Author: Ami DePierro | Co-Founder, 2 Dog Digital
Ami DePierro is Co-Founder of 2 Dog Digital and a former US Marine Intelligence Analyst who brings analytical precision to cybersecurity strategy for small and mid-sized businesses across the Raleigh/Triangle area. Digit is the voice. Ami is the author.
What every small business needs to know before the first personal device touches company data
BYOD Policy for Small Business: What You Need Before a Personal Device Touches Your Data
Somewhere in your company right now, an employee is finishing a client proposal on a laptop you have never seen, on a network you did not configure, running an operating system that has not been updated since last spring. Nobody meant to create a security risk. They were just trying to get their job done.
That’s the BYOD problem in one paragraph. The good news is it doesn’t require magic. It requires rules
What Is a BYOD Policy and Why Does Every Small Business Need One
What is a BYOD policy? A BYOD (Bring Your Own Device) policy is a written set of rules that defines which personal devices employees may use for work, what security requirements those devices must meet, what company data they can access, and what happens to that data when the employee leaves.
When most people hear “BYOD,” they think about phones. That’s only part of the picture.
A BYOD policy covers:
- Windows laptops – the most common attack surface in most small businesses.
- Macs – not immune to malware and just as vulnerable when they aren’t properly managed.
- Tablets – often used in the field, for sales, and anywhere work happens away from a desk.
- Phones – easy to lose and often filled with company email, calendars, contacts, and files.
If it connects to company systems, the policy applies. Windows, Mac, tablet, or phone. The device changes. The risk doesn’t.
Bring Your Own Device is no longer unusual. Organizations of every size allow employees to access company resources from personal devices. Because of that, NIST published guidance on how to secure BYOD environments rather than whether businesses should allow them. The question is no longer if personal devices will be used. It’s whether your business has rules for using them safely.
Small businesses in Raleigh and across North Carolina don’t get a pass. If your team accesses company systems from personal devices and you don’t have a written policy, you have a security gap whether you’ve discovered it yet or not.
The Actual Risks of Letting Employees Use Personal Devices for Work
There’s nothing inherently wrong with employees using personal devices for work. The problem is that they often exist outside the security controls your business relies on every day.
Attackers don’t care who owns the device. They care whether it’s protected.
Some of the biggest risks include:
- Unmanaged endpoints. Your IT team can’t secure devices they don’t know exist. If a laptop, tablet, or phone isn’t enrolled in your management platform, it may be missing security updates, endpoint protection, or basic compliance checks.
- Credential exposure. According to the 2025 Verizon Data Breach Investigations Report, 46% of infostealer-compromised devices containing corporate credentials were unmanaged personal devices. That’s nearly half. Attackers don’t have to break into your network if they can steal valid credentials from an unmanaged device.
- Offboarding gaps. When an employee leaves, company data doesn’t automatically disappear from their personal devices. Unless you’ve planned for it, that laptop, phone, or tablet may still have access to email, cloud storage, business applications, or downloaded files.
- Shared and outdated devices. Personal devices are often shared with family members, used for personal downloads, and updated on the owner’s schedule instead of yours. Every one of those differences increases your risk.
What Should a BYOD Policy Include
- Which devices are permitted
- What security requirements must be met before access is granted
- Multi-factor authentication (MFA) or passkeys. Passkeys are the stronger choice where your platforms support them. They replace passwords with device-based cryptographic authentication verified by a biometric or PIN, making them resistant to phishing. Windows, macOS, iOS, and Android all support passkeys natively.
- Screen lock enabled with a PIN or biometric authentication.
- Full-disk encryption enabled (BitLocker, FileVault, or the device’s built-in encryption).
- Operating system and applications kept current according to your patching policy.
- No jailbroken or rooted devices.
- What company data can be accessed and stored
- Whether Mobile Device Management (MDM) enrollment is required
- Who owns company data on a personal device
- What happens when an employee leaves
Digit’s Rule 12: An ex-employee’s login works until someone makes it stop working.
Your offboarding process should include revoking accounts, removing access from enrolled devices, selectively wiping company data where appropriate, and reviewing access logs. Those steps should happen the day employment ends, not the following week.
- What happens if the policy is ignored
BYOD vs. Company-Owned Devices: The Honest Comparison
| Factor | BYOD (Personal Device) | Company-Owned Device |
|---|---|---|
| Upfront cost | Low | Higher |
| IT control | Partial | Full |
| Offboarding complexity | Higher | Lower |
| Employee privacy concerns | Must be explicitly addressed | Less of a concern |
| Compliance overhead | Higher | Lower |
| Security risk by default | Higher | Lower with proper management |
BYOD is not the wrong choice. For many small businesses, it’s the practical one.
The question isn’t whether employees use personal devices for work. They already do. The question is whether your business has rules for securing them.
If you work in a regulated industry such as healthcare, legal, or financial services, company-owned devices are often the safer choice. The additional controls required for BYOD can quickly outweigh the cost of providing managed devices.
Whatever you choose, make it a decision. Don’t let it become the default because nobody ever wrote a policy.
The BYOD Policy Checklist for Small Business
- Written policy signed by all employees with device access
- Permitted device types defined: Windows laptops, Macs, tablets, and phones
- Minimum operating system versions specified for each device type
- MFA required, with passkeys supported where available
- Full-disk encryption and screen lock required
- MDM enrollment required for access to sensitive company data
- Employee privacy clearly documented, including what IT can and cannot access
- Acceptable use rules defined, including restrictions on local file storage and personal cloud storage
- Company files stored in company-controlled cloud storage
- Written offboarding procedure covering account revocation, selective device wipe, and access removal from all enrolled devices
- Policy reviewed at least annually
What Happens to Company Data When an Employee Leaves
The answer depends entirely on what you set up before they left.
MDM enrolled, selective wipe authority in the policy: remove company data from every enrolled device, confirm it is gone, close the accounts. Done in under an hour.
No MDM, no policy, no technical controls: you hope the employee deleted everything from their laptop, their tablet, and their phone. That is not a security posture.
Can an employer remove company data from a personal device? Yes – but only if the employee agreed to it in writing before accessing company data, and only if you have the technical tools to execute it. Retroactive MDM enrollment of a former employee is not a realistic option. This is a setup-before-access requirement, not an after-the-fact fix.
How 2 Dog Digital Helps Small Businesses Build and Enforce BYOD Policies
2 Dog Digital is a managed IT and cybersecurity provider based in Raleigh, North Carolina. We don’t sell a one-size-fits-all BYOD solution because there isn’t one.
Most BYOD conversations start after something goes wrong. A laptop is lost. An employee leaves. An audit uncovers personal devices with access to company data that nobody knew existed. By then, you’re fixing a problem instead of preventing one.
We help businesses identify which personal devices are accessing company systems, determine where the security gaps are, and build a BYOD policy that fits the way they actually work. That includes selecting the right management and authentication tools for your environment, documenting clear expectations for employees, and making sure your offboarding process removes company access when employment ends.
If your business allows employees to use personal devices for work and you aren’t confident your policy covers them, let’s talk.
A 30-minute strategy call can help you understand where your biggest gaps are and what it would take to close them.
Contact 2 Dog Digital: https://www.2dogdigital.com
Key Takeaways
- A BYOD policy covers every personal device used for work: Windows laptops, Macs, tablets, and phones. One policy. All four.
- Employee privacy is a genuine obligation. The policy should state plainly what IT can and cannot access. Trust drives compliance; suspicion drives workarounds.
- Authentication standards have moved. MFA is the minimum. Passkeys are phishing-resistant and supported natively across all major platforms. With 80% of AI-generated phishing attacks now targeting SMBs, removing the credential entirely is the stronger play.
- Offboarding is where BYOD policies pay for themselves. If you cannot remove company data from a personal laptop or tablet on the day someone leaves, your policy has a gap.
- Start before something goes wrong. 60% of small businesses that suffer a significant breach do not reopen.
FAQ
What should a BYOD policy include for a small business?
A small business BYOD policy should cover which devices are permitted (Windows laptops, Macs, tablets, and phones), minimum security requirements such as MFA or passkeys and full-disk encryption, what company data employees can access, MDM enrollment requirements, explicit employee privacy disclosures, data ownership language, the offboarding procedure, and consequences for violations. Every employee with device access signs it before they get in.
Can employees use personal laptops and devices for work?
Yes, with controls in place. Personal devices of any type should meet defined security requirements, have phishing-resistant authentication enabled, and where sensitive data is involved, be enrolled in an MDM solution. Access without those controls is the risk. BYOD itself is workable when it is governed.
Who owns business data stored on a personal device?
The company owns the data regardless of which device it sits on. A client file saved to a personal Mac is still company property. Your BYOD policy must state this explicitly, and employees should sign it before accessing company systems. Without that written agreement, data ownership disputes after a departure become legally complicated.
What happens to company data when an employee leaves?
If MDM is in place, IT executes a selective wipe of company data from all enrolled personal devices on the day of separation, and accounts are revoked the same day. Without MDM, data removal relies on the employee’s cooperation across every laptop, tablet, and phone they used, and is unverifiable. MDM enrollment should be a condition of access, not something you add later.
How do I find a cybersecurity partner in Raleigh to help with BYOD policy?
Look for a Raleigh managed IT services provider that understands your specific mix of Windows, Mac, and mobile devices and recommends tools based on your needs rather than a preferred vendor list. 2 Dog Digital provides managed IT and cybersecurity services for small businesses across the Raleigh Triangle and North Carolina. A no-charge assessment is a reasonable starting point.