Home Worker Security: Using Personal IT Equipment Safely
When employees use personal devices for work, the security boundary between corporate and personal becomes blurred. This guide covers the risks of BYOD (Bring Your Own Device) in home working environments, the controls that mitigate those risks and what UK businesses are legally required to consider under UK GDPR.
Nathan Hill-Haimes
Technical Director
How widespread is BYOD home working in UK SMEs?
Bring Your Own Device (BYOD — staff using personal phones and laptops for work) is now the default in many UK SMEs rather than the exception. The pandemic turned an informal habit into permanent practice, and most hybrid teams now access email, files and cloud apps from hardware the business does not own or manage.
The risk is not hypothetical. The government's Cyber Security Breaches Survey found 43% of UK businesses identified a cyber attack in the prior 12 months (gov.uk). Personal devices — often unpatched, running consumer antivirus, and shared with family — are a materially weaker target than a managed corporate endpoint. The National Cyber Security Centre publishes dedicated BYOD guidance precisely because the attack surface is real.
What are the core security risks of personal devices for work?
Personal devices carry four risks a corporate fleet does not: unpatched software, shared family access, no endpoint detection, and uncontrolled local copies of company data. Each one widens the gap between what you can see and what an attacker can reach — and each is invisible to your IT team until it goes wrong.
- Outdated software and unpatched vulnerabilities. Managed devices receive patches automatically through tools like Microsoft Intune. A personal Windows laptop several cumulative updates behind may carry known critical vulnerabilities an attacker can exploit directly.
- Shared devices. A home laptop used by a spouse or teenager — while logged into work email, OneDrive or a VPN — invites accidental deletion, exposure of client data, and family members walking into phishing on a work-connected browser profile.
- No endpoint detection. Corporate devices run an EDR (Endpoint Detection and Response) agent that spots suspicious activity and can be wiped remotely. Personal devices typically run consumer antivirus or nothing, with zero visibility for IT.
- Data residency. Files downloaded, emails saved locally, or app data cached on a personal device sit outside company control. If the device is lost or the employee leaves, that data may be exposed or unrecoverable.
What does UK GDPR require when staff use personal devices?
Under UK GDPR the employer is the data controller and remains responsible for the security of personal data regardless of which device it sits on. If an employee's unencrypted personal device holding customer data is stolen, you may have a reportable breach to the ICO — even though the hardware was never yours.
That responsibility is not optional. The Information Commissioner's Office sets out the security obligations under UK GDPR, and Article 32 requires "appropriate technical and organisational measures." In practice this gives you a binary choice: provide managed corporate devices, or bring personal devices up to an acceptable standard with enforceable controls. Doing neither leaves the controller carrying the liability.
Which controls actually secure BYOD home workers?
Five controls do the heavy lifting: Mobile Device Management, MFA, Conditional Access, cloud-first data handling, and a signed Acceptable Use Policy. None of them require seizing personal hardware — they create a managed work boundary on the device while leaving personal content untouched.
- Mobile Device Management (MDM). Tools like Microsoft Intune create a separate, managed work profile on a personal device. IT can enforce encryption, require a PIN and remote-wipe the work partition without ever touching personal photos or apps. Intune is included in Microsoft 365 Business Premium at £16.90 per user per month ex VAT (microsoft.com/en-gb) and supports Windows, macOS, iOS and Android.
- Conditional Access. Microsoft Entra Conditional Access checks device compliance before granting access — blocking unmanaged or non-compliant devices from reaching Microsoft 365 entirely.
- Multi-factor authentication. MFA on Microsoft 365 is the single highest-impact control. Even if a personal device is compromised and credentials stolen, MFA stops attackers reaching work systems. Enforce it on every work account, without exception.
- Cloud-first data handling. Configure SharePoint, Teams and OneDrive to allow browser-based viewing and editing while blocking downloads to unmanaged devices. This removes most of the data-residency risk before it starts.
- Acceptable Use Policy. A signed BYOD policy defines permitted devices, minimum patch levels, mandatory MDM enrolment and the consequences of a breach — forming part of the organisational measures UK GDPR Article 32 demands.
These controls sit inside our broader managed cybersecurity and Microsoft 365 hybrid working security approach, so home working does not become a blind spot.
Are corporate devices a better option than BYOD?
For businesses where home working is permanent rather than occasional, issuing managed corporate devices is often the cleaner long-term answer. You gain enforced patching, full EDR visibility, and unambiguous data ownership when staff leave — removing the controller liability that BYOD leaves hanging.
The trade-off is cost. A managed laptop runs roughly £600–£1,500 for hardware (typical UK 2026 range) plus device-management licensing, against the lower upfront cost but higher residual risk of BYOD. The comparison below sets out where each model wins.
| Factor | Personal device (BYOD) | Managed corporate device |
|---|---|---|
| Patching | At the employee's discretion | Enforced automatically via MDM |
| Endpoint detection (EDR) | Usually none | Standard, monitored by IT |
| Data ownership on exit | Ambiguous, hard to recover | Clear, fully recoverable |
| Family/shared-device risk | High | Eliminated |
| Upfront cost | Low | Higher (hardware + licence) |
| UK GDPR controller exposure | Higher without strong controls | Lower |
AMVIA advises on both: hardening BYOD where personal devices are unavoidable, and building managed-device programmes where the right approach to mobile device management and BYOD security is a permanent corporate fleet. One provider, security-first, with Microsoft-certified engineers — so the policy, the tooling and the accountability sit in one place.
Are Your Remote Workers Creating Security Gaps?
AMVIA can assess how personal devices are being used in your business and implement the right combination of MDM, Conditional Access and policy controls to reduce the risk.
Frequently Asked Questions
Only within the managed work profile. If your employer enrols your personal device in MDM with a separate work container, they can manage and monitor activity inside that container — not your personal apps, photos or messages. Any monitoring should be disclosed in your contract and BYOD policy, and employers should never monitor personal content on personal hardware.
Report it to IT immediately. If the device was MDM-enrolled, your team can remote-wipe the work partition; a corporate device can be wiped entirely. If the device was unmanaged and held company data, the employer must assess whether a UK GDPR personal data breach has occurred and decide on ICO notification within 72 hours.
No. A VPN encrypts the network connection but does nothing about the device-level risks — outdated software, missing EDR, shared family access. Treat VPN as one layer among several. MDM enrolment, MFA and Conditional Access carry equal weight and address the gaps a VPN cannot.
Microsoft Intune is a cloud endpoint-management platform included in Microsoft 365 Business Premium. For BYOD it creates a managed work profile on personal devices, letting IT enforce security policies, require compliance checks before Microsoft 365 access, and remote-wipe work data without touching personal content. It supports Windows, macOS, iOS and Android.
A BYOD Acceptable Use Policy should set out permitted device types, minimum OS and patch levels, mandatory MDM enrolment, acceptable use of work data, a ban on family sharing of work profiles, required VPN use, lost-or-stolen responsibilities, and employee privacy rights on enrolled devices. Staff should sign it, and it should be reviewed annually.
Related Reading
Keeping Remote Workers Secure Post-COVID-19
How to maintain cybersecurity for permanent hybrid and remote working arrangements in the post-pandemic business environment.
UK Cybersecurity Guide for SMEs | Practical Steps
Practical cybersecurity steps for UK SMEs including endpoint management and access controls.
Data Protection & Privacy | UK GDPR Guide for Businesses
How UK GDPR obligations apply to personal data processed on employee devices, including personal data breach obligations.