than a comprehensive policy nobody has implemented.

Share LinkedIn X

Ready to build it right?

Get a transparent, milestone-based estimate for your project in a free consultation.

Book a free strategy call