Company Devices or BYOD? Choosing a Mobile Device Strategy
Key takeaway
Company-owned devices give you full control and cost more; personal devices cost less and limit what you can enforce. Either way, manage the applications and data rather than the whole device where personal devices are involved — attempting full control of an employee's phone creates privacy problems and quiet non-compliance.
Work happens on phones whether or not there's a policy. The choice is between managing that deliberately and discovering later that company data is spread across devices nobody has an inventory of.
The options
- Company-owned, business-only — full control, clean separation, highest cost, and employees carrying two phones will use the other one.
- Company-owned, personal use permitted — good control with a clear policy on monitoring and acceptable use.
- Bring your own device — lowest hardware cost, highest complexity, and the approach most people will default to anyway.
- A mixed policy by role is common and sensible: managed devices for those handling sensitive data, personal devices for everyone else with tighter application controls.
Manage the data, not the person's phone
- On personal devices, use application-level management: company data lives in managed apps that can be wiped independently.
- Require a device passcode, current operating system, and disk encryption as conditions of access rather than taking control of the device.
- Avoid location tracking and personal data visibility on employee-owned devices — it's usually unlawful, always resented, and rarely necessary.
- Make the leaving process clean: remove company data without touching personal photographs, and say so in the policy up front.
Write the policy people can follow
- State which data may be accessed on personal devices and which may not.
- Explain exactly what the organisation can and cannot see. Ambiguity here produces workarounds.
- Cover lost and stolen devices: who to tell, how fast, and what happens next.
- Address the cost question — a contribution towards the phone bill, or none, stated clearly rather than assumed.
- Cover what happens when someone leaves, including access revocation on the same day.
The practical minimum
Even with no formal programme, three controls cover most of the risk: multi-factor authentication on email and business applications, the ability to revoke access centrally when a device is lost, and a requirement that company documents stay in managed cloud storage rather than being downloaded locally. Those are achievable in a week and matter more than a comprehensive policy nobody has implemented.