Bitweb
Guide · Policy template

A remote work and BYOD policy staff will accept

The hard part of a bring-your-own-device policy isn't security; it's trust. Staff will refuse anything that looks like the company controlling their phone. Here's how to get the protections you need while promising the one thing that makes people say yes.

By a working IT technician supporting 400+ users · Updated September 2026 · 6 min read

Company devices used remotely

These are the easy half: full-disk encryption on, automatic screen lock at ten minutes or less, endpoint protection installed, automatic updates with a weekly restart so they apply. Work happens in approved cloud services or over VPN; no forwarding work email to personal accounts, no downloading files to personal storage "to work on them". A lost or stolen device is reported within an hour so it can be wiped.

Personal devices: the wipe promise

Personal phones and laptops may access company email and approved apps only under one of two conditions: enrolled in the company's device management, or protected by app-level controls (a PIN on the work app, encryption, remote wipe of company data only). Then the sentence that makes the policy work:

Policy text

[Company Name] will only ever wipe company data and apps from a personal device, never personal photos, messages or files, unless the user requests a full wipe of a lost device. The company does not access personal content on personal devices.

Modern app-protection policies in Microsoft 365 and Google Workspace can enforce exactly this scope, so the promise is technically true, not just reassuring. Add the rest: devices kept updated, not jailbroken or rooted, not shared with family members while signed in to company accounts.

Networks and travel

Physical security at home

Screens angled so confidential information isn't visible during video calls or to visitors; printed confidential material locked away and shredded, never in household recycling. Two sentences, but they're the ones a privacy regulator asks about after a mis-delivered document.

What not to put in it

Don't try to dictate home network hardware, mandate the company's antivirus on a personal laptop, or claim a right to inspect personal devices. Each of those turns a security policy into an HR dispute, and none of them is required by insurers or by CIS IG1. Keep the policy to the access path (the app, the account, the connection) rather than the device itself, and staff will sign it.

Want the documents done for you?The Small Business Cybersecurity Policy Bundle is the written policy set, incident response plan and asset register described here, as editable Word and Excel files: CA$24 on its own, or CA$39 in the full kit, instant download. Get all 8 policies
The cyber-insurance questionnaire, question by question12 questions, what "yes" needs, which document proves itAn incident response plan a small business will actually useRoles, severity levels, first-hour checklist, three playbooksWhat an IT asset inventory needs to track (and what it can skip)The columns insurers and auditors look for