← All terms

BYOD (Bring Your Own Device)

BYOD (bring your own device) lets employees use personal phones and laptops for work — expanding productivity and the attack surface at the same time.

BYOD (bring your own device) is a workplace policy — or, just as often, an unspoken reality — in which employees use personal phones, tablets, and laptops for work: reading corporate email, joining calls, opening documents, and signing in to business applications from hardware the organization does not own or manage.

How it becomes a security problem

On a personal device, work data lives beside everything security controls were built to keep away from it. Work email sits one notification above personal SMS, where smishing lures arrive without any corporate mail filtering. Browsers hold saved passwords for both banking and business apps. Family members share the laptop, OS updates wait months, and the corporate URL filter, endpoint agent, and backup tooling usually are not there at all. A single infostealer infection on a personal machine can harvest cached work sessions and tokens — a pattern behind several major corporate breaches, where attackers found enterprise credentials sitting in a personal browser profile. Unmanaged devices are also where shadow IT and personal AI accounts concentrate, moving data further from visibility. Because hybrid work made the phone a primary work surface, attackers have shifted with it: Verizon's Mobile Security Index reports 85% of organizations seeing mobile attacks increase year over year.

How to defend against it

Treat BYOD as a program, not a permission. Write down which roles and data classes may use personal devices, and enforce minimum posture — supported OS version, screen lock, disk encryption — through mobile device management or lighter app-level containers that separate work data without touching personal content. Require phishing-resistant MFA and conditional access so a stolen password from an unmanaged device is not enough on its own. Give employees a fast, blame-free way to report a lost or compromised device, and rehearse remote wipe of the work container before it is needed. NIST SP 800-46 provides the reference framework for telework and BYOD security. Finally, train for the personal half of the device — the family, the app downloads, the public Wi-Fi — because that is the half the security team will never see. Our guide to remote and hybrid work security covers where BYOD fits in the wider distributed-work risk picture.

Related terms

Shadow ITShadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.Shadow AIShadow AI is employees' use of AI tools without IT approval — chatbots, assistants, note-takers — creating invisible data leakage and compliance risk.SmishingSmishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.Juice JackingJuice jacking is an attack that uses compromised public USB charging stations to steal data from or install malware on devices plugged in to charge.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo