A remote work and BYOD policy staff will accept
The hard part of a bring-your-own-device policy isn't security; it's trust. Staff will refuse anything that looks like the company controlling their phone. Here's how to get the protections you need while promising the one thing that makes people say yes.
Company devices used remotely
These are the easy half: full-disk encryption on, automatic screen lock at ten minutes or less, endpoint protection installed, automatic updates with a weekly restart so they apply. Work happens in approved cloud services or over VPN; no forwarding work email to personal accounts, no downloading files to personal storage "to work on them". A lost or stolen device is reported within an hour so it can be wiped.
Personal devices: the wipe promise
Personal phones and laptops may access company email and approved apps only under one of two conditions: enrolled in the company's device management, or protected by app-level controls (a PIN on the work app, encryption, remote wipe of company data only). Then the sentence that makes the policy work:
[Company Name] will only ever wipe company data and apps from a personal device, never personal photos, messages or files, unless the user requests a full wipe of a lost device. The company does not access personal content on personal devices.
Modern app-protection policies in Microsoft 365 and Google Workspace can enforce exactly this scope, so the promise is technically true, not just reassuring. Add the rest: devices kept updated, not jailbroken or rooted, not shared with family members while signed in to company accounts.
Networks and travel
- Home Wi-Fi on WPA2 or WPA3 with a strong password; the router's default admin password changed.
- Public Wi-Fi only through the company VPN or a personal hotspot. No data connections to public USB charging ports.
- International travel: tell the IT Lead in advance. Devices can be inspected at borders; remove confidential data before departure and access it from the cloud on arrival.
Physical security at home
Screens angled so confidential information isn't visible during video calls or to visitors; printed confidential material locked away and shredded, never in household recycling. Two sentences, but they're the ones a privacy regulator asks about after a mis-delivered document.
What not to put in it
Don't try to dictate home network hardware, mandate the company's antivirus on a personal laptop, or claim a right to inspect personal devices. Each of those turns a security policy into an HR dispute, and none of them is required by insurers or by CIS IG1. Keep the policy to the access path (the app, the account, the connection) rather than the device itself, and staff will sign it.