Cybersecurity

Home Worker Security: Using Personal IT Equipment Safely

When employees use personal devices for work, the security boundary between corporate and personal becomes blurred. This guide covers the risks of BYOD (Bring Your Own Device) in home working environments, the controls that mitigate those risks and what UK businesses are legally required to consider under UK GDPR.

NH

Nathan Hill-Haimes

Technical Director

8 min read·Mar 2026

How widespread is BYOD home working in UK SMEs?

Bring Your Own Device (BYOD — staff using personal phones and laptops for work) is now the default in many UK SMEs rather than the exception. The pandemic turned an informal habit into permanent practice, and most hybrid teams now access email, files and cloud apps from hardware the business does not own or manage.

The risk is not hypothetical. The government's Cyber Security Breaches Survey found 43% of UK businesses identified a cyber attack in the prior 12 months (gov.uk). Personal devices — often unpatched, running consumer antivirus, and shared with family — are a materially weaker target than a managed corporate endpoint. The National Cyber Security Centre publishes dedicated BYOD guidance precisely because the attack surface is real.

What are the core security risks of personal devices for work?

Personal devices carry four risks a corporate fleet does not: unpatched software, shared family access, no endpoint detection, and uncontrolled local copies of company data. Each one widens the gap between what you can see and what an attacker can reach — and each is invisible to your IT team until it goes wrong.

  • Outdated software and unpatched vulnerabilities. Managed devices receive patches automatically through tools like Microsoft Intune. A personal Windows laptop several cumulative updates behind may carry known critical vulnerabilities an attacker can exploit directly.
  • Shared devices. A home laptop used by a spouse or teenager — while logged into work email, OneDrive or a VPN — invites accidental deletion, exposure of client data, and family members walking into phishing on a work-connected browser profile.
  • No endpoint detection. Corporate devices run an EDR (Endpoint Detection and Response) agent that spots suspicious activity and can be wiped remotely. Personal devices typically run consumer antivirus or nothing, with zero visibility for IT.
  • Data residency. Files downloaded, emails saved locally, or app data cached on a personal device sit outside company control. If the device is lost or the employee leaves, that data may be exposed or unrecoverable.

What does UK GDPR require when staff use personal devices?

Under UK GDPR the employer is the data controller and remains responsible for the security of personal data regardless of which device it sits on. If an employee's unencrypted personal device holding customer data is stolen, you may have a reportable breach to the ICO — even though the hardware was never yours.

That responsibility is not optional. The Information Commissioner's Office sets out the security obligations under UK GDPR, and Article 32 requires "appropriate technical and organisational measures." In practice this gives you a binary choice: provide managed corporate devices, or bring personal devices up to an acceptable standard with enforceable controls. Doing neither leaves the controller carrying the liability.

Which controls actually secure BYOD home workers?

Five controls do the heavy lifting: Mobile Device Management, MFA, Conditional Access, cloud-first data handling, and a signed Acceptable Use Policy. None of them require seizing personal hardware — they create a managed work boundary on the device while leaving personal content untouched.

  • Mobile Device Management (MDM). Tools like Microsoft Intune create a separate, managed work profile on a personal device. IT can enforce encryption, require a PIN and remote-wipe the work partition without ever touching personal photos or apps. Intune is included in Microsoft 365 Business Premium at £16.90 per user per month ex VAT (microsoft.com/en-gb) and supports Windows, macOS, iOS and Android.
  • Conditional Access. Microsoft Entra Conditional Access checks device compliance before granting access — blocking unmanaged or non-compliant devices from reaching Microsoft 365 entirely.
  • Multi-factor authentication. MFA on Microsoft 365 is the single highest-impact control. Even if a personal device is compromised and credentials stolen, MFA stops attackers reaching work systems. Enforce it on every work account, without exception.
  • Cloud-first data handling. Configure SharePoint, Teams and OneDrive to allow browser-based viewing and editing while blocking downloads to unmanaged devices. This removes most of the data-residency risk before it starts.
  • Acceptable Use Policy. A signed BYOD policy defines permitted devices, minimum patch levels, mandatory MDM enrolment and the consequences of a breach — forming part of the organisational measures UK GDPR Article 32 demands.

These controls sit inside our broader managed cybersecurity and Microsoft 365 hybrid working security approach, so home working does not become a blind spot.

Are corporate devices a better option than BYOD?

For businesses where home working is permanent rather than occasional, issuing managed corporate devices is often the cleaner long-term answer. You gain enforced patching, full EDR visibility, and unambiguous data ownership when staff leave — removing the controller liability that BYOD leaves hanging.

The trade-off is cost. A managed laptop runs roughly £600–£1,500 for hardware (typical UK 2026 range) plus device-management licensing, against the lower upfront cost but higher residual risk of BYOD. The comparison below sets out where each model wins.

FactorPersonal device (BYOD)Managed corporate device
PatchingAt the employee's discretionEnforced automatically via MDM
Endpoint detection (EDR)Usually noneStandard, monitored by IT
Data ownership on exitAmbiguous, hard to recoverClear, fully recoverable
Family/shared-device riskHighEliminated
Upfront costLowHigher (hardware + licence)
UK GDPR controller exposureHigher without strong controlsLower

AMVIA advises on both: hardening BYOD where personal devices are unavoidable, and building managed-device programmes where the right approach to mobile device management and BYOD security is a permanent corporate fleet. One provider, security-first, with Microsoft-certified engineers — so the policy, the tooling and the accountability sit in one place.

Are Your Remote Workers Creating Security Gaps?

AMVIA can assess how personal devices are being used in your business and implement the right combination of MDM, Conditional Access and policy controls to reduce the risk.

Frequently Asked Questions